Workspaces
What does the isolated sandbox protect?
Sandbox mode uses a dedicated Docker container for task execution and mounts selected resources.
OfficeCubs · · 1 min read
Sandbox mode uses a dedicated Docker container for task execution and mounts selected resources. It limits file and process access, but still permits network access for model services.
Before you begin
A workspace determines where a teammate executes work and saves files. The environment is captured with a task, so changing a teammate later does not rewrite an earlier task. Local execution and Docker isolation have different permissions; read the selected mode before submitting real project data.
Steps
- Start Docker and prepare the sandbox image.
- Choose Isolated sandbox for the teammate.
- Attach only needed source material.
- Run a small file-producing task.
Example
The teammate workspace is writable at /workspace. Selected attachment and skill resource directories are mounted read-only.
Check the result
Confirm the output appears in the teammate’s local workspace after the container finishes.
Limits and troubleshooting
This is not an offline environment. Task content may be sent to the connected model provider, and the entire home folder is not mounted.