Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- At 07:13:54 UTC October 6—15:13:54 Beijing time—Tibo @thsottiaux labeled this Day2.1: Auto-review is free for ChatGPT-signed-in users and review itself consumes no plan usage.
- The change is pricing and eligibility. The linked research was published April 30; do not call October 6 Auto-review’s first launch.
- Enable Settings → General → Permissions → Auto-review, then choose Approve for me below the chat composer. Enabling the menu does not change existing chats automatically.
- It reviews actions needing approval beyond current boundaries; it does not expand file/network permissions, inspect every already-allowed action, or perform GitHub PR review.
- The announcement does not make main tasks or API-key review free, grant resets, or cancel organization rules. Review models can misjudge; this is not a security guarantee.
Review is free, not unlimited main-task execution
At 07:13:54 UTC October 6, 2026—15:13:54 Beijing time—Tibo @thsottiaux posted Day2.1, quoting Day1’s speed announcement. He said Auto-review was now free for all ChatGPT-signed-in users, could be enabled in permissions settings, and no longer consumed plan usage. This explicitly announces changed pricing and access.
People whose long tasks are repeatedly interrupted by approvals can consider automatic review without the review allowance cost described in this announcement. Main-agent execution, model calls, and other features still follow their own usage rules. Free review is not free entire tasks, every model, or API inference.
The explicit scope is ChatGPT-account sign-in. Equivalent API-key treatment, every client’s rollout time, a universal minimum version, and all organization policies were not specified. This article checks public announcements/docs without logging into others’ accounts to verify access or metering.
It handles approval interruptions within actual boundaries
A long task has two stages: routine work inside the allowed workspace, then an approval request when it needs to go beyond current boundaries. Official docs say another reviewer agent assesses eligible requests instead of always waiting for a human click.
This differs from giving the main agent full access. It does not expand writable folders, open disabled networking, or relax protected paths. Already-allowed sandbox/rule actions generally do not get extra review. Not every command, line of code, or file read is examined by another agent.
Tibo says the reviewer focuses on risky actions and departures from original intent. Actual triggering and permissions follow current docs/configuration. The word review does not mean GitHub PR or code-quality auditing.
Desktop setup: enable the menu, then select it for this chat
First confirm your own desktop app is signed in with a ChatGPT account. In official Permissions docs, open Settings → General and enable Auto-review under Permissions. Tibo abbreviates this settings → permissions → auto-review.
Second return to the permission control below the composer and select Approve for me. Enabling it in settings only exposes the mode; it neither selects it nor changes existing chats. Check the current chat’s displayed mode to confirm this step.
Third inspect permissions and review records in an existing clearly scoped task. Do not deliberately delete, upload secrets, or access production merely to test the toggle. If unavailable, check local configuration/organization requirements; the free announcement cannot override administrator restrictions.
IDE extensions use their permission controls; CLI uses /permissions. Displays differ. Do not apply the desktop menu path to every client or invent a required version when the announcement gives none.
Why might human intervention still be needed?
There must be an approval request to review. Docs cover on-request or granular policies that still generate relevant prompts. approval_policy=never provides no such requests. Do not disable sandboxing or choose never to suppress prompts, then mistake their absence for working Auto-review.
Rejected review gives the agent a reason to seek a materially safer approach, asking the user if it cannot continue. Record the action, rejection reason, and task scope before adjusting. Changing commands repeatedly to do the same denied action is not normal recovery.
Computer Use has separate app-level authorization that still goes directly to users. A human prompt need not mean free eligibility failed; identify its permission/approval layer first.
Reconciling the free announcement with older usage wording
At this check Agent approvals & security still had generic wording that automatic review adds model calls and may increase Codex usage. Tibo’s new post explicitly says review is free and consumes no plan usage for ChatGPT-signed-in users. Preserve both source and scope: old general wording does not negate the new announcement, and the new scope does not cover every authentication method.
If actual metering or UI differs, record sign-in method, client version, time, and review record, redact project secrets, and contact official support. When review and main tasks share totals, declining remaining usage alone does not prove review was charged. No personal metering test was performed here.
Fewer interruptions still require authorization and isolation
At 07:14:06 UTC Tibo replied with OpenAI Alignment Research’s Auto-review article, dated April 30, 2026. It describes an existing mechanism and evaluation. Its reviewer model, internal interruption reductions, or pass rates are not today’s guaranteed experience for every account.
The research and current docs acknowledge possible model misjudgment without a definite safety guarantee. Project files, webpages, and tool outputs may contain untrusted instructions. Keep suitable sandboxing, monitoring, and organization rules. Free review does not remove authorization boundaries for production, sensitive data, or irreversible actions.
An explicitly numbered28-day update, not a simultaneous reset
No date or CLI-version inference is needed: Tibo labeled this Day2.1 and quoted Day1. Keep his numbering without inventing a one-feature-per-day rule. The28-day promise is meaningful improvements or full resets; this is his explicitly announced access/pricing improvement.
The post did not also announce full reset, banked reset, API credits, or cash compensation. Check your own usage/activity terms without inferring a reset from free Auto-review. Sources include the continuing28-day plan and previous speed updates.
Sources
- Tibo @thsottiaux: Day2.1 free Auto-review announcement, October 6 07:13:54 UTC
- Tibo: reply linking Auto-review research
- OpenAI: Auto-review triggers, reviewers, and boundaries
- OpenAI: enabling permission modes and selecting them in chats
- OpenAI: Agent approvals & security and generic usage notes
- OpenAI Alignment Research: Auto-review, April 30, 2026
- Tibo:28-day improvement or reset pledge
- PuppyIP: Codex28-day plan and reset explanation
Frequently Asked Questions
Is Auto-review now free?
Tibo announced October 6, 2026 that ChatGPT-signed-in users get free review without plan usage for review itself. This article has not checked every account’s UI/metering, and equivalent API-key pricing remains unconfirmed.
Does free review mean Codex tasks consume no allowance?
No. The announcement concerns review itself. Main tasks, model inference, and other features follow their own usage/pricing rules.
Does enabling it in settings switch the current chat?
No. It exposes the mode in the menu. Select Approve for me in the current chat’s permission control and check the displayed selection.
How does it differ from Full Access?
Auto-review preserves sandbox/approval boundaries and sends eligible requests to a reviewer. Full Access has different permission risks; it is not a substitute, and no prompts do not prove approval.
Why are there refusals or human prompts?
Review can reject requests; app-level Computer Use permissions still require users, and organizations may restrict modes. Read reasons/layers rather than loosening sandboxing or changing commands to evade rejection.
Is this the feature’s first launch or a reset?
Neither description fits. The mechanism predates this announcement; Day2.1 changes free access for ChatGPT sign-in, without a simultaneous usage reset.