Four modes

How to answer a permission dialog
Default mode, and some agent-mode actions, open a permission dialog:
Requests from an external process are labeled separately. The dialog has a countdown. After timeout it closes and the model continues with the current policy. Set the timeout seconds in Settings → General → Behavior.
When the model asks you a multiple-choice question, it uses an Ask user dialog. Turn on system notifications in Settings so you do not miss it after switching windows.
Plan mode
Plan mode only grants read-only tools. The model analyzes the code, proposes a plan, then waits for your approval. Typical flow:- Switch to Plan mode
- Describe the change
- Review the plan and ask for a revision if needed
- Approve or reject it in the approval box
- After approval, let it execute

Codex sandbox
Codex has a separate sandbox policy in Settings → Permissions. It is a second layer on top of chat mode:- Mode: whether to ask you
- Sandbox: which directories and network the command can actually touch