Codex CLI v0.160 and how to configure automatic review (Guardian)

Codex Published:

The four new features in Codex CLI v0.160.0, and how the opt-in Guardian review is configured through auto_review.policy and the managed guardian_policy_config.

Verified on Oct 5, 2026 These tools change quickly. Please also check the latest official documentation.
Contents
  1. Four new features
  2. Configuring automatic review (Guardian)
  3. Starting a session outside a project
  4. Windows and the other fixes
  5. Summary

Codex CLI v0.160.0 is mostly bug fixes, with one change worth configuring: the opt-in Guardian review got broader.

In short, the setting to know is the review policy. Write it as Markdown in auto_review.policy in config.toml, and use the managed guardian_policy_config when an organization needs one policy everywhere.

This article treats the release notes as the primary source and only states configuration keys the official configuration reference confirms, naming what it could not.

KEY POINT

What you will learn

  • The four new features in v0.160.0
  • How auto_review.policy relates to the managed guardian_policy_config
  • What is still absent from the configuration reference

Four new features

From the release notes:

ChangeWhat it does
Agent command centerA keyboard-accessible "Show more" for browsing older tasks (#49106)
Select and copy on X11Select transcript text and paste with middle-click in fullscreen mode on supported local Linux X11 terminals (#49112)
Sessions outside a projectStart with workspace defaults where policy permits, and restore saved permissions on resume (#49160)
Guardian reviewOpt-in capabilities to retrieve earlier user instructions and include context from agent handoffs (#49036, #49057)

Of these, Guardian is the one with configuration behind it. For the other three, no corresponding key appears in the configuration reference.

Configuring automatic review (Guardian)

Two keys in the configuration reference set the policy for automatic review.

KeyTypeWhat the reference says
auto_review.policystringLocal Markdown policy instructions for automatic review. Managed guardian_policy_config takes precedence. Blank values are ignored
auto_review.extra_policystringAdditional local Markdown policy for automatic review, included alongside the main policy. Managed guardian_extra_policy takes precedence. Blank values are ignored

The policy is prose in Markdown. Think of it as the brief you hand a reviewer, not a list of settings.

auto_review.policy = """
## Review policy

- For any diff that changes a public API, state whether it is backwards compatible
- Flag behavior changes that arrive without tests
- Do not comment on generated output (dist/, *.lock)
"""

auto_review.extra_policy = """
- This repository does not swallow exceptions. Always flag a swallowed exception.
"""

用語解説

Local versus managed: auto_review.* lives in your own config.toml. guardian_policy_config and guardian_extra_policy are the managed-settings keys, and the reference states the managed ones take precedence. For one policy across an organization, put it in managed settings so a local file cannot override it.

Blank values are ignored, so you cannot disable a policy by emptying it. Remove the key instead.

For the file's overall structure and profiles, see Configuring Codex with config.toml.

Starting a session outside a project

The release notes say sessions can "start with workspace defaults when policy permits, and restore saved permissions when resuming" — a change to what happens when you launch Codex outside a repository.

Relatedly, the configuration reference documents per-profile workspace roots:

KeyTypeWhat the reference says
permissions.<name>.workspace_rootstableProfile-defined workspace roots that receive :workspace_roots filesystem rules alongside the session's runtime workspace roots
permissions.<name>.workspace_roots.<path>booleanOpt a path into the profile's workspace root set when true. Disabled entries remain inactive
permissions.<name>.descriptionstringHuman-readable description for this named profile. A profile does not inherit its parent's description through extends

The workspace defaults key could not be confirmed

Whether the release notes' "workspace defaults" means the permissions.<name>.workspace_roots above, or a separate mechanism, could not be confirmed in the configuration reference as of October 5, 2026. To be explicit about where a projectless session may write, start from the workspace_roots keys that are documented. The wider picture is in Extending where Codex can write with writable_roots.

Windows and the other fixes

The bug fixes concern the runtime environment, with Windows work continuing from v0.158:

  • Windows sandbox PowerShell fallbacks, long-path permission repairs, and suppressing unwanted console windows from background helpers (#49019, #49058, #49098, #49164, #49386)
  • Unsent queued messages resuming after a reconnection once uncertain submissions resolve, without duplicate sends (#49105)
  • The TUI preserving server provider, reasoning-summary and verbosity settings, and showing the correct sessions in resume and fork history (#49144, #49161, #49171)
  • Subagents retaining environments that are still starting, and receiving their configuration or preparation failure (#49075)
  • Preventing SQLite stalls during connection setup and logging, surfacing initialization errors instead of masking them as timeouts (#49032, #49102)
  • Explicit provider model catalogs no longer including unsupported bundled models or reusing stale entries after a refresh failure (#49135)

For approvals and the sandbox, see Codex approval modes and sandbox; for what led here, Codex CLI v0.158.

Summary

  • v0.160.0 has four new features, and automatic review (Guardian) is the only one with configuration behind it
  • Write the policy as Markdown in auto_review.policy, with auto_review.extra_policy alongside it
  • The managed guardian_policy_config and guardian_extra_policy take precedence over the local keys
  • Blank values are ignored, so remove the key rather than emptying it
  • The "workspace defaults" key and the TUI copy settings were not in the configuration reference on October 5, 2026

FAQ

What is the headline of v0.160?
The opt-in Guardian review gains the ability to retrieve earlier user instructions and to include context from agent handoffs.
Where do I write the automatic review policy?
In auto_review.policy in config.toml, as Markdown. auto_review.extra_policy adds to it. Managed guardian_policy_config and guardian_extra_policy take precedence over both.
Can I run Codex outside a project?
Per the release notes, sessions can start with workspace defaults where policy permits, and saved permissions are restored on resume. The key that defines those workspace defaults could not be found in the configuration reference.
Where are the TUI copy settings?
v0.158's release notes describe configurable copy-on-select and right-click paste, but no matching key appears in the configuration reference as of October 5, 2026.

Primary sources

This article was drafted by AI from official documentation and reviewed by the site operator before publishing. Found a mistake? Let us know via the contact page.