Skip to content

Skip Guardian reviews in Full Access - #42147

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/089ab4296dde473b8e33ab8324be79c5446c46f6
Sep 1, 2026
Merged

Skip Guardian reviews in Full Access#42147
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/089ab4296dde473b8e33ab8324be79c5446c46f6

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 1, 2026

Copy link
Copy Markdown

Skip Guardian reviews in Full Access

Why

Full Access already combines approvalPolicy: "never" with unrestricted
permissions, so confirmation-only actions do not require a model review.

What changed

  • Detect Full Access consistently across the thread and every selected
    environment. Pending, failed, or restricted environments are not treated as
    Full Access.
  • Approve confirmation-only Guardian and MCP requests without synchronous
    review, sampler prewarming, or background scoring. Cancellation, explicit
    denials, and forms that require user input keep their existing behavior.
  • Re-evaluate the active permission state on each turn so an existing thread
    can enter or leave Full Access safely.

Testing

Added coverage for switching approval modes, strict sensitive MCP
confirmations, failed and pending environments, and suppression of Guardian
requests and background-scoring connections.

## Why

Full Access already combines `approvalPolicy: "never"` with unrestricted
permissions, so confirmation-only actions do not require a model review.

## What changed

- Detect Full Access consistently across the thread and every selected
  environment. Pending, failed, or restricted environments are not treated as
  Full Access.
- Approve confirmation-only Guardian and MCP requests without synchronous
  review, sampler prewarming, or background scoring. Cancellation, explicit
  denials, and forms that require user input keep their existing behavior.
- Re-evaluate the active permission state on each turn so an existing thread
  can enter or leave Full Access safely.

## Testing

Added coverage for switching approval modes, strict sensitive MCP
confirmations, failed and pending environments, and suppression of Guardian
requests and background-scoring connections.

GitOrigin-RevId: 089ab4296dde473b8e33ab8324be79c5446c46f6
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/089ab4296dde473b8e33ab8324be79c5446c46f6 branch from 9f19368 to e576993 Compare September 1, 2026 22:18
@copyberry
copyberry Bot merged commit e576993 into main Sep 1, 2026
24 of 32 checks passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/089ab4296dde473b8e33ab8324be79c5446c46f6 branch September 1, 2026 22:19
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 1, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants