Codex: Approve All vs Approving Each Step

Ask Codex to do something and it asks you back. The choice people describe searching for is a ladder: approve this once, approve for this session, approve everything. Our Pedal Four is only relevant to one rung of it, so the useful part of this page is the choice itself rather than the hardware.

What are the three choices really?

They differ in scope, not in trust. Approving a single action keeps you as the check on every step and costs you an interruption per step. Approving for the session widens the permission to one sitting and then throws it away when the session ends. Approving everything removes the check until you put it back, and, importantly, you have to remember to put it back.

Notice that the third option is the only one whose consequences outlive the work you were doing when you chose it. That is the real distinction worth carrying around.

Why is session scope the underrated one?

Because it matches how the annoyance actually behaves. The prompts that wear you down are repetitive: the same test command, the same build, the same file being edited for the fifth time. A session scoped permission kills exactly that repetition and expires on its own, without you having to remember anything at the end of the day. Most people who think they want everything approved actually want this, and discover it after a scare.

When is approve everything genuinely right?

When the work is disposable and the environment is contained. A throwaway branch, a sandbox you can delete, a spike you intend to rewrite. In that setting the review is worth less than the interruption and turning the prompts off is the correct engineering decision, not a lapse. The line is not how clever the model is, it is whether a wrong action can reach anything you cannot recreate in a minute.

Why does a session approval seem not to stick?

This one has a large search cluster behind it, so it is worth answering carefully rather than confidently. Before concluding it is broken, check the obvious things. Is it genuinely the same session, or did something restart in between? Is the command identical to the one you approved, since most permission rules match on what was written and a different path, argument or pipe may not be covered by it? Is it the same kind of action, given that permission to run a command and permission to write a file are usually treated separately? If all of that holds and it still asks, that is worth reporting to the tool rather than hunting for a hidden setting. And check the current documentation, because the wording and the behaviour here have both moved.

If you are approving each step, make the press cheap

This is the one place hardware helps. Keeping per step approval is a defensible choice, and the cost of it is landing a keystroke while your hands are somewhere else. Put accept and reject under a foot with Pedal Four at $85 and the interruption stops competing with your typing. It does not make you a better reviewer, and if what you really want is to stop reviewing, the setting is free and we are not the answer.

For the pedal by pedal mapping in a terminal agent, see the three pedal foot switch setup for Codex CLI.

Back to blog