Auto-review of agent actions without synchronous human oversight OpenAI released Auto-review in Codex, a mode that replaces human approval at the sandbox boundary with review by a separate Codex agent, cutting how often Codex sessions stop for human approval by roughly 200x compared with manual approval mode while approving around 99% of the small fraction of actions that need review. OpenAI said Auto-review performed well on its dangerous actions evaluations and that a majority of Codex Desktop token usage within OpenAI now comes from Auto-review mode, a share that is growing. The company said the mode is conservative enough for its security teams and unobtrusive enough for its research and deployment workflows, and it is meant to block actions causing serious or hard-to-reverse harm such as exfiltrating data, exposing secrets, deleting data, weakening security settings, or running untrusted code. Last week, we released Auto-review in Codex https://developers.openai.com/codex/concepts/sandboxing/auto-review . Until now, users had two choices: Default mode , which requires frequent human approval, and Full Access mode which removes friction at the expense of oversight. Auto-review offers an alternative path. It replaces user approval at the sandbox boundary with review by a separate agent. Internally, Auto-review increases our confidence in running long agentic tasks without synchronous human oversight. In Auto-review mode, Codex sessions stop for human approval roughly 200x less often than in manual approval mode, while still catching many of the actions humans would want stopped. Most actions run without approval in the sandbox. For the small fraction that need review, Auto-review approves around 99%. Even when Auto-review rejects an action, Codex often recovers on its own by finding a safer way to make progress. Auto-review performed well on our dangerous actions evaluations, giving us enough confidence to deploy it internally. It is conservative enough for our security teams and unobtrusive enough for our research and deployment workflows. Today, a majority of Codex Desktop token usage within OpenAI comes from Auto-review mode, and that share is growing, giving us increasing confidence in making it available more broadly. Approval friction harms security Default permission mode