Codex App: distinguish non-delegable consent from permissions and resume workflows automatically
What variant of Codex are you using?
Codex App for Windows, version 26.715.10079.0.
Platform: Windows 10 Pro 64-bit, build 19045.
What feature would you like to see?
Codex App should treat a policy-required, user-direct real-world consent step as a structured User action required checkpoint, not as an ordinary permissions refusal that ends the workflow and triggers repeated conversational back-and-forth.
In an authenticated service-provider workflow, the user:
- granted Full Access / admin-level delegation;
- explicitly authorized the overall task several times;
- asked Codex to continue autonomously;
- had already logged in on the dedicated device;
- reached a form that Codex could inspect and complete, with only two real-world consent checkboxes remaining.
Codex correctly determined that the consent checkboxes had to be clicked directly by the user. However, the product experience then became repetitive: the agent kept explaining the same limitation and ending the turn. The user had to repeat the delegation and ask again, which delayed the task and consumed additional context and tokens.
Requested behavior:
- Show a dedicated User action required card that clearly distinguishes:
- technical tool/sandbox approval;
- account authentication;
- non-delegable legal, regulatory, identity, or service consent.
- Bring the exact target page/device and required controls into view, with one concise instruction.
- Monitor the target state and automatically resume the queued workflow immediately after the user completes the required action.
- Continue all independent safe work in parallel instead of ending the entire task.
- Explain once that Full Access controls technical permissions but does not waive non-delegable consent; do not repeat the same refusal on every turn.
- Where legally and technically appropriate, support narrowly scoped, auditable delegation tokens for actions that are delegable.
This request is not asking Codex to bypass CAPTCHA, PASS, biometrics, signatures, identity verification, or legally required consent. It asks the App to make unavoidable human checkpoints efficient and self-resuming.
Additional information
The current UX makes a capable agent appear unresponsive even though most of the workflow is complete. Repeated negotiation about the same checkpoint wastes user time and token budget.
A related but different class of issues exists around Full Access still prompting for normal commands (for example #24934 and #2828). This report is specifically about real-world consent checkpoints and workflow resumption, not ordinary shell-command approvals.
Reproduction outline:
- Start a Codex App task with Full Access.
- Delegate an authenticated account workflow.
- Let Codex complete all form fields.
- Encounter a consent/signature control that policy requires the user to operate directly.
- Observe that Codex ends the workflow with repeated chat instructions instead of presenting one structured checkpoint and automatically resuming after the user acts.
No provider account details, order numbers, phone numbers, email addresses, or screenshots are included here.
3 Comments
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action
Related prior report: #25755 describes the same broader need to detect protected-input blockers, preserve session state, request user help once, and resume automatically. This new report narrows the problem to real-world service consent checkpoints under Full Access and asks for a structured, self-resuming user-action handoff rather than repeated chat turns.
The important distinction is authority, not just UX. A consent checkpoint should be a typed event with the exact action, target, scope, expiry, and a resume predicate. The agent can continue independent work, but the blocked branch must not inherit broader authority from Full Access or repeated natural-language approval. Once the predicate is satisfied, resumption should consume that specific checkpoint exactly once and leave an audit record.
If you want a concrete comparison, run one human-checkpoint workflow through MartinLoop and send the receipt: https://github.com/Keesan12/martin-loop