Workspaces

What does the isolated sandbox protect?

Sandbox mode uses a dedicated Docker container for task execution and mounts selected resources.

OfficeCubs · · 1 min read

Sandbox mode uses a dedicated Docker container for task execution and mounts selected resources. It limits file and process access, but still permits network access for model services.

Before you begin

A workspace determines where a teammate executes work and saves files. The environment is captured with a task, so changing a teammate later does not rewrite an earlier task. Local execution and Docker isolation have different permissions; read the selected mode before submitting real project data.

Steps

  1. Start Docker and prepare the sandbox image.
  2. Choose Isolated sandbox for the teammate.
  3. Attach only needed source material.
  4. Run a small file-producing task.

Example

The teammate workspace is writable at /workspace. Selected attachment and skill resource directories are mounted read-only.

Check the result

Confirm the output appears in the teammate’s local workspace after the container finishes.

Limits and troubleshooting

This is not an offline environment. Task content may be sent to the connected model provider, and the entire home folder is not mounted.

Keep exploring

Practical workflows from the blog