CHAPTER 07 · Sandboxing, Approvals, and Checkpoints · 5 / 5
Key takeaways
- Sandboxing limits what an executed command can physically do, using native OS mechanisms (Seatbelt on macOS, Landlock on Linux, a custom sandbox on Windows). MCP tools are not covered by the harness sandbox and must guard themselves.
- Approvals are layered: auto-approve safe commands, allowlist trusted patterns, and require explicit approval for sandbox violations like network access or out-of-workspace writes.
- For unattended runs, Smart Approvals route risky actions to a guardian subagent instead of a human, so the agent does not stall.
- Checkpoints snapshot files before edits so you can undo, but they cannot undo external side effects (deploys, API calls), which is why those always prompt.
- Treat the agent as a privileged identity: least privilege, isolated secrets, human review for anything touching production.
Original sources: "Inside the Agent Harness" (Codex codebase analysis), the "Inside the Codex Agent Loop" deep-dive, and Anthropic's How Claude Code works.