OpenAI Codex Auto-Review: How Free Safety Checks Work
Quick answer: Codex Auto-review is an optional safety feature that lets a separate reviewer evaluate eligible actions that would otherwise pause and wait for your approval. When you are signed in to Codex with a ChatGPT account, OpenAI says these Auto-review safety checks are free and do not count toward your plan’s usage limits. The feature does not remove workspace restrictions, and it does not eliminate every approval prompt.
The key distinction is easy to miss: Auto-review is not a blanket “always allow” switch. It inserts a safety review step between Codex and an action that would normally require you to approve it. If the separate reviewer approves the action, Codex can continue. If the reviewer denies it, Codex can try a safer route or return to you for input.
What Codex Auto-review actually does
Codex can perform long-running software tasks that involve reading files, editing code, running commands and interacting with development tools. Some actions sit behind permission boundaries. Without Auto-review, Codex may stop at one of those boundaries and ask you to approve the next action manually.
Auto-review changes that flow for eligible actions. A separate reviewer checks the proposed action against the applicable safety and permission rules. An approved action can proceed without the ordinary pause. A rejected action does not receive permission simply because Auto-review is turned on.
OpenAI’s current Codex help documentation describes three outcomes worth remembering:
- Approved: Codex can continue with the eligible action.
- Denied: Codex may attempt a safer alternative instead.
- Still needs you: some approvals remain human decisions even with Auto-review enabled.
Is Codex Auto-review free?
For users signed in to Codex with a ChatGPT account, OpenAI says Auto-review safety checks are free and do not count toward the plan’s usage limits. That wording matters. It refers to the safety-checking layer itself; it does not mean every Codex task, model call or external service becomes free.
Codex access and normal usage still depend on the ChatGPT plan and any relevant workspace policies. The safest way to think about the update is: the extra reviewer used for eligible Auto-review checks is not deducted from your ChatGPT plan usage when you are signed in with ChatGPT.
How to enable Auto-review in Codex
OpenAI’s current setup path is straightforward:
- Open Codex while signed in with your ChatGPT account.
- Open Settings.
- Go to Permissions.
- Turn on Auto-review.
If the option is missing, first confirm you are using a current Codex client and that your organization has not restricted the setting. Enterprise and managed workspaces can enforce boundaries that individual users cannot override.
What Auto-review does not change
The most important limitation is that Auto-review respects the permission system around Codex. It is not designed to bypass workspace controls. If an administrator has restricted an action, connector, environment or data source, Auto-review does not grant Codex broader authority than the workspace allows.
It also does not promise that Codex will never pause. OpenAI explicitly says it does not replace every approval prompt. Actions that are outside the eligible set, are ambiguous, or require a higher-confidence human decision may still stop and ask for confirmation.
It is not the same as full autonomous access
Turning on Auto-review should not be interpreted as giving a coding agent unrestricted access to a machine. Permission boundaries still matter. For teams, that means the feature is best understood as a way to reduce avoidable approval friction, not as a substitute for least-privilege access controls.
Where Auto-review can save the most time
The feature is most useful when Codex is doing multi-step work and repeatedly reaches low-risk approval points. Examples include a long refactor, test-and-fix loop, repository cleanup, dependency investigation or code review workflow where the agent needs to perform several related operations before producing a final result.
Without Auto-review, a user can lose time simply because the agent is waiting. With an approved safety review, the same task can keep moving. That is especially valuable for background work where the developer is not watching every step in real time.
How Auto-review fits into Codex permissions
A useful mental model is to separate three layers:
- Your workspace policy: the hard boundary that defines what Codex is allowed to access or do.
- The action request: the specific command or operation Codex wants to perform.
- The Auto-review decision: a separate safety check on an eligible action that would otherwise need your approval.
This explains why Auto-review can reduce interruptions without weakening administrator controls. The reviewer can approve an action only inside the permissions and restrictions that already apply.
Should teams enable it by default?
There is no single answer for every environment. A small development team working in disposable branches may value uninterrupted agent runs. A regulated organization handling production infrastructure may prefer more manual checkpoints.
A practical rollout is to enable Auto-review first in lower-risk environments, keep sensitive production permissions narrow, and review the kinds of actions that still trigger human approval. That gives teams evidence about how much friction the feature removes without treating the switch as a replacement for security policy.
Codex Auto-review vs ordinary approval prompts
| Question | Normal approval flow | Auto-review enabled |
|---|---|---|
| Eligible action reaches a boundary | Codex pauses for you | Separate reviewer evaluates it |
| Approved low-risk action | You approve manually | Codex can continue |
| Action violates restrictions | Not permitted | Still not permitted |
| All prompts eliminated? | No | No |
| Safety-check usage for ChatGPT sign-in | N/A | OpenAI says it is free |
Why this update matters
Agentic coding tools are increasingly judged not only by model quality but also by how much attention they require while doing routine work. Every unnecessary pause breaks the benefit of handing off a longer task. Auto-review targets that operational bottleneck: it gives Codex a controlled way to clear some approval gates while preserving higher-level restrictions.
That makes the change more important than a simple pricing note. OpenAI is effectively separating a safety-checking function from the user’s ordinary usage meter for ChatGPT-authenticated Codex sessions. For developers who run longer tasks, that can make background workflows more practical.
If you are tracking broader OpenAI platform changes, see AVARIXO’s explainer on the GPT-6 Astra and GPT-6.1 Sol speed update and our guide to ChatGPT text watermarking in the EU.
FAQ
Does Auto-review use my ChatGPT quota?
OpenAI says Auto-review safety checks are free and do not count toward plan usage limits when you are signed in with a ChatGPT account.
Does Auto-review remove every permission prompt?
No. OpenAI explicitly says the feature does not replace every approval prompt.
Can Auto-review bypass company restrictions?
No. Workspace restrictions remain in effect.
What happens if Auto-review rejects an action?
Codex may try a safer approach or ask you for input rather than proceeding with the rejected action.
Where do I turn it on?
Open Codex Settings, choose Permissions, and enable Auto-review if the option is available in your environment.
Sources
Primary source: OpenAI Help Center — Using Codex with your ChatGPT plan. AVARIXO checked the current documentation on October 7, 2026.
