Separate identities
Agent execution identity
A scoped API key bound to organization, project, agent, and integration channel. It can start runs, request checkpoints, and record results. It cannot make human REVIEW decisions.
Human reviewer identity
A short-lived Supabase session whose user and organization membership are resolved server-side for every intervention read and decision.
Fail-closed control boundary
The supported CLI generates an isolated CODEX_HOME and validates PreToolUse interception, PostToolUse result reconciliation, bounded reads, exact adapter files, Codex version, Argos credentials, and verifier availability before launch.
The generated launch uses the proven workspace-write sandbox and hook-trust configuration. The trust bypass applies only to the isolated generated configuration; unsupported tools remain denied by the Argos hook.
Independent verifier
The local trusted-host verifier receives a frozen plan, runs structured declared commands, and rereads final Git and filesystem state. Agent completion text is not verification evidence. This is a separate code path, not security-isolated or attested verification.
Current trust limits
- The proven integration supports Codex CLI 0.143.0 only.
- Only one existing-file update in each
apply_patchproposal is controlled. - Argos cannot control a session that was not launched through the supported active boundary.
- REVIEW continuation is process-bound.
- Hostile repository scripts can access same-user credentials. Malicious-repository isolation is unsupported; use trusted criteria and dependencies in a dedicated worktree without concurrent writers.
- External mutation and result recording are not one atomic transaction; ambiguous outcomes require reconciliation rather than blind retry.
Task and Evidence pages remain protected by normal application authentication and tenant authorization. Secrets and generated state stay outside the repository.