Boundlane Sheet D-405 / Glossary

D-405 Reference

Glossary

The words these docs use, in one place. Where a word comes from the sandbox runtime, it means what the runtime means by it.

Alphabetical

Terms

Agent
A command-line program that uses a model to read and change code, such as Claude Code or Codex. Boundlane starts it inside a sandbox. See Agents.
Approval
A person's decision to open a door the policy did not list. It applies to the running sandbox and lasts as long as that sandbox. See Requests and approvals.
Boundary
The outer limit a policy is checked against. On Free it is compiled from the same file plus the agent's key endpoints. On Team the security lead publishes it.
Bundle
A team policy document and its revision number, signed by the control plane. Machines accept only a bundle with a valid signature and a higher number than the one they hold.
Catalog
The list of agents Boundlane knows how to start: each one's command, image, pinned version, program paths, key, and hosts.
Console
The Team web app. Publish policies, see machines, read decisions, review requests.
Control plane
The service behind the console. It stores policy revisions and decision records. It never connects to a developer's machine and never holds model keys.
Decision
One allow or deny the sandbox recorded for a network call: time, program, destination, rule, and for a deny, the reason. See Decision log.
Door
A network rule. Doors can change while the agent runs: an approval or a host change loads into the running sandbox.
Drift
A machine whose sandboxes do not match the published policy, or an approval that did not come from the console. See Drift.
Forwarder
boundlane forward. It runs on the developer's machine and sends decisions and requests to the console. See Forwarding decisions.
Gap
A record that says part of a sandbox's decision stream was lost, with the time span. Shown in the console instead of being hidden.
Gateway
The runtime's control process on a machine or a cluster. It holds sandboxes, their policies, and the stored keys.
OCSF
Open Cybersecurity Schema Framework. The open format the runtime writes decisions in, which is why they line up with a SIEM.
Placeholder
What the agent sees where its model key would be. The runtime replaces it with the real key on the way out, only on requests to that key's endpoints.
Policy
The short file that says what the agent may touch: boundlane.yaml on a project, or the team policy on Team. Boundlane compiles it into the runtime's own policy format. See Policy file.
Profile
The endpoints an agent's key may be sent to, and the programs allowed to send it. Boundlane ships a reviewed copy per agent.
Prover
The runtime's policy checker. It compares a compiled policy with a boundary and returns within_boundary, or the action that goes past it. Nothing starts without a pass.
Request
An ask for more network access, drafted by the sandbox from a refused call or filed by the agent with a reason. It waits for a person.
Revision
A numbered, published version of a team policy. Numbers only go up. See Publish and revisions.
Sandbox
The isolated environment the agent runs in, created fresh for each run. It holds a copy of the project, not your machine.
Staging
The folder on your machine where the agent's changes wait after the sandbox ends, until you run boundlane apply. See Workspace and changes.
Supervisor
The runtime's enforcement process inside each sandbox. It applies the filesystem and process rules at start, and runs the proxy every network call goes through.
Wall
A filesystem or process rule. Walls are fixed when a sandbox is created. Changing one means a new sandbox, and Boundlane says so.