PonoLens guide

Codex vs. Claude CLI activity: what can local tools actually observe?

Local monitoring depends on the connections each AI coding tool provides. The coverage is not identical.

Codex

PonoLens can observe supported Codex session records and connect prompts with reported tool activity. Codex side-chat prompts are observed after submission, so PonoLens cannot stop those prompts before they are sent.

Claude CLI

Claude CLI provides supported hooks at points such as prompt submission and tool use. When those hooks are configured and running, PonoLens can receive the available event before or during an action. Experimental Block or Redact behavior depends on that hook.

What both have in common

  • PonoLens works from records and hooks supplied by the tool.
  • It can explain only the activity made available to it.
  • Report Only is the stable default.
  • Records stay on the Mac. Prompt text is redacted by default; other receipt fields remain redacted even if a user explicitly turns prompt-text redaction off.
Observed, sent, and blocked mean different things. Observed means PonoLens recorded evidence. Sent means the integration indicates data left the device. Blocked means a supported adapter actually stopped the action before it completed.

Why the difference matters

A green record does not prove an entire AI tool is safe. It means PonoLens did not find configured private information or unusual movement in the evidence it received. Always review each tool’s own privacy settings and current documentation.

Read next

How freelancers can use AI without mixing customer information →