Skip to slide
Chapter 7 · Sandboxing, Approvals, and Checkpoints
47 / 142

CHAPTER 07 · Sandboxing, Approvals, and Checkpoints · 5 / 5

Key takeaways

  • Sandboxing limits what an executed command can physically do, using native OS mechanisms (Seatbelt on macOS, Landlock on Linux, a custom sandbox on Windows). MCP tools are not covered by the harness sandbox and must guard themselves.
  • Approvals are layered: auto-approve safe commands, allowlist trusted patterns, and require explicit approval for sandbox violations like network access or out-of-workspace writes.
  • For unattended runs, Smart Approvals route risky actions to a guardian subagent instead of a human, so the agent does not stall.
  • Checkpoints snapshot files before edits so you can undo, but they cannot undo external side effects (deploys, API calls), which is why those always prompt.
  • Treat the agent as a privileged identity: least privilege, isolated secrets, human review for anything touching production.

Original sources: "Inside the Agent Harness" (Codex codebase analysis), the "Inside the Codex Agent Loop" deep-dive, and Anthropic's How Claude Code works.

← → arrow keys work too