Codex generates freely. AxiomGate lets it act only within explicit authority: right identity, right target, enforced at the Codex hook. And it lets Codex claim done only with a tamper-evident Build Receipt anyone can verify offline.
Across 2,208 prompt variants, UnderSpecBench measured action-boundary violation rates of 55.8-67.8%, including Wrong Target and OverScope cases. AxiomGate is the layer that stops that.
$npx axiomgate replay all$ axiomgate mission run◆ contract msn_lockout · sha256:d5548d7d9c… ✕ DENY preview.deploy · PreToolUse 'acme-staging' is not owned by mokimeow EXISTS_NOT_OWNED · recorded as evidence ✓ PASS lockout engages after 5 failed logins · evd_impl✓ PASS the change exposes no secrets · evd_secr $ axiomgate receipt verify✓ PASS receipt integrity · 5/5 checks · offline
A mission is compiled into a versioned, hashed contract before Codex writes a line. Every action and every claim of done is checked against it by machinery, not by the model's self-report.
Objective and acceptance criteria compiled into a hashed contract.
Identity resolved. Every action policy-checked at the Codex hook.
Codex builds under sandbox and intent boundary. Usage is ledgered.
Tests and scanners produce machine evidence. Model claims don't count.
Completion gated on evidence. A tamper-evident receipt is emitted.
Every mission ends in a Build Receipt: contract hash, commit, and a hash-chained evidence trail for every criterion. Anyone can verify it offline. No server, no account, no trust in the agent's word.
Three commands. No cloud, no account. Mission state lives in your workspace's .axiomgate/ directory and receipts verify offline.
Give Codex real authority boundaries and demand real evidence back. Plan. Govern. Execute. Prove.