Codex CLI permissions config Date: 2026 04 05 Summary: Updated ~/.codex/config.toml to default to approval policy = "never" and sandbox mode = "workspace write" . Enabled network access for the workspace write sandbox. Added profiles for approvals , untrusted , readonly , and yolo . Tightened deploy