Earliest supported layer
Rules distinguish availability, discovery, parsing, configuration, dependency, connection, authentication, registration, exposure, activation, authorization, execution, and persistence.
Codex capability diagnosis
Include the exact action, approval/policy message, surface, and whether the prompt returns in a new session.
Local redaction. Save only by choice.
Diagnosis workspace
Not checkedYour result appears here after you review and submit the sanitized evidence.
The capability action works after approval, but Codex asks for the same permission every time I open a new session. The approval does not persist across reopen.
The earliest supported failure is authorization: the capability is reachable or activated, but the requested action is not allowed by the current provider scope, workspace policy, approval, or sandbox boundary.
The supplied evidence explicitly names forbidden/denied access, a missing scope/role, or approval that does not persist.
Separate authentication from workspace policy, approval lifetime, sandbox, or command-rule authorization.
Method and limits
Deterministic rules over your redacted evidence. What the tool cannot support, it declines to claim.
Rules distinguish availability, discovery, parsing, configuration, dependency, connection, authentication, registration, exposure, activation, authorization, execution, and persistence.
A rule must meet a deterministic threshold. Conflicting or incomplete evidence becomes partial or unknown; it is not converted into a confident root cause.
The site does not install capabilities, execute packages, contact private endpoints, edit configuration, or ask for credentials.
A diagnosis is stateless by default. Saved reports use random URLs, expire after seven days, can be deleted immediately, and are excluded from indexing.