Boundlane Sheet D-208 / Decision log

D-208 Use

Decision log

Every network call the agent makes is allowed or denied by the sandbox, and each decision is recorded with the program, the destination, and the rule. When something is blocked, you get a log line instead of a story.

Command: boundlane logNetwork decisions

Read the log

boundlane log
Example output
time      action   process  destination                   rule
10:42:05  allowed  claude   POST api.anthropic.com/v1/messages  _provider_bl-claude
10:42:07  denied   curl     paste.example.net:443         -
10:42:31  allowed  python3  GET pypi.org/simple/requests/  pypi_org
10:43:12  reset    node     registry.npmjs.org:443        policy changed, the client reconnects

Without flags, log shows the latest sandbox for the folder you are in. Outside a project, it shows the latest one overall and says which.

Flags

FlagShows
--denyDenies only, with the sandbox's reason for each.
--since 10mOnly the last ten minutes. Any duration works: 30s, 2h.
--followKeeps printing as the agent works. For a running sandbox.
--sandbox <name>A specific sandbox, running or finished.
--rawEverything the sandbox logged, as the runtime wrote it: settings changes, policy loads, closed connections.

What a deny reason means

ReasonMeaningThe agent saw
policy_dns_ineligibleThe host is not in the policy, so its name was not resolved.Could not resolve host.
transparent_tcp_policy_deniedA connection to a host or address the policy does not list.Could not connect.
binary ... not allowed in policyThe host is listed, but not for this program. The line names the program and the programs above it.A refused connection.
policy_deniedThe host is listed, but the rule does not allow this method or path.HTTP 403 with the same reason in JSON.

The first two look like a network outage from inside the sandbox. That is why the log, not the agent's error, is where to start. See A blocked host looks like a network error.

reset lines

When the network policy changes, for example after an approval, the sandbox closes open connections so that every new one is checked against the new rules. Those show up as reset. The client reconnects. Nothing was refused, so --deny leaves them out.

Where it is kept

While the sandbox runs, log reads the runtime's stream. Deleting a sandbox deletes the runtime's copy, so when the agent exits Boundlane waits until the log stops growing and saves it to ~/.cache/boundlane/runs/<sandbox>/sandbox.log before it asks whether to delete the sandbox. Finished sandboxes are read from that file.

Decisions are recorded in OCSF, an open schema for security events, so they line up with what a SIEM already expects.

What the log does not hold

  • Blocked file writes. The runtime does not record them. The agent sees Permission denied.
  • Request bodies, headers, and query strings. A decision names the method and path, never the payload.
  • The agent's conversation or terminal output. Those stay in your terminal.
  • Calls the sandbox never sees. If a model vendor runs a tool on its own side, such as Claude Code's web search, the only line is the call to the model API. See Known limits.

On Team

boundlane forward sends each decision to the console, where you can filter by machine, sandbox, destination, or action across the whole team. If part of the stream was lost, the console shows the gap instead of hiding it. See Forwarding decisions. The same records export as JSONL for your own tools.