DEV Community

aicoding-guide
aicoding-guide

Posted on Originally published at aicoding-guide.com

Codex CLI v0.160 and how to configure automatic review (Guardian)

Originally published at https://aicoding-guide.com.

Codex CLI v0.160.0 is mostly bug fixes, with one change worth configuring: the opt-in Guardian review got broader.

In short, the setting to know is the review policy. Write it as Markdown in auto_review.policy in config.toml, and use the managed guardian_policy_config when an organization needs one policy everywhere.

This article treats the release notes as the primary source and only states configuration keys the official configuration reference confirms, naming what it could not.

Key point
What you will learn

  • The four new features in v0.160.0
  • How auto_review.policy relates to the managed guardian_policy_config
  • What is still absent from the configuration reference

Four new features

From the release notes:

Change What it does
Agent command center A keyboard-accessible "Show more" for browsing older tasks (#49106)
Select and copy on X11 Select transcript text and paste with middle-click in fullscreen mode on supported local Linux X11 terminals (#49112)
Sessions outside a project Start with workspace defaults where policy permits, and restore saved permissions on resume (#49160)
Guardian review Opt-in capabilities to retrieve earlier user instructions and include context from agent handoffs (#49036, #49057)

Of these, Guardian is the one with configuration behind it. For the other three, no corresponding key appears in the configuration reference.

Configuring automatic review (Guardian)

Two keys in the configuration reference set the policy for automatic review.

Key Type What the reference says
auto_review.policy string Local Markdown policy instructions for automatic review. Managed guardian_policy_config takes precedence. Blank values are ignored
auto_review.extra_policy string Additional local Markdown policy for automatic review, included alongside the main policy. Managed guardian_extra_policy takes precedence. Blank values are ignored

The policy is prose in Markdown. Think of it as the brief you hand a reviewer, not a list of settings.

auto_review.policy = """
## Review policy

- For any diff that changes a public API, state whether it is backwards compatible
- Flag behavior changes that arrive without tests
- Do not comment on generated output (dist/, *.lock)
"""

auto_review.extra_policy = """
- This repository does not swallow exceptions. Always flag a swallowed exception.
"""
Enter fullscreen mode Exit fullscreen mode

Glossary
Local versus managed: auto_review.* lives in your own config.toml. guardian_policy_config and guardian_extra_policy are the managed-settings keys, and the reference states the managed ones take precedence. For one policy across an organization, put it in managed settings so a local file cannot override it.

Blank values are ignored, so you cannot disable a policy by emptying it. Remove the key instead.

For the file's overall structure and profiles, see Configuring Codex with config.toml.

Starting a session outside a project

The release notes say sessions can "start with workspace defaults when policy permits, and restore saved permissions when resuming" — a change to what happens when you launch Codex outside a repository.

Relatedly, the configuration reference documents per-profile workspace roots:

Key Type What the reference says
permissions.<name>.workspace_roots table Profile-defined workspace roots that receive :workspace_roots filesystem rules alongside the session's runtime workspace roots
permissions.<name>.workspace_roots.<path> boolean Opt a path into the profile's workspace root set when true. Disabled entries remain inactive
permissions.<name>.description string Human-readable description for this named profile. A profile does not inherit its parent's description through extends

The workspace defaults key could not be confirmed
Whether the release notes' "workspace defaults" means the permissions.<name>.workspace_roots above, or a separate mechanism, could not be confirmed in the configuration reference as of October 5, 2026. To be explicit about where a projectless session may write, start from the workspace_roots keys that are documented. The wider picture is in Extending where Codex can write with writable_roots.

Windows and the other fixes

The bug fixes concern the runtime environment, with Windows work continuing from v0.158:

  • Windows sandbox PowerShell fallbacks, long-path permission repairs, and suppressing unwanted console windows from background helpers (#49019, #49058, #49098, #49164, #49386)
  • Unsent queued messages resuming after a reconnection once uncertain submissions resolve, without duplicate sends (#49105)
  • The TUI preserving server provider, reasoning-summary and verbosity settings, and showing the correct sessions in resume and fork history (#49144, #49161, #49171)
  • Subagents retaining environments that are still starting, and receiving their configuration or preparation failure (#49075)
  • Preventing SQLite stalls during connection setup and logging, surfacing initialization errors instead of masking them as timeouts (#49032, #49102)
  • Explicit provider model catalogs no longer including unsupported bundled models or reusing stale entries after a refresh failure (#49135)

For approvals and the sandbox, see Codex approval modes and sandbox; for what led here, Codex CLI v0.158.

Summary

  • v0.160.0 has four new features, and automatic review (Guardian) is the only one with configuration behind it
  • Write the policy as Markdown in auto_review.policy, with auto_review.extra_policy alongside it
  • The managed guardian_policy_config and guardian_extra_policy take precedence over the local keys
  • Blank values are ignored, so remove the key rather than emptying it
  • The "workspace defaults" key and the TUI copy settings were not in the configuration reference on October 5, 2026

Top comments (0)