Agent Systems · core

Agent Permissions & Sandboxing

Capability grants, read/write scopes, approval gates, secret isolation, network policy, quotas, and audit logs.

agent-systemspermissions

Mental model

Treat an agent as an untrusted principal. Grant the smallest capability for the shortest time, isolate execution, require approval for irreversible effects, and log authority use. Scope: this card owns treating an agent as an untrusted principal — capability grants, approval gates for irreversible effects, secret isolation and audit. The underlying isolation technology is `sandbox-execution-environments`; the threat-modelling discipline is `security-isolation-boundaries`.

How to study Agent Permissions & Sandboxing

Begin by restating the mental model in your own words, then connect it to a concrete system you have built or operated. Name the mechanism, the constraint it addresses, and the trade-off it introduces. Use How we contain Claude across products, Defeating Prompt Injections by Design (CaMeL), Making Claude Code More Secure and Autonomous with Sandboxing to check details, but close the source before writing your explanation. Retrieval is the learning step; rereading is only preparation.

Next, compare Agent Permissions & Sandboxing with Durable Agent Execution, Long-running & Scheduled Agents. Ask what changes in correctness, latency, resource use, operability, and failure recovery. Complete Design exercise: Agent Permissions & Sandboxing and preserve the command, input, output, and one failed attempt as evidence. Finish by explaining the idea without jargon to someone who has not studied the track.

Proof of understanding

  • Explain the mechanism from first principles and identify the state it reads or changes.
  • Give one situation where the concept is the right choice and one where it is not.
  • Predict a realistic failure mode before running the drill, then compare the prediction with evidence.
  • Connect the result to a roadmap or build artifact instead of treating the concept as isolated trivia.

Learn from primary sources

Practice and explain it back

Design exercise: Agent Permissions & Sandboxing

Capability grants, read/write scopes, approval gates, secret isolation, network policy, quotas, and audit logs. Implement designOutline() returning non-empty values for: capabilityScope, approvalGate, auditTrail. Each value must name a concrete mechanism or decision.

Expected evidence: A design outline with capabilityScope, approvalGate, auditTrail plus an explicit failure mode or trade-off.

Open the interactive drill →

Review prompts

  • Why is an agent treated as an untrusted principal even when the user is trusted?

Build evidence

Synthesize: Agent Systems

Engineer useful agents with bounded loops, tools, memory, protocols, durability, permissions, and long-running control. Produce one working system, benchmark, or evidence-backed design that integrates the path.

  • Implements or precisely models the core mechanisms from all three milestones
  • Includes at least one injected failure or adversarial case and demonstrates recovery
  • Reports quality, latency, resource, reliability, or usability measurements relevant to the domain
  • Ships a concise architecture note explaining decisions, trade-offs, and remaining risks

Prerequisites

Related concepts

Learning paths