The kernel's operator is the agent that installs and runs teams for you, so kernel agents now launch with the broad permissions that job needs, and Codex runs there without a sandbox. If you'd rather keep the old behaviour, set an explicit permission choice.
Agents in the built-in kernel rig launch with wider permissions by default, so its operator can install and run teams for you. Claude Code runs in acceptEdits with an allow list for file tools, reads under your home folder and operational commands such as rig, tmux, npm, git, ssh and curl; Codex runs unsandboxed with approvals off. rig seat status reports the source as the kernel operational default.
Applies only when no explicit permission choice, member or rig policy, or (for Codex) named profile is set; set one to keep the previous behaviour. Your ask and deny rules still apply to Claude Code.
rig seat status- Release
- OpenRig 0.6.6 release notes