CODING AGENT · Profile revision 1
OpenAI Codex CLI
A coding-agent CLI with a public JSONL event stream and opt-in OpenTelemetry logs, metrics, and traces for execution, plans, tools, approvals, usage, and outcomes.
Why it is in the map
Codex contributes a current machine-readable coding-agent event model and a separate public OTel contract with approval and privacy controls.
Tracevity boundary
A documented field can support reconstruction, but its presence alone does not prove completeness, authenticity, authorization, or external settlement.
Profile findings
What the documentation can—and cannot—establish
Each row distinguishes source evidence from Tracevity's bounded interpretation. “Not documented” describes the reviewed sources; it does not prove an implementation cannot record the artifact.
System identity
DocumentedThread, turn, item, model, and application-version data support execution correlation.
Tracevity interpretation
This does not establish a universal versioned agent-definition record.
Limit
Stable agent instance and definition/version fields are not guaranteed across every public output path.
Primary evidence (1)
- OpenAI: Non-interactive mode thread.started, turn lifecycle, and item events
Principal and delegation
Partially documentedExecution origin and authentication mode can be recorded without establishing the initiating human principal.
Tracevity interpretation
Originator or auth mode must not be promoted to verified identity or authority.
Limit
Authenticated principal, delegation, credential scope/expiry, and elevation are not canonical.
Primary evidence (1)
- OpenAI: Advanced configuration OpenTelemetry resource attributes
Instruction and context
Partially documentedInstructions and selected execution context can be partially reconstructed from messages and item events.
Tracevity interpretation
Visible items do not guarantee complete system/user instruction or context provenance.
Limit
Retrieval-source version, context fingerprint, explicit missing-context state, and complete prompt capture are not universal.
Primary evidence (1)
- OpenAI: Non-interactive mode JSONL item types
Decision artifacts
Partially documentedPlans, recorded reasoning summaries, and approval decisions can be observable artifacts.
Tracevity interpretation
A recorded reasoning item is not hidden chain-of-thought or ground-truth motive.
Limit
Selected alternative, general policy result, calibrated confidence, and refusal reason are not universal.
Primary evidence (1)
- OpenAI: Non-interactive mode Plan update and recorded reasoning item types
Model activity
DocumentedModel identity, request lifecycle, errors, usage/cache categories, and timing are representable.
Tracevity interpretation
The recorded model name does not guarantee an exact provider-side build identifier.
Limit
Exact model version and complete request/response bodies depend on public capture settings and emitted fields.
Primary evidence (1)
- OpenAI: Advanced configuration API request, stream, model, timing, and usage telemetry
Tool and MCP activity
DocumentedTool/MCP identity, calls/results, errors, timing, and item correlation are representable.
Tracevity interpretation
Tool evidence does not establish credential authority or downstream settlement.
Limit
Tool-server identity, retry, and downstream provider correlation are not uniformly guaranteed.
Primary evidence (1)
- OpenAI: Non-interactive mode Command, file change, MCP, web search, and item lifecycle events
Effects
Partially documentedSome local effect types and reported changes are explicitly represented.
Tracevity interpretation
A command or file-change event cannot prove that a remote API, message, or transaction settled.
Limit
Provider acceptance, external effect state, and independently observed state delta are not universal.
Primary evidence (1)
- OpenAI: Non-interactive mode Command execution and file change item types
Human control
DocumentedApproval/denial and its user-versus-configuration source are explicit public telemetry artifacts.
Tracevity interpretation
Policy-sourced approval is not evidence of a contemporaneous human decision.
Limit
Human edit, takeover, rollback request, reviewer identity, and delegated authority are not universal.
Primary evidence (1)
- OpenAI: Advanced configuration Tool decision event and approval source
Outcome
DocumentedRuntime completion, failure, error, and tool-reported success can be reconstructed.
Tracevity interpretation
These outcomes do not independently verify external destination state.
Limit
External verification, ambiguous settlement, rollback, and compensation are not first-class public events.
Primary evidence (1)
- OpenAI: Non-interactive mode turn.completed, turn.failed, error, and result events
Trace integrity
Not documentedPublic JSONL and OTel provide transportable events, not documented evidence integrity.
Tracevity interpretation
Session identity and timestamps do not make records tamper-evident or independently verifiable.
Limit
Clock provenance, immutability, append-only behavior, signature, tamper evidence, and independent verification are absent.
Primary evidence (1)
- OpenAI: Non-interactive mode JSONL output and ephemeral execution
Portability
DocumentedJSONL, OTLP, and SDK/app-server interfaces provide multiple public integration surfaces.
Tracevity interpretation
Transport options do not guarantee lossless mapping between Codex item types and OTel events.
Limit
JSONL schema version, import destinations, documented conversion, and exact semantic loss are not established.
Primary evidence (1)
- OpenAI: Configuration reference OTel log, metric, and trace exporters
Privacy
Partially documentedPublic controls limit prompt telemetry and local persistence, but sensitive execution output may still be captured.
Tracevity interpretation
This profile is public-doc-only and makes no claim about undocumented desktop internals or private local/backend files.
Limit
Universal retention, deletion, redaction coverage, screenshots, hashing, and hosted behavior are not established by the cited public pages.
Primary evidence (1)
- OpenAI: Advanced configuration OpenTelemetry disabled by default and log_user_prompt control
Reconstruction reading
Do not collapse these findings into one score.
This profile describes documented evidence surfaces. Whether they are sufficient depends on the reconstruction question and the other identity, authorization, tool, and destination records available.
Potentially useful evidence
- Identity: Thread, turn, item, model, and application-version data support execution correlation.
- Principal: Execution origin and authentication mode can be recorded without establishing the initiating human principal.
- Context: Instructions and selected execution context can be partially reconstructed from messages and item events.
- Decisions: Plans, recorded reasoning summaries, and approval decisions can be observable artifacts.
- Models: Model identity, request lifecycle, errors, usage/cache categories, and timing are representable.
Explicit gaps or uncertainty
- Integrity: Clock provenance, immutability, append-only behavior, signature, tamper evidence, and independent verification are absent.
Source register
4 reviewed primary sources
- Non-interactive modeOpenAI · OFFICIAL DOCUMENTATION · observed August 28, 2026 · currentOpen source ↗
- Advanced configurationOpenAI · OFFICIAL DOCUMENTATION · observed August 28, 2026 · currentOpen source ↗
- Configuration referenceOpenAI · OFFICIAL DOCUMENTATION · observed August 28, 2026 · currentOpen source ↗
- Codex SDKOpenAI · OFFICIAL DOCUMENTATION · observed August 28, 2026 · currentOpen source ↗
Next question
What evidence does your use case require?
Move from documented field presence to an explicit reconstruction target, or examine selected directional format mappings without changing this system's documentation posture.
Trace Reconstruction Requirements Explore compatibility evidence