OpenAI Adds Workspace Audit Logs for Codex Policy Changes
Authorized administrators can review changes made through Codex Policies & Configurations in the UI or retrieve them through the Compliance API.
Edited by Tyronne Panaino
OpenAI's September 11, 2026 release notes add workspace audit logging for changes made through the Codex Policies & Configurations interface. For organizations administering Codex, the material change is a reviewable history of those control changes, rather than only the settings currently in effect.
The Enterprise and Edu update record says authorized administrators can review the logs in the UI or retrieve them through the Compliance API. It does not describe unrestricted access for every workspace member.
Policy history is not a complete agent-action record
The stated scope is changes made through a particular policy and configuration interface. That is an important boundary: the announcement should not be read as evidence that every local configuration edit, command or agent action now appears in these logs.
A history of control changes can help an administrator investigate a suspected configuration change. It cannot, by itself, demonstrate that a policy was enforced in every client or that an agent's resulting work was correct. Those are separate verification questions.
UI review and API retrieval have access gates
OpenAI's Compliance Platform guidance identifies ChatGPT Enterprise and Edu workspaces as eligible. Reviewing Codex control history in Admin Console requires an eligible workspace role; retrieving it through the API requires an Admin key with the relevant log permissions.
The platform documentation also distinguishes immutable, append-only compliance events from a stateful API that queries state at request time. A record of a change and a view of current state serve different purposes. Teams evaluating the update should be clear about which question their integration is answering.
Longer retention needs a collection plan
The Compliance Logs Platform retains data for 30 days, according to OpenAI. Customers wanting a longer history are told to continuously download logs and retain them under their own policies. The feature therefore should not be assumed to provide an indefinite archive automatically.
A useful next checkpoint is a controlled policy change: confirm an authorized reviewer can find the expected record, then verify that any intended collection integration receives it. This article has not performed that workspace test or validated an event schema.
Status
Confirmed official update. Internal confidence is medium because the announcement and access guidance are vendor records, not an independent test of a deployed customer workspace.
Sources
Update note: Reviewed against official records in this release run; workspace-specific access and collection behavior remain untested.
Sources
- OpenAI — Release notes — official
- OpenAI Help — Enterprise and Edu release notes — official
- OpenAI Help — Compliance Platform — official
Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.