Updated
The short answer. Codex can be safe for company code when its account, workspace, sandbox, approvals, network, and credentials match the task. The CLI and IDE extension can read files and run shell commands inside the boundary you grant. Codex Cloud works in a remote environment with the repositories, tools, and network destinations you configure.
Treat each permission as access to company systems. Start with the smallest workspace and no command network access, keep secrets outside reachable files, and review the diff and test results before merge.
What Codex can access
- CLI. Codex can inspect repository files, edit files allowed by the sandbox, and run shell commands. OpenAI documents the CLI as the terminal surface for inspecting, editing, and automating code (Codex CLI).
- IDE extension. The extension works beside the code in the editor and uses the same local sandbox and approval controls (Codex IDE extension).
- Codex Cloud. Each task gets a cloud workspace. The environment can include repositories, setup commands, tools, environment variables, network destinations, and network secrets selected by the organization (Codex Cloud).
Access grows when a user adds writable roots, enables networking, connects tools, supplies credentials, or selects full access. Review the effective settings for the specific session.
Sandbox and approval modes
OpenAI documents three local sandbox modes. read-only allows inspection and requires approval for edits or commands outside its boundary. workspace-write allows reads, workspace edits, and routine local commands. danger-full-access removes filesystem and network restrictions (Sandboxing).
With on-request, Codex pauses when it needs to cross the sandbox boundary. With never, it does not show approval prompts. The documented local default limits writes to the workspace and keeps command network access off. OpenAI also documents that automatic review leaves the sandbox boundary in place (Agent approvals and security).
Data handling follows the account and plan
As of 2026-10-07, Codex requests authenticated through a personal ChatGPT workspace follow OpenAI’s consumer data controls. Content can be used for model improvement when the setting allows it. Turning off model improvement excludes new conversations. Requests authenticated through ChatGPT Business, Enterprise, or Edu are excluded from training by default (consumer data handling; business data privacy).
API-authenticated use follows API controls. OpenAI states that API inputs and outputs are excluded from training unless the organization opts in, and abuse-monitoring logs are retained for up to 30 days by default, with stated exceptions and eligible retention controls (API data controls).
Safe setup for company work
- Use the company account. Record the ChatGPT workspace or API organization, owner, plan, and data settings.
- Start with one repository. Remove unrelated folders and mounts from the session boundary.
- Use workspace-write with on-request approvals. Keep full access for a separately reviewed need.
- Keep command networking off. Add only required destinations, and keep credentials outside files the agent can read.
- Review every result. Inspect the diff, commands, test output, and destination branch before merge.
- Document the rule. Add Codex to the AI acceptable use policy and include coding agents in the shadow AI inventory.
Where Sentinel fits
SUPERWISE® Sentinel replaces credit card numbers, IBANs, Social Security numbers, passport numbers, MAC addresses, VINs, and labeled dates of birth and medical record numbers with placeholders before a prompt leaves the PC, and logs every request. It does not redact names or passwords. Use the PII redaction guide to test the covered routes and documented limits.
Codex sandboxing controls local access. Sentinel controls supported values in routed prompts. The company still owns account selection, source-code access, network policy, credentials, approvals, and review.
Frequently asked questions
Is Codex safe to use?
Codex is suitable for approved company work when the company limits its files, commands, network destinations, credentials, account plan, and approval path. Review every change before it reaches production.
Can Codex access my files?
The CLI and IDE extension can read files available inside their configured boundary. Workspace-write limits edits to the active workspace, while read-only prevents edits without approval. Codex Cloud receives the repositories and files assigned to its environment.
Can Codex run terminal commands?
Yes. Codex can run shell commands within the active sandbox. Commands that cross an on-request sandbox boundary pause for approval.
Does Codex use code for training?
The answer follows the account used for the request. OpenAI excludes Business, Enterprise, Edu, and API data from training by default. Personal workspace content follows consumer data controls, including the model-improvement setting.
Sources
All read on 2026-10-07.
- https://learn.chatgpt.com/docs/codex/cli
- https://learn.chatgpt.com/docs/codex/ide
- https://learn.chatgpt.com/docs/cloud
- https://learn.chatgpt.com/docs/sandboxing
- https://learn.chatgpt.com/docs/agent-approvals-security
- https://developers.openai.com/api/docs/guides/your-data
- https://openai.com/business-data/
- https://help.openai.com/en/articles/7039943-how-openai-handles-data-in-consumer-services