Type: Connector disposition
Subject: Codex Local (desktop, CLI, and IDE extension)
Decision requested: Approve the proposed disposition for Codex Local (desktop, CLI, and IDE extension) across its 6 assessed actions
Inherent / residual: Critical / Moderate
Control owner: InfoSec + Engineering (developer tooling) + ChatGPT Enterprise Workspace Owner / Codex Admin + IT (MDM)
Context: 6 assessed actions. No Claude runtime control on this path. Administrative actions proposed: Permit with restrictions x4, Permit x1, Do not enable x1. Proposed for Blocked: Bypass approvals and sandbox (--dangerously-bypass-approvals-and-sandbox / --yolo). Class: Local execution surface (IDE extension or CLI running on the developer's endpoint, with filesystem and shell reach). Control point: Codex admin-enforced requirements.toml, deployed from the Codex managed configuration or by MDM under the com.openai.codex domain, plus ChatGPT Enterprise workspace settings and RBAC. Control owner: InfoSec + Engineering (developer tooling) + ChatGPT Enterprise Workspace Owner / Codex Admin + IT (MDM).
Risks: R-11 [High inherent / Low residual] Substitution by unmanaged third-party MCP servers for the same services | R-46 [Critical inherent / High residual] Agentic coding tools reach everything the developer account can reach on disk | R-47 [Critical inherent / Low residual] Bypass modes remove every local control at once | R-48 [High inherent / High residual] A second model vendor with endpoint reach
Open verification: V-42 [High] The ChatGPT Enterprise workspace agreement, retention position and whether zero data retention is configured; plus Codex Admin group membership and whether it is backed by the identity provider.
Ruling:
Amendment or condition: