The approval policy (.kcap/approvals.yaml) and the server policy judge govern only Claude (local PreToolUse/PermissionRequest hooks, #1318; the hosted seam, #1365) and ACP-hosted vendors (AcpInteractionBridge, #1365). Codex has no policy seam in either lane:
- Local Codex hooks.
CodexHookCommand swallows PreToolUse, and its PermissionRequest handler never evaluates the policy. A repo policy's allow, ask and deny rules and its judge block have no effect in a Codex session.
- Hosted Codex (app-server).
CodexApprovalBridge forwards every */requestApproval straight to the user's card, with no PolicyEngine evaluation and no judge consultation.
What a Codex seam needs
- Rules first, then the judge on unmatched calls, with the fail-open handling the Claude seams use: pass through on
uncertain, a non-200, a timeout or a transport error.
- A declared turn set and declared refusals read from the Codex rollout.
complete must be false whenever the rollout can't be read in full.
- Budgets: the hook ceiling locally, up to 5 s on the hosted lane.
- A policy decision event with the
judge block, as the Claude seams emit.
- Codex's hook output contract preserved. A
PermissionRequest with no answer must still write {}, or Codex hangs.
- A live certification against Codex, the same as the Claude one.
Open question: whether the hosted lane should evaluate in CodexApprovalBridge before forwarding (as ClaudeHostedPolicySeam does in LocalPermissionBridge) or reuse the ACP bridge's path.
The approval policy (
.kcap/approvals.yaml) and the server policy judge govern only Claude (local PreToolUse/PermissionRequest hooks, #1318; the hosted seam, #1365) and ACP-hosted vendors (AcpInteractionBridge, #1365). Codex has no policy seam in either lane:CodexHookCommandswallowsPreToolUse, and itsPermissionRequesthandler never evaluates the policy. A repo policy's allow, ask and deny rules and itsjudgeblock have no effect in a Codex session.CodexApprovalBridgeforwards every*/requestApprovalstraight to the user's card, with noPolicyEngineevaluation and no judge consultation.What a Codex seam needs
uncertain, a non-200, a timeout or a transport error.completemust be false whenever the rollout can't be read in full.judgeblock, as the Claude seams emit.PermissionRequestwith no answer must still write{}, or Codex hangs.Open question: whether the hosted lane should evaluate in
CodexApprovalBridgebefore forwarding (asClaudeHostedPolicySeamdoes inLocalPermissionBridge) or reuse the ACP bridge's path.