Browse documentation
AlphaCodex 0.143Public npm alpha

Argos developer documentation

Security Model

Argos separates machine execution authority, human review authority, pre-mutation control, and independent verification.

Separate identities

Agent execution identity

A scoped API key bound to organization, project, agent, and integration channel. It can start runs, request checkpoints, and record results. It cannot make human REVIEW decisions.

Human reviewer identity

A short-lived Supabase session whose user and organization membership are resolved server-side for every intervention read and decision.

Fail-closed control boundary

The supported CLI generates an isolated CODEX_HOME and validates PreToolUse interception, PostToolUse result reconciliation, bounded reads, exact adapter files, Codex version, Argos credentials, and verifier availability before launch.

The generated launch uses the proven workspace-write sandbox and hook-trust configuration. The trust bypass applies only to the isolated generated configuration; unsupported tools remain denied by the Argos hook.

Independent verifier

The local trusted-host verifier receives a frozen plan, runs structured declared commands, and rereads final Git and filesystem state. Agent completion text is not verification evidence. This is a separate code path, not security-isolated or attested verification.

Current trust limits

  • The proven integration supports Codex CLI 0.143.0 only.
  • Only one existing-file update in each apply_patch proposal is controlled.
  • Argos cannot control a session that was not launched through the supported active boundary.
  • REVIEW continuation is process-bound.
  • Hostile repository scripts can access same-user credentials. Malicious-repository isolation is unsupported; use trusted criteria and dependencies in a dedicated worktree without concurrent writers.
  • External mutation and result recording are not one atomic transaction; ambiguous outcomes require reconciliation rather than blind retry.

Task and Evidence pages remain protected by normal application authentication and tenant authorization. Secrets and generated state stay outside the repository.