CODING AGENT · Profile revision 1

OpenAI Codex CLI

A coding-agent CLI with a public JSONL event stream and opt-in OpenTelemetry logs, metrics, and traces for execution, plans, tools, approvals, usage, and outcomes.

coding-agentjsonlopentelemetryhuman-control

Why it is in the map

Codex contributes a current machine-readable coding-agent event model and a separate public OTel contract with approval and privacy controls.

Tracevity boundary

A documented field can support reconstruction, but its presence alone does not prove completeness, authenticity, authorization, or external settlement.

Profile findings

What the documentation can—and cannot—establish

Each row distinguishes source evidence from Tracevity's bounded interpretation. “Not documented” describes the reviewed sources; it does not prove an implementation cannot record the artifact.

01

System identity

Documented

Thread, turn, item, model, and application-version data support execution correlation.

Tracevity interpretation

This does not establish a universal versioned agent-definition record.

Limit

Stable agent instance and definition/version fields are not guaranteed across every public output path.

Primary evidence (1)
02

Principal and delegation

Partially documented

Execution origin and authentication mode can be recorded without establishing the initiating human principal.

Tracevity interpretation

Originator or auth mode must not be promoted to verified identity or authority.

Limit

Authenticated principal, delegation, credential scope/expiry, and elevation are not canonical.

Primary evidence (1)
03

Instruction and context

Partially documented

Instructions and selected execution context can be partially reconstructed from messages and item events.

Tracevity interpretation

Visible items do not guarantee complete system/user instruction or context provenance.

Limit

Retrieval-source version, context fingerprint, explicit missing-context state, and complete prompt capture are not universal.

Primary evidence (1)
04

Decision artifacts

Partially documented

Plans, recorded reasoning summaries, and approval decisions can be observable artifacts.

Tracevity interpretation

A recorded reasoning item is not hidden chain-of-thought or ground-truth motive.

Limit

Selected alternative, general policy result, calibrated confidence, and refusal reason are not universal.

Primary evidence (1)
05

Model activity

Documented

Model identity, request lifecycle, errors, usage/cache categories, and timing are representable.

Tracevity interpretation

The recorded model name does not guarantee an exact provider-side build identifier.

Limit

Exact model version and complete request/response bodies depend on public capture settings and emitted fields.

Primary evidence (1)
06

Tool and MCP activity

Documented

Tool/MCP identity, calls/results, errors, timing, and item correlation are representable.

Tracevity interpretation

Tool evidence does not establish credential authority or downstream settlement.

Limit

Tool-server identity, retry, and downstream provider correlation are not uniformly guaranteed.

Primary evidence (1)
07

Effects

Partially documented

Some local effect types and reported changes are explicitly represented.

Tracevity interpretation

A command or file-change event cannot prove that a remote API, message, or transaction settled.

Limit

Provider acceptance, external effect state, and independently observed state delta are not universal.

Primary evidence (1)
08

Human control

Documented

Approval/denial and its user-versus-configuration source are explicit public telemetry artifacts.

Tracevity interpretation

Policy-sourced approval is not evidence of a contemporaneous human decision.

Limit

Human edit, takeover, rollback request, reviewer identity, and delegated authority are not universal.

Primary evidence (1)
09

Outcome

Documented

Runtime completion, failure, error, and tool-reported success can be reconstructed.

Tracevity interpretation

These outcomes do not independently verify external destination state.

Limit

External verification, ambiguous settlement, rollback, and compensation are not first-class public events.

Primary evidence (1)
10

Trace integrity

Not documented

Public JSONL and OTel provide transportable events, not documented evidence integrity.

Tracevity interpretation

Session identity and timestamps do not make records tamper-evident or independently verifiable.

Limit

Clock provenance, immutability, append-only behavior, signature, tamper evidence, and independent verification are absent.

Primary evidence (1)
11

Portability

Documented

JSONL, OTLP, and SDK/app-server interfaces provide multiple public integration surfaces.

Tracevity interpretation

Transport options do not guarantee lossless mapping between Codex item types and OTel events.

Limit

JSONL schema version, import destinations, documented conversion, and exact semantic loss are not established.

Primary evidence (1)
12

Privacy

Partially documented

Public controls limit prompt telemetry and local persistence, but sensitive execution output may still be captured.

Tracevity interpretation

This profile is public-doc-only and makes no claim about undocumented desktop internals or private local/backend files.

Limit

Universal retention, deletion, redaction coverage, screenshots, hashing, and hosted behavior are not established by the cited public pages.

Primary evidence (1)

Reconstruction reading

Do not collapse these findings into one score.

This profile describes documented evidence surfaces. Whether they are sufficient depends on the reconstruction question and the other identity, authorization, tool, and destination records available.

Potentially useful evidence

  • Identity: Thread, turn, item, model, and application-version data support execution correlation.
  • Principal: Execution origin and authentication mode can be recorded without establishing the initiating human principal.
  • Context: Instructions and selected execution context can be partially reconstructed from messages and item events.
  • Decisions: Plans, recorded reasoning summaries, and approval decisions can be observable artifacts.
  • Models: Model identity, request lifecycle, errors, usage/cache categories, and timing are representable.

Explicit gaps or uncertainty

  • Integrity: Clock provenance, immutability, append-only behavior, signature, tamper evidence, and independent verification are absent.

Source register

4 reviewed primary sources

  1. Non-interactive modeOpenAI · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗
  2. Advanced configurationOpenAI · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗
  3. Configuration referenceOpenAI · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗
  4. Codex SDKOpenAI · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗

Next question

What evidence does your use case require?

Move from documented field presence to an explicit reconstruction target, or examine selected directional format mappings without changing this system's documentation posture.

Trace Reconstruction Requirements Explore compatibility evidence