I kept getting burned by “what permissions am I running with?” so I built Codeman: a thin launcher around codex that forces
an explicit security level each run (read-only, orkspace-write, networked, full), with a clear confirmation panel before higher-risk modes. It also supports resuming by session UUID and optional Slack/Discord webhook notifications. Repo:
https://github.com/shabo/codeman Feedback welcome: naming, UX, and whether the level breakdown matches how you actually work
with Codex.