Codex Trusted Mode One-Pager
Codex Trusted Mode starts with a useful standalone local hardening baseline and upgrades to SDE-backed governed execution when teams need deterministic authorization and enterprise evidence.
Free Baseline
- Allows read-only shell commands
- Blocks patch application by default
- Blocks mutating shell commands by default
Current Governed Claim
- Governed flow exists and is mock-PDP validated
- Public certification is
CERTIFIED_ENFORCEDfor the validated observed current workspace session only - Additional Ubuntu WSL and fresh Ubuntu VM validation support that declared row