A machine for each agent
Isolated execution and deterministic policy
Each agent gets a machine of its own: a microVM with its own kernel. You choose the files, the credentials and the network destinations it can reach, so a tool or service works only at an address you allow. The rules run on the host, where the agent cannot edit them.
- One microVM per agent, on macOS and LinuxShipping
- One project mounted. No keychain, SSH agent or other host directoryShipping
- Egress allow and deny rules by host and CIDR, enforced on macOS with the hvi backendShipping
- A run does not start if its backend cannot enforce the policyShipping
- An admin policy ceiling that users cannot loosenPrivate beta