# Local and cloud repository-access worksheet

Record where code comes from, which identity authorises access and who owns the resulting records.

Illustrative access paths and blank observations. No repository grant or product test is performed.

Source: https://aona.ai/resources/guides/codex-local-cloud-repository-access/
Sources checked: 2026-09-21

## Two repository access paths

### Local path

Device identity → accessible workspace → local client

Note: Review roots and permissions

### Hosted path

Source-system grant → selected checkout → cloud environment

Note: Review repository and audience

### Shared review

Code context → model handling and task records

Note: Confirm the applicable terms

| Path | Authorisation to verify | Observation |
| --- | --- | --- |
| Local workspace | Device identity and effective roots | Untested |
| Hosted checkout | Source-system grant and selected repository | Untested |
| Task records | Applicable workspace/provider handling | Unreviewed |
| External source system | Its own access and retained records | Unreviewed |

## Review checklist

- [ ] Identify both access identities
  Distinguish local device permissions from the connected source-system account and repository grant.
- [ ] Record the permitted repository audience
  Use least-necessary scope and a representative authorised reviewer.
- [ ] Review retained records separately
  Access revocation, source-system records and task data are different questions.

## Included example files

- README.md
- local-cloud-access.csv
- access-decision.md

## Source references

- OpenAI: Agent approvals and security: https://learn.chatgpt.com/docs/agent-approvals-security (2026-09-21)
- OpenAI: Enterprise admin setup: https://learn.chatgpt.com/docs/enterprise/admin-setup (2026-09-21)
- OpenAI: Cloud environments: https://learn.chatgpt.com/docs/environments/cloud-environment (2026-09-21)
- OpenAI: Enterprise Work admin FAQ: https://learn.chatgpt.com/docs/enterprise/work-admin-faq (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
