Glossary · Sandbox Policy

Sandbox Policy.

Approval and confinement are different axes.

Direct answer

A sandbox policy declares what an agent may read, write, execute and reach over the network, and is enforced independently of approval prompts. The key property: auto-approving actions (yolo mode) must not widen confinement, approval decides whether an action is attempted, the sandbox decides whether it is possible. Profiles typically range from project-scoped to whole-computer to strict-deny, with a fail-closed capability report when the OS backend cannot enforce the policy.

In Anvaya

How We Implement It.

01Sandbox PolicyAnvaya enforces SandboxPolicy at the tool layer for every tool, including all three exec paths (run_command, run_script, monitor): profiles project/computer/strict, sanitized env, network gates, and explicit refusals when confinement is requested but unavailable. Kernel backends: macOS Seatbelt (live-verified), Linux Landlock (compile-verified), Windows refusal.

Questions

Asked About Sandbox Policy.

Q

Does --yolo widen the sandbox?

No. In Anvaya, approval and confinement are orthogonal: --yolo auto-approves but the same policy still blocks out-of-scope reads, writes, exec and network.

Q

What is kernel enforcement?

Applying the policy through OS primitives (Seatbelt, Landlock) instead of only checking arguments in the tool. It is opt-in in Anvaya until the default allow-list passes a build fixture.

Q

What happens on an unsupported platform?

A refused capability, named explicitly, fail-closed. Anvaya reports which confinement is missing rather than silently running unconfined.

Run Agents That Fit On Your Laptop.

25.6 MB median RSS. 25 agents ran in parallel on a Core 2 Duo with 4 GB RAM. Hundreds on your machine. Zero cloud required on the Ollama path.

Requires Rust/cargo to build from source. Linux and macOS today, Windows not yet supported. Pre-1.0, public beta. Pricing TBD.