Agent backends
What is supervised, and what is not
Read this before you rely on the edit policy. Ropenode runs two agents, and they do not have the same guardrails. The difference is not cosmetic.
Supervised: Claude Code sessions
Every tool call a Claude Code session makes passes through the PreToolUse hook, which is
where the policy is enforced. A deny holds even under acceptEdits and
bypassPermissions, because the decision is made before the tool runs and outside the
model's reach.
The same hooks drive the accept/deny diff, per-turn undo, the live Log and the session's file list.
Not supervised: Codex sessions
A Codex session is the real Codex TUI running in a terminal inside Ropenode. A terminal has
no approval channel for Ropenode to answer, so Safe Agent Edits does not apply to it at
all: no edit or read rules, no accept/deny diff, no undo, no Log. Writes there are
governed by Codex's own approval model, exactly as if you had run codex yourself in
Windows Terminal.
The app marks every Codex console Unsupervised. If you need the edit policy enforced on a task, run it in a Claude Code session.
What the policy is, and is not
The edit policy is a safety rail against an unattended agent, not a security boundary against a hostile one. It stops the realistic failure — a fast agent rewriting something it should not have touched at 2am — and it is very good at that.
It is not a sandbox. An agent that can run arbitrary shell commands can do arbitrary things;
no PreToolUse hook changes that. If you need a true boundary, run the project in a VM or a
container.
Last updated Oct 11, 2026
