An isolated execution environment where an agent's actions, like running generated code, are contained and can't touch the real system or network.
Mental model: Think of it like a supervised practice run — mistakes happen inside a fence that keeps them from reaching anything real.
often confused with Scoped PermissionsA sandbox isolates where actions run; scoped permissions limit what they're allowed to touch — different layers of the same safety goal.