Gemini CLI and Codex CLI

Both are handled by the standard adapter path: detected automatically, connected by Govern all detected tools or individually from their card, and disconnected the same way.

Connecting

Tools, find the card, Connect. Then restart your terminal — like every other command-line tool here, they read their environment at startup.

Connection mode

Both appear in Policy → Connection modes in the admin console, where an admin chooses whether they run on the developer's own subscription or on the organization's managed provider key.

Codex CLI and posture

Codex CLI has settings that materially change how much autonomy the agent has, and the Endpoint Suite reports on them:

These are reported, not blocked. They appear as posture findings on the device in the admin console's Diagnostics screen, so an admin can have a conversation about them. See Posture findings.


Revision #8
Created 2026-08-02 10:19:40 UTC by Sentilai Docs
Updated 2026-08-02 16:30:16 UTC by Sentilai Docs