Architecture study · working profile
OpenAI Codex
A current, deliberately bounded working study of the open-source local coding agent and the responsibilities its public repository summary does and does not establish.
Inspected 343074d4207d572809bd8cea15f4be1d09d98e0b · FD · deep dive needed · Last reviewed 2026-08-22
Evidence boundary. This page is current at the recorded repository pin, but its source inspection is README-level. Unknown internal paths stay unknown rather than inheriting claims from older or adjacent Codex products.
Deep-inspection backlog includes compaction, resume, multi-agent, approvals and sandbox, and ambiguous-effect behavior.
Responsibility map
System boundary
The inspected official repository presents Codex as a coding agent that runs locally in a developer's terminal and working directory.
Local execution makes workspace identity, sandboxing, approvals, and project checks important harness boundaries, but the current source record does not yet map their complete implementation.
The developer and repository policy remain responsible for review, protected merge, deployment, and product acceptance.
Common comparison grammar
Normalized topology
- AdmitownedThe product accepts a coding request on the developer's computer.
- Assemblenot establishedComplete context assembly is not established by the current inspected path.
- Bindnot establishedTool binding
- RunownedThe documented coding agent runs locally on the developer's computer.
- Recovernot establishedSession and effect recovery are not established by the current inspected path.
- Verify and closeexternalProject checks
Lifecycle trace
One complete run
The trace names the owner and observable outcome of each established transition. An unknown path stays unknown rather than being filled from an adjacent product.
- 01
Receive local task
Owner · Codex
A coding request enters the local agent surface.
- 02
Perform coding work
Owner · Codex
The local coding agent advances the requested work.
- 03
Review outcome
Owner · Developer
The result remains subject to project checks and acceptance.
Where responsibility lives
State, authority, recovery, and proof
- Context
- The documented surface places the coding agent on the developer's local computer.
- Canonical state
- Session durability and its internal owner are not established by the current inspected path.
- Tools and authority
- Sandbox, approval, and capability-binding semantics require a deeper source inspection.
- Interruption and recovery
- Session recovery and external-effect reconciliation require a deeper source inspection.
- Verification and closure
- Project checks, review, and acceptance remain outside the documented repository summary.
Deliberately remains outside
- Codex does not replace project-specific review, CI, protected merge, or product acceptance.
Mechanisms worth retaining
How the system carries responsibility
Local work is still governed work
Running on a developer machine does not collapse identity, permission, or acceptance into the model loop. The working directory and admitted task are part of the effective system.
Current does not mean complete
The repository pin and release identity are current, while compaction, resume, multi-agent, capability binding, and effect recovery remain scheduled for path-level inspection.
External checks remain real owners
A coding agent can produce a change and run project commands. CI, code review, protected merge, deployment gates, and the product owner retain distinct closure responsibilities.
Transfer, with boundaries
Adopt, adapt, or reject
- Adopt
- Adopt the local developer-workspace boundary and preserve repository checks as explicit evidence rather than model assertions.
- Adapt
- Adapt the coding loop through project-specific capability, identity, sandbox, and protected-delivery policies after deeper source inspection.
- Reject
- Reject the inference that local execution or a passing project command establishes least privilege, safe deployment, or product acceptance.
Limits, not footnotes
Failure boundary
- This working study does not claim a complete internal control, compaction, recovery, or multi-agent architecture.
- Local execution alone does not prove least privilege, data custody, or safe external effects.
- Project-specific correctness and product acceptance remain outside the inspected repository summary.
Test your model
Retrieval check
A Codex run changes the intended files and reports that tests passed. Which responsibilities remain external? Name at least review, protected merge, deployment admission, and product acceptance, and do not treat local execution as proof of any one of them.