Boundlane Sheet D-207 / Workspace and changes

D-207 Use

Workspace and changes

Your project is copied into the sandbox, not mounted. The agent works on the copy. When it is done, the copy comes back to a staging folder, you read the diff, and nothing touches your repo until you apply it.

Copy in, copy outYou apply

What goes in

boundlane run copies the folder you run it from to /sandbox/<folder>, and the agent starts there.

  • Files matched by .gitignore are left out. So are build output and dependencies, if your .gitignore lists them.
  • .git is left out. The sandbox has no history, no remotes, and no Git credentials.
  • If the copy includes files that look like secrets, such as .env or a private key, run names them before it starts. Add them to .gitignore if the agent should not see them.

Before the copy, Boundlane records a fingerprint of every file it sends. That is what the diff and the conflict check compare against later.

To start with an empty folder instead, use boundlane run --no-upload -- claude.

What comes back

When the agent exits, or when you run boundlane stop, the project folder is copied out of the sandbox to ~/.cache/boundlane/staging/<sandbox>. run then shows the changes and asks what to do with them, and only after that asks whether to keep the sandbox. Deleting the sandbox does not touch the staged copy. stop deletes it after asking. If the copy fails, the sandbox is kept, so nothing is lost. --keep on run keeps it without asking.

Only the project folder comes back. The agent's own settings live in its home folder, /sandbox, outside the project, so they stay out of the diff.

Read the diff

boundlane diff
Example output
■ 3 files changed from the agent  not applied yet

  deleted src/legacy-router.ts  −31
  new     src/routes.test.ts    +18
  edited  src/routes.ts         +2 −1
                                +20 −32 in total

── src/routes.ts  edited  +2 −1
    12   import { Router } from "./router";
    13 - import { legacy } from "./legacy-router";
    13 + import { health } from "./health";
    14 + import { users } from "./users";
    15
    16   export const routes = new Router();

Nothing in ~/src/web has changed. boundlane apply copies them in.

Added, edited, and deleted files are all listed with their line counts, then each file's changed lines with three lines around them. Removed lines are marked -, added lines +. Long output opens in your pager. Binary files and very large rewrites show their counts only. --stat prints the list without the lines. The comparison is built in; git is not needed.

Apply

boundlane apply

Shows the list, then asks: apply them, show the changes, or keep them for later. Applying writes the changes into your repo and clears the staging folder. Keeping them changes nothing, and they stay staged until you apply. --yes applies without asking. It refuses if any of those files changed on your side since the agent started, and lists them, so you never lose your own edits to the agent's. Resolve them and run it again.

  • Symbolic links and special files are not applied. A link could point outside the project.
  • Nothing is written outside the project folder, whatever path the staged copy names.
  • Each file is written in full and moved into place, so an interrupted apply does not leave half a file.

Then commit as you normally would. The agent does not commit or push. The changes arrive as files in your working tree, and your Git history is yours.

Several runs on one project

Each sandbox has its own staging folder. diff and apply pick the latest sandbox for the folder you are in; pass --sandbox <name> for an earlier one. boundlane ps --all lists finished sandboxes whose changes you can still read.

On Team

The workspace never leaves the machine. The control plane receives decision records, not files. See What our cloud receives.