D-307 Team
License plan
The same control plane, in your VPC. Code, decisions, and approvals stay in your account, and gateways can run where developers do not administer them. That is the difference between recording what a laptop did and enforcing it.
What it adds to Team
| Team | License | |
|---|---|---|
| Control plane | Hosted by us | In your VPC |
| Decision records | Sent to us, kept 90 days by default | Kept in your account, for as long as you set |
| Sign-in | Console accounts | Single sign-on through your identity provider |
| Export | JSONL | JSONL, plus SIEM export |
| Gateways | On developers' machines | On developers' machines, and on your cluster |
| Enforcement against the machine's owner | No. Changes show as drift. | Yes, for agents that run on a cluster gateway. |
Where sandboxes run
On laptops. The same as Team. The developer's machine runs the gateway, and the policy comes from your control plane instead of ours. A developer can still change their own machine, and the console records it.
On your cluster. Agents that run in CI or on shared workers start in sandboxes on a gateway in your Kubernetes cluster. Developers submit work to it. They do not administer it, so they cannot loosen its policy, approve their own requests, or delete its logs.
In both cases the gateways dial out to the control plane. Nothing needs an inbound port, and nothing reaches our cloud.
The Kubernetes install
The install pins the sandbox runtime's chart to a tested version and runs the forwarder in the cluster, next to the gateway.
Kubernetes accepts a NetworkPolicy object even when the cluster's network plugin ignores it. If it is ignored, a sandbox's traffic can skip the policy proxy. The install tests that egress policy is actually enforced on your cluster, not only accepted, and refuses to finish if it is not.
The documentation for the install lists the network plugins we have tested.
Single sign-on
The console and boundlane login go through your identity provider, so people sign in with the account they already have and you manage access in one place.
SIEM export
Decision records are OCSF, an open schema for security events, so they need no translation layer. Export them as JSONL, push them to a webhook, or let your SIEM poll for them. Formats for specific tools are built on the same records, not on a separate collector.
Buying it
There is no public price in the first version. Join the waitlist and say why you want Team or License. Your cloud bill stays yours: the control plane and the cluster gateways run on your infrastructure, and we do not bill sandbox hours. See Price.