Skip to content

Apply the approval policy and judge at the Codex seams #1380

Description

@alexeyzimarev

The approval policy (.kcap/approvals.yaml) and the server policy judge govern only Claude (local PreToolUse/PermissionRequest hooks, #1318; the hosted seam, #1365) and ACP-hosted vendors (AcpInteractionBridge, #1365). Codex has no policy seam in either lane:

  • Local Codex hooks. CodexHookCommand swallows PreToolUse, and its PermissionRequest handler never evaluates the policy. A repo policy's allow, ask and deny rules and its judge block have no effect in a Codex session.
  • Hosted Codex (app-server). CodexApprovalBridge forwards every */requestApproval straight to the user's card, with no PolicyEngine evaluation and no judge consultation.

What a Codex seam needs

  • Rules first, then the judge on unmatched calls, with the fail-open handling the Claude seams use: pass through on uncertain, a non-200, a timeout or a transport error.
  • A declared turn set and declared refusals read from the Codex rollout. complete must be false whenever the rollout can't be read in full.
  • Budgets: the hook ceiling locally, up to 5 s on the hosted lane.
  • A policy decision event with the judge block, as the Claude seams emit.
  • Codex's hook output contract preserved. A PermissionRequest with no answer must still write {}, or Codex hangs.
  • A live certification against Codex, the same as the Claude one.

Open question: whether the hosted lane should evaluate in CodexApprovalBridge before forwarding (as ClaudeHostedPolicySeam does in LocalPermissionBridge) or reuse the ACP bridge's path.

Activity

  1. linear-code commented on Oct 9, 2026

    @linear-code
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions