Boundlane Sheet A-701 / Inspection

A-701 Inspection

Inspection before move‑in.

The wrong file, the wrong host, and a prompt that does not hold. These are the questions people ask before they let an agent into a real machine.

What is an AI agent sandbox?

An AI agent sandbox is the boundary around the coding agent: the directories it can write, the hosts it can call, and the keys it cannot see. The rules live outside the model, so a bad prompt cannot move them. The floor plan is on how it works.

What are the AI agent security risks?

The agent will open the wrong file, call the wrong host, and follow a bad instruction if that instruction is in the context window. A prompt does not stop it. The sandbox does, and the log names the process.

What are the best practices?

Pick the directories, pick the hosts, and keep the keys outside the sandbox. A person approves any host the policy does not already allow. The agent does not approve itself.

How do I sandbox Claude Code?

Install Boundlane, then run boundlane run -- claude. You see a deny, approve one host, and take the changes back into your repo. The steps are how to sandbox Claude Code.

Does it sandbox Codex too?

Yes. Codex starts with boundlane run -- codex, and the key stays on your machine. This Codex sandbox is Boundlane starting the agent. It is not a setting inside Codex.

Which agents does it work with?

Any AI agent you start through Boundlane: Codex, Claude Code, Cursor CLI, Grok, Muse, and the next one. The rule applies to the process, not the brand. A desktop app that opens its own terminal outside the sandbox is outside the line, so start the agent through Boundlane.

If AI is dangerous, why help people run it?

Because they are going to run it. The useful move is to bound the process.

Do you trust the model?

No. That is why the rules are not inside it.

What does your cloud see?

Policy versions and decision records: which machine, which rule, allowed or denied. Not your source, not your terminal, not your keys. The Team plan is the hosted log, and with the License the control plane runs in your VPC and none of it reaches us.

What if the sandbox has a bug?

Then we have a software bug, and we say so. The sandbox is OpenShell, which is open source, so you can read it. We pin a version, show the policy, and keep the default tight: workspace open, secrets shut.

Will this slow the agent down?

The agent keeps working on the task. It loses paths and hosts you did not grant. If normal work needs a host, put that host on the list.

Why is the control plane not open source too?

You can audit the sandbox and the CLI, which is the code on your machine. The control plane is how a company shares one policy and keeps the log. That is the part we sell.

What does it run on?

Linux and Apple Silicon Macs. No special hardware. On Windows it runs through WSL 2, and we say that up front.