A developer gives an AI agent a disposable workspace, watches it build an application, and deletes the workspace when the task finishes. That sounds contained. The security question starts with everything the workspace could reach before it disappeared: source repositories, deployment credentials, customer files, package registries, and the preview link shared with a colleague.
The word sandbox describes part of a system. It does not tell a business which information can leave, which accounts the agent can use, or what survives the task. Those are the boundaries an assessment needs to establish.
Start with the business authority inside the workspace
Write down the task in ordinary language. An agent fixing a layout needs a copy of the relevant code and a way to show its changes. It may not need production database access, billing permissions, or a credential that can publish directly. Compare that task with the environment the agent actually receives, including inherited variables, mounted directories, and helper processes.
Consider an illustrative agency workflow. Three clients use the same automation platform, and each task starts a separate container. If every container receives a shared deployment credential covering all three clients, process separation has left an important business boundary unresolved. The assessment must test the credential’s effective scope, rather than stop at confirming that there are three containers.
Outbound connections decide where information can go
An isolated filesystem can still coexist with broad network access. Ask which destinations a task needs and who enforces that list. Package installation, repository access, and a preview service may each be legitimate, but they should have identifiable purposes and owners.
For a controlled assessment, place a synthetic marker in a test file and use a destination owned by the test team. Attempt a transfer outside the approved destination set. Retain the attempted destination, the enforcement decision, and confirmation that the marker did not arrive. A model saying it will respect the rule is less informative than a network or service control rejecting the request.
Also inspect permitted destinations. An approved storage service may contain both a company account and an unrelated account. Allowing the service’s hostname does not establish that every account on it is an appropriate recipient. Where that distinction matters, application authorization must accompany network restrictions.
A snapshot creates another copy to govern
Cloudflare’s September 30 sandbox update includes runtime image selection and filesystem snapshots in public beta. These capabilities make workspace creation and resumption more flexible. The assessment implication is that task completion, workspace deletion, and deletion of retained copies need separate definitions.
Trace an illustrative task through creation, pause, restoration, and retirement. Put a non-secret identifier in its workspace, save a snapshot, then remove the original user’s access. Test who can restore the snapshot and which identity the restored task uses. Record whether credentials are refreshed under current authorization or retained from an earlier session.
Choose retention based on the information in the workspace. A snapshot holding only public code has a different handling requirement from one containing confidential customer exports. The useful inventory lists snapshot owner, source task, storage location, permitted restorers, and deletion policy. A list of running containers will miss this entire lifecycle.
Treat preview links as application access
An agent’s preview can expose unfinished account controls, debug responses, or test records. Review how the preview is authenticated, how it is associated with its task, and when it expires. Check whether access to the platform automatically grants access to every preview, including another client’s work.
Use two synthetic client workspaces and two users. Confirm the intended reviewer can open the correct preview, then attempt the same link as the other user and without a session. After retiring the task, test the old link again. The evidence should show authorization decisions and the actual response, with no real customer information involved.
Define what Ceron should verify before adoption
For a Ceron assessment, scope the agent platform, workspace controller, connected credentials, and public preview surface explicitly. Agree which components can be tested and which require evidence from the hosting provider. An external website scan alone cannot establish container isolation or inspect private credential handling.
The acceptance record should connect each business boundary to a result: client separation, approved destinations, current permissions after restoration, and preview retirement. Keep exceptions visible. If a build genuinely requires broad registry access, document that need alongside the controls protecting secrets within the build.
The decision is whether the workspace gives the agent only the authority the task requires, throughout its lifecycle. That is a useful standard to carry into a procurement review or a release meeting, and a much stronger answer than pointing to a product feature called sandbox.
Related assessment guidance
Ceron’s guide to AI agent permissions covers business actions behind connected tools. The AI application launch checklist addresses the application the agent produces. The agency and workspace scenarios above are proposed assessment cases, not reported customer incidents.