Execution identity
The agent proposes work.
A scoped execution API key starts Tasks, requests checkpoints, and records results. It cannot approve its own REVIEW action.
Security and trust
Control is credible when you can see who has authority, where a change is held, and what evidence supports the outcome. Those boundaries are part of the Argos alpha.
Short-lived human session
Scoped execution credential
Agent cannot self-approve. Human authority is checked separately.
Execution identity
A scoped execution API key starts Tasks, requests checkpoints, and records results. It cannot approve its own REVIEW action.
Human identity
A short-lived human session identifies the reviewer. The server rechecks organization membership and existing decision permissions.
Verification source
The independent verifier reads actual Git and filesystem state and runs the declared checks. Agent completion claims cannot certify success.
Before mutation
The Codex alpha uses a dedicated configuration with PreToolUse interception and PostToolUse result reconciliation. Required hooks, entrypoints, credentials, and verifier availability are checked before controlled work starts.
Codex reads through the bounded reader and proposes a supported apply_patch update.
Minimized operation metadata is checked against deterministic Task scope before mutation.
Authorized work continues through its intended invocation. PROTECTED stays blocked; REVIEW waits for a human.
When required control components cannot be validated, the supported launcher refuses to start the controlled Codex session.
Minimized engineering data
Truthful results
Authorization, execution, and verification are distinct states. Generic external callbacks and result recording are not one atomic transaction; an uncertain result must not trigger a blind retry.
Every required deterministic check and declared repository outcome passed.
A required engineering condition was conclusively false, even if the patch executed successfully.
Repository truth or required checks could not be established because of environment or infrastructure failure.
Access and current limits
Execution keys are limited by organization, project, agent, and integration channel. A key authenticates instrumented traffic; it does not automatically observe an agent.
Task and Evidence links require authentication and authorized workspace access. Possession of a URL grants no access.
Codex 0.143.0, one repository, and one existing-file apply_patch update per operation. REVIEW continuation is process-bound. Verification proves the declared deterministic contract.
Keep local human credentials separate from agent execution credentials. Evaluate the repository, declared checks, reviewer access, and supported launch configuration before a pilot.
Your next engineering Task
Start with Codex, one repository, and a boundary you can inspect.