Codex 0.160 Guardian review reads prior instructions: Sume args
Codex CLI 0.160 adds opt-in Guardian review that can fetch earlier user instructions. Write Sume calls so a reviewer can approve them from the arguments alone.

Codex CLI 0.160.0 (2026-10-01) adds opt-in Guardian review capabilities to retrieve prior user instructions and include context from agent handoffs (read 2026-10-03). For Sume's paid MCP tools, that helps a reviewer judge whether a call matches what the person asked, but the arguments still have to carry the facts. A call with dry_run, max_spend_usd, and a descriptive idempotency_key can be approved from its own text; a call with none of them forces the reviewer to guess.
The Codex entry is on the Codex changelog. The Sume gates come from MCP tools and gates. The retry behavior of the same review loop is covered in the approval review retry post.
What a reviewer can check
A reviewer, human or model, compares three things: the instruction the user gave, the tool the agent chose, and the arguments it passed. Instruction retrieval improves the first. Sume's documented gates improve the third, because they put cost intent in the call itself. A call that says dry_run: true is obviously safe to approve; one that says max_spend_usd: 2 states its own ceiling; and an idempotency_key such as launch-banner-v2-001 names the work.
| Argument | What it tells a reviewer | Required? |
|---|---|---|
dry_run: true | Preview only, nothing submitted | Optional |
max_spend_usd | Declared spend ceiling | Optional, enforced when present |
idempotency_key | Dedup identity, ideally readable | Required on write and paid |
payload.model | Named family; omitted routes to sume/auto | Optional |
Instruction text that makes calls reviewable
Put the reviewable habits in the instruction file Codex reads, since Guardian looks at what the agent did against what it was told. Keep the text specific about arguments, not about attitude.
- Name every idempotency key after the task and a counter, never a random string.
- Pass
max_spend_usdon every paid call, using the number from the preview. - Preview first for any burst or any call you cannot size from the prompt.
- Never paste signed URLs or tokens into arguments; Sume tells agents to prefer public ids and media URLs in reports.
Key naming helper
A readable key also makes the Sume side easier to audit afterwards, because jobs_list can be matched to the task. This helper builds keys that are stable for a retry and unique per item.
import re
def idem_key(task: str, item: int, attempt_group: str = "a") -> str:
slug = re.sub(r"[^a-z0-9]+", "-", task.lower()).strip("-")[:40]
return f"{slug}-{attempt_group}-{item:03d}"
if __name__ == "__main__":
for i in range(3):
print(idem_key("Launch banner v2", i))Remember what the review cannot do. It does not change Sume's own rules: an OAuth session with only mcp:read still gets insufficient_scope on a paid call, however well the call was reviewed, and there is no mcp:paid scope, so spend is decided by wallet and admission. Treat review as a second opinion on intent, and keep the cap in the call as the first line of defense. If a session reconnects and resends a queued message, the same key makes the resend harmless.
What to do when the reviewer says no
A refusal is information. If the reviewer blocks a paid call, read why before retrying: it usually says the call did not match the request, the cost was unclear, or an argument looked wrong. The cheapest fix is a dry_run call that shows the estimate, then a new submit that cites it in max_spend_usd. Do not reword the same call with a fresh idempotency_key hoping for a different outcome; a new key is a new request, and if the first approval was in fact granted somewhere, you may start two jobs.
If the reviewer keeps blocking reads, such as jobs_status, check the tool list: a client-side setting may be treating every MCP tool as sensitive. Allowlist the read tools by name and keep the review for the creates. Sume's read tools do not spend, and a review that fires on every poll just trains people to approve without reading.
Sources
Related posts
More in Agents
- Codex config.toml enabled_tools and required for Sume's read tools
Codex's MCP config can allowlist tools with enabled_tools and fail startup with required. Give a task only Sume's read and wait tools and a longer timeout.
- Can I create a Sume scheduled agent by API? Read and run, not create
The Sume API can list, read, run and monitor scheduled agents, but not create, edit or delete them. Authoring is the dashboard or the Agent chat.
- Fire a cron schedule on demand: api_trigger_enabled, cron kept
A Sume cron schedule can also accept API runs. Turn on api_trigger_enabled and your service can start it now without touching the cadence.
- Hermes Agent cron job that starts a Sume Format run
A Hermes cron job begins with no memory of last week. Write the prompt, idempotency key, spend cap and SILENT or CRON_FAILURE reply so a Sume run starts once.
Written by Sume