On October 6, 2026, OpenAI representative Tibo Sottiaux announced that Codex Auto-review is free for users signed in through a ChatGPT account and does not draw usage from their plan. The change concerns usage costs: Auto-review was already in Codex by late April.

What Auto-review changes

A sandbox is a restricted environment that limits what an agent can access or change. When a Codex action needs approval to cross one of those boundaries, Auto-review sends the request to a separate reviewer agent. The reviewer returns a decision and rationale; the main agent remains subject to its existing filesystem, network and sandbox limits.

That makes Auto-review a change in who handles an eligible approval request, not a permissions upgrade. OpenAI’s documentation says the feature does not expand writable locations, enable network access or weaken protected paths.

Which requests reach the reviewer

Auto-review handles interactive approval requests, such as escalated shell or exec calls, network requests blocked by the active sandbox, edits outside permitted writable locations, and MCP or app tool calls that require approval. Actions already allowed inside the sandbox do not trigger a review. Computer Use app-level approvals still go directly to the user.

The distinction matters in daily use: Auto-review can handle certain requests that would otherwise interrupt a workflow, but it does not inspect every action the agent takes. If an action stays within the active sandbox, it is not routed to the reviewer.

What OpenAI’s April evaluation reported

In its April 2026 internal evaluation, OpenAI reported a 99.1% approval rate on sandbox-escalation traffic and a 99.93% effective approval rate across all actions. The figures describe different populations: the first covers escalated actions, while the second covers all actions in the internal deployment.

Those results are a dated snapshot of OpenAI’s evaluation, not a security guarantee. OpenAI says Auto-review can make mistakes, particularly in adversarial or unusual situations, and may not see actions that remain inside the sandbox. The company describes it as one layer alongside sandbox design, monitoring and organization-specific policies.

Settings and approval requirements

Sottiaux gave the activation path as Settings > Permissions > Auto-review. The desktop permission mode is called Approve for me.

Auto-review requires an interactive approval policy. OpenAI’s documented configuration example uses approval_policy = "on-request" with approvals_reviewer = "auto_review". With approval_policy = "never", there is no approval request for Auto-review to handle.

When the reviewer denies a request, Codex receives the rationale and is instructed to try a materially safer alternative or stop and ask the user. OpenAI’s documentation describes a circuit breaker that interrupts a turn after three consecutive denials or 10 denials within the rolling window of the last 50 reviews in that turn.