Agent backends

What is supervised, and what is not

Read this before you rely on the edit policy. Ropenode runs two agents, and they do not have the same guardrails. The difference is not cosmetic.

Supervised: Claude Code sessions

Every tool call a Claude Code session makes passes through the PreToolUse hook, which is where the policy is enforced. A deny holds even under acceptEdits and bypassPermissions, because the decision is made before the tool runs and outside the model's reach.

The same hooks drive the accept/deny diff, per-turn undo, the live Log and the session's file list.

Not supervised: Codex sessions

A Codex session is the real Codex TUI running in a terminal inside Ropenode. A terminal has no approval channel for Ropenode to answer, so Safe Agent Edits does not apply to it at all: no edit or read rules, no accept/deny diff, no undo, no Log. Writes there are governed by Codex's own approval model, exactly as if you had run codex yourself in Windows Terminal.

The app marks every Codex console Unsupervised. If you need the edit policy enforced on a task, run it in a Claude Code session.

A Codex session under the Unsupervised banner, auditing a file with its own tools and its own approval rules.

What the policy is, and is not

The edit policy is a safety rail against an unattended agent, not a security boundary against a hostile one. It stops the realistic failure — a fast agent rewriting something it should not have touched at 2am — and it is very good at that.

It is not a sandbox. An agent that can run arbitrary shell commands can do arbitrary things; no PreToolUse hook changes that. If you need a true boundary, run the project in a VM or a container.

Last updated Oct 11, 2026