D-104 Start
Security model
The model is not trusted, and neither is the agent process. The rules live in the sandbox, outside both, so a bad prompt or a confused plan cannot move them. This sheet says what each layer stops and who has to be trusted for that to hold.
Who is trusted
| Party | Trusted with | Not trusted with |
|---|---|---|
| The model | Nothing. Its output is treated as untrusted input. | Deciding what the agent may touch. |
| The agent process | The project copy, and the hosts the policy lists. | Your home folder, your keys, other hosts, or approving its own requests. |
| The sandbox runtime | Enforcing the policy and holding keys. It runs on your machine. | Talking to our cloud. It has no connection to us. |
| The person approving | Opening a door the policy did not list. | Moving a wall in a running sandbox. Paths change only in the next one. |
| The machine's owner | On Free and Team, everything on that machine, including the runtime. | On License, the gateway. It runs where they do not administer it. |
| Our cloud | Policy text and decision records, on Team. | Source code, file contents, terminal output, the agent's conversation, model keys, or Git tokens. |
What each layer stops
| The agent tries to | What stops it | What the agent sees |
|---|---|---|
Read ~/.aws or ~/.ssh | Your home folder is not in the sandbox. Only the project copy is uploaded. | The file does not exist. |
| Write outside the project | Filesystem rules, enforced by Landlock in the kernel. | Permission denied |
| Call a host the policy does not list | The sandbox's network namespace and its policy proxy. DNS and the connection are both refused. | A failed connection. The reason is in the log. |
| Use a listed host in a way the rule does not allow | The proxy reads the request and checks method and path. | HTTP 403 with policy_denied and the rule that is missing. |
| Skip the proxy with a raw socket | Seccomp blocks raw sockets. Direct connections are refused. | Protocol not supported or Permission denied |
| Use a listed host from another program | Each rule names the programs allowed to use it, by real path. Programs the agent starts inherit its rules; others do not. | A refused connection. |
| Read the model key | The agent holds a placeholder. The runtime adds the real key on the way out, and only on requests to the endpoints bound to that key. | The placeholder. |
| Approve its own request | Approvals are a person's action, outside the sandbox. Automatic approval is never turned on. | A request that waits. |
Each row comes from the runtime's own enforcement. Boundlane writes the policy and checks it. It does not add a second enforcement layer of its own, and it does not ask the agent to behave.
Checked before start
Before a sandbox starts, the compiled policy is checked by OpenShell's policy prover against a boundary. After the sandbox is created, the policy it actually holds, including the endpoints each key adds, is checked again. If either check finds an action outside the boundary, nothing runs. See The check before start.
The prover shows what a policy allows. It does not show that the agent is good, and we do not present it that way.
When rules change
Network rules can change while a sandbox runs. Filesystem and process rules cannot. A change to paths or workspace access takes effect in the next sandbox, and Boundlane says so instead of pretending a running agent picked it up. See Walls and doors.
What a laptop cannot enforce
A developer owns their laptop and the runtime on it. They can change it, approve their own requests, or start an agent outside Boundlane. Team cannot prevent that. It records it as drift. Enforcement the machine's owner cannot change needs a gateway they do not administer, which is the License plan.
Channels outside the sandbox
Some traffic leaves through an allowed path. The clearest case: Claude Code's web search runs on Anthropic's side. The only request the sandbox sees is the call to the model API, so search queries leave inside that call, and the sandbox cannot block them without blocking the model. If that matters, turn web search off in the agent's own settings or your Anthropic organization. That setting is not enforced by the sandbox. The full list is in Known limits.