Infrastructure

Agent Sandboxes

Own the machines your agents run on.

The sandbox service behind Engine, available standalone. Deploy it on-prem or in your cloud and give every agent an isolated Windows, Linux, or macOS machine with snapshots, network policy, and full session recording.

Agent Sandboxes
Example workflow
Running

Linux

us-west / private

Ready

Windows

on-prem / finance

Ready

macOS

build pool / 04

Network policyrefund-review
api.internalAllow443
documents.internalAllow443
Public internetDenyall
Checkpoints

Image ready

snapshot 01

Tools installed

snapshot 02

Before submission

snapshot 03

How it works

From request to a reviewable result.

Each run keeps the request, actions, evidence, and final decision together.

  1. 01 · Create

    Start from an approved image.

    Request a Windows, Linux, or macOS environment with the machine policy assigned to the workflow.

    Output · Isolated machine

  2. 02 · Operate

    Run with scoped network access.

    The agent uses the machine while Context records actions and enforces the configured egress policy.

    Output · Recorded session

  3. 03 · Preserve

    Keep evidence, not residue.

    Export artifacts and the run record, then restore a checkpoint or destroy the environment.

    Output · Artifacts and snapshot

What you can inspect

Capability is only useful when it leaves evidence.

Three operating systems

Windows, Linux, and macOS sandboxes from one API, for agents that operate real desktop and server software.

Recorded with the runImage and OS attestation

Your infrastructure

Runs on-prem or in your VPC. Machine images, data, and traffic never leave your perimeter.

Recorded with the runDeployment and region

Snapshot and restore

Checkpoint a machine mid-task, branch it, or roll it back. Reproduce any run from its snapshot.

Recorded with the runImmutable snapshot ID

Network policy per sandbox

Default-deny egress with allowlists per workflow, so an agent reaches exactly what its task requires.

Recorded with the runApplied egress policy

Session recording

Full video and input capture of every session, tied to the run's trace for review and audit.

Recorded with the runTime-linked recording

Deployment boundaries

Control is part of the product.

Agent Sandboxes can run as a standalone surface, while its traces, evals, and policy decisions remain part of the same Context system.

Capacity follows deployment

Operating-system availability and startup time depend on the images and hardware configured in your environment.

Recording is configurable

Retention, redaction, and access to session recordings follow your organization's policy.

See how it works with Engine

Talk to us.
Bring a workflow your team runs today and see it run in your environment.