Earliest supported layer
Rules distinguish availability, discovery, parsing, configuration, dependency, connection, authentication, registration, exposure, activation, authorization, execution, and persistence.
Codex capability diagnosis
Paste the availability, approval, sandbox, or action error and state which Codex surface is affected.
Local redaction. Save only by choice.
Diagnosis workspace
Not checkedYour result appears here after you review and submit the sanitized evidence.
Browser Use is visible and activates, but the safe navigation action is blocked by policy: permission denied by the workspace sandbox. I did not disable the sandbox.
The earliest supported failure is authorization: the capability is reachable or activated, but the requested action is not allowed by the current provider scope, workspace policy, approval, or sandbox boundary.
The supplied evidence explicitly names forbidden/denied access, a missing scope/role, or approval that does not persist.
Separate authentication from workspace policy, approval lifetime, sandbox, or command-rule authorization.
Method and limits
Deterministic rules over your redacted evidence. What the tool cannot support, it declines to claim.
Rules distinguish availability, discovery, parsing, configuration, dependency, connection, authentication, registration, exposure, activation, authorization, execution, and persistence.
A rule must meet a deterministic threshold. Conflicting or incomplete evidence becomes partial or unknown; it is not converted into a confident root cause.
The site does not install capabilities, execute packages, contact private endpoints, edit configuration, or ask for credentials.
A diagnosis is stateless by default. Saved reports use random URLs, expire after seven days, can be deleted immediately, and are excluded from indexing.