Boundlane Sheet D-202 / Default access

D-202 Use

Default access

What an agent can read, write, and reach in a new sandbox when the project has no boundlane.yaml. The short version: the project copy is writable, four hosts are readable, the model API works with a key the agent cannot see, and everything else is closed.

Policy: developer-defaultFree plan

Files

PathAccessWhy
/sandbox/<project>Read and writeThe copy of your project. The agent starts here.
/sandboxRead and writeThe agent's home folder, so its own settings stay out of your project and out of the diff.
/tmp, /dev/nullRead and writeScratch space. Gone when the sandbox is deleted.
/bin, /usr, /lib, /etc, /appRead onlyThe image's programs and libraries.
/proc, /var/log, /dev/urandomRead onlyWhat ordinary programs expect to find.

Your home folder is not in the list because it is not in the sandbox at all. ~/.aws, ~/.ssh, your shell history, and other repositories were never copied in. Files matched by .gitignore, and .git itself, were not copied either. See Workspace and changes.

Hosts

HostAccessUsed for
api.github.comread-onlyReading issues, pull requests, and repository metadata.
registry.npmjs.orgread-onlyInstalling npm packages.
pypi.orgread-onlyPython package index.
files.pythonhosted.orgread-onlyPython package downloads.

read-only means GET, HEAD, and OPTIONS. Pushing to GitHub, publishing a package, or posting anywhere is denied. Every other host is refused at DNS and at connect.

What each agent adds

The policy does not list model APIs. Each agent's key comes with the endpoints it is bound to, and those are added when the sandbox is created. Some agents also need a host for their own start-up check, which gets a read-only rule and never the key.

AgentModel endpoint, with the keyOther hosts, without the key
Claude Codeapi.anthropic.com:443platform.claude.com:443, read-only. Claude Code checks it on first start.
Codexapi.openai.com:443None.
OpenCodeapi.anthropic.com:443None. This catalog entry is Anthropic only.
Grokapi.x.ai:443None.

Claude Code also runs with CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1, its own documented switch for telemetry, error reports, and update checks. Without it, those calls would be refused and file a request on every run. OpenCode runs with its update check, model-list refresh, language-server downloads, and default plugins turned off, and with its provider list limited to Anthropic. The image also skips a plugin install OpenCode would otherwise try on startup. With those, a start reached only api.anthropic.com. Grok runs with its update check off and its own sandbox off. A start reached only api.x.ai.

Processes

The agent runs as an unprivileged sandbox user, not root, under Docker and Podman. Under the MicroVM driver it runs as the user the driver configures. Raw sockets are blocked, so a program cannot open its own path around the proxy. Programs the agent starts, such as git, pip, or npm, inherit the agent's network rules. A program started some other way does not.

Keys

The agent's environment holds a placeholder where the key would be. The real key is added on the way out, only on requests to the model endpoint above. See Model keys.

Asking for more

When the task needs a host that is not listed, the sandbox drafts a request from the refused call. Agents that get Boundlane's guide can also file one themselves, through the sandbox's local policy API, with a reason. A person approves or denies it. See Requests and approvals.

To give every run on a project the same extra hosts, add them to boundlane.yaml. See Adding hosts for a project.

See it yourself

boundlane policy compile --agent claude

That prints the exact policy the sandbox would get, without starting anything.