Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Sandboxing limits where an AI agent’s code can run; access controls limit what that code can reach. They are complementary safeguards, not substitutes. An agent can interact with files, credentials, tools, and network destinations exposed by its environment, so enforce limits in the operating system and trusted application layers—not just in a prompt.

What sandboxing and access restriction each do

A sandbox is an execution boundary: it can constrain the files, processes, and other resources available to agent-directed code. Access restriction is the broader policy governing which files, tools, credentials, data, and network destinations the agent may use. A sandbox does not automatically make every exposed resource safe, and an access policy is only effective if the environment and application enforce it.

OpenAI’s sandbox security guidance warns that code generated or directed by an agent can access the files, credentials, and network available to its environment. Treat those capabilities as real even when the agent has been instructed not to use them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to sandbox an AI agent

  1. Define the workload boundary. Decide which user, task, or workload owns the environment. Use separate environments when users or workloads must not share data. If they share an environment, treat its files, credentials, and other resources as shared access.
  2. Choose an execution boundary that fits the risk. Do not treat a working directory, HOME, or cwd as confinement. OpenAI’s Agents SDK sandbox client guide says its Unix-local Linux backend runs commands as host processes and adds no OS-level confinement. Use a suitably configured Docker or hosted sandbox, or another external isolation mechanism, for untrusted commands. The local macOS backend applies filesystem restrictions but does not provide network isolation or the same boundary as a container.
  3. Limit the sandbox’s filesystem and privileges. Expose only the workspace and files needed for the task. Avoid admin or sudo privileges by default, and do not allow an agent to grant itself more privileges. Make database access read-only unless a specific task requires writes.
  4. Set network policy deliberately. Disable outbound access if the workflow does not need it. Otherwise, permit only approved destinations and consider where tool connections originate. Restricting a sandbox’s network does not necessarily constrain connections made by tools or services outside it.
  5. Keep valuable secrets outside the execution environment. Do not put application API keys or broadly usable third-party credentials where agent-directed code can read them. A trusted broker or vault-backed proxy can provide narrowly scoped access for approved destinations without exposing the underlying secret to the code.
  6. Keep the harness separate from execution. The agent harness can retain model calls, tool routing, approvals, audit and tracing, recovery, and run state in trusted infrastructure while sandbox compute executes commands and manipulates files. A sandbox is most useful when work needs commands, packages, artifacts, exposed services, a workspace, or resumable state; a short response without persistent execution may not need one.
  7. Test and monitor the controls. Before production, test third-party tools and generated scripts in hardened environments with syscall and network-egress restrictions where appropriate. Monitor execution and review permissions, mounts, network rules, and connector configuration.

How to stop an AI agent from accessing files or secrets

Files and shared workspaces

Mount or expose only the files needed for the task, and separate environments when users or workloads must not see one another’s data. A workspace path is a convenience, not a security boundary: a host process may still access other resources permitted by the host. OpenAI’s self-hosted guidance also notes that agents sharing an environment can access the same files, credentials, and other resources; the operator must configure isolation rather than assume it.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Application and third-party credentials

Keep application credentials in trusted infrastructure rather than the execution container. For third-party access, use a broker or vault-backed proxy that checks the destination and attaches a narrowly scoped credential outside the sandbox. OpenAI documents this pattern for hosted sandboxes: code can see a placeholder while a proxy supplies a real secret only for approved hosts. On self-hosted infrastructure, the operator must provide the trusted proxy or server.

Tools, connectors, and data

Apply least privilege to the agent’s role and each tool operation. Prefer read-only access where practical, restrict sensitive personal data, and do not allow the agent to modify its own privileges. Connected applications can expand effective access beyond the sandbox: OpenAI warns that users may access data or perform actions through a creator’s personal app connections. Limit who can use such agents, avoid sensitive or high-impact connectors where possible, and audit their configurations.

Rank #2
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Shared memory

Shared agent memory is a separate access and integrity risk. AWS guidance describes it as dynamic and potentially difficult to validate with conventional database constraints. Treat retrieved memory as partially trusted: limit who can modify it, validate information before acting on it, and consider a deterministic gateway for centralized filtering, integrity checks, policy enforcement, and audit trails.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to restrict an AI agent’s network access

Start with no egress when the task can run without network access. If it needs access, allow only the domains or endpoints required, and review whether requests originate from the sandbox, a tool, or a separate service. A prompt asking an agent to avoid a destination does not block network traffic.

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

OpenAI’s hosted-sandbox documentation describes three network modes: outbound access can be enabled, disabled, or restricted to listed domains. It says access is enabled by default unless an inherited template policy applies. These are documented behaviors of that product, not assumptions to make about other hosted or self-hosted systems.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing a local, containerized, hosted, or self-hosted setup

Compare the actual boundary and operating responsibilities, not the label “sandbox.” The table distinguishes common deployment approaches; the exact guarantees depend on configuration and provider.

Rank #4
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
Approach Execution boundary Network and credentials Separation and operations
Local execution On OpenAI’s Unix-local Linux SDK backend, commands are host processes with no OS-level confinement. Its macOS backend restricts filesystem access but does not provide network isolation or a container-equivalent boundary. Resources permitted to the host may be reachable; workspace settings do not establish isolation. Configure external controls if the workload is untrusted. Runs on the operator’s machine. Do not assume a separate environment per user or workload.
Containerized execution A configured container can provide an execution boundary; the real guarantee depends on its configuration and the host. Set filesystem mounts, privileges, and network egress explicitly; keep valuable secrets outside the container. The operator configures and maintains the container and its isolation. A container alone does not prove users or workloads are separated.
OpenAI-hosted sandbox Provider-managed sandbox compute; OpenAI documents a separate workspace for each session. Documented network modes allow outbound access, disable it, or restrict it to listed domains. Vault credentials keep real secrets outside the sandbox. OpenAI documents per-session workspaces; provider-managed infrastructure does not remove the need to scope permissions and connections.
Self-hosted sandbox The operator chooses and configures the laptop, container, or remote sandbox; the name alone does not establish a boundary. The operator must isolate execution, scope environment credentials, keep the application API key out of the sandbox, and provide any trusted credential proxy. Offers operational control, with responsibility for setup, patching, isolation, monitoring, and audit. Shared environments share access to their resources.

For any option, verify six things before deploying: the enforced OS or virtualization boundary; filesystem mounts and per-workload separation; egress policy and connection origin; whether code can read real credentials; whether roles and permissions are narrow and reversible; and who patches, monitors, and audits the infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis Nano-C FIDO2 Security Key Hardware Passkey Device with USB Type C, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
  • USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Deployment checklist

  • Separate users and workloads that must not share data.
  • Do not rely on prompts, workspace paths, HOME, or cwd as security boundaries.
  • Use an appropriately configured container, hosted sandbox, or external isolation for untrusted execution.
  • Expose only necessary files, tools, data, and permissions; avoid admin privileges and unnecessary database writes.
  • Disable network egress when possible; otherwise allow only required destinations.
  • Keep application and third-party secrets outside the execution environment; broker narrowly scoped access.
  • Review connector permissions, shared memory write access, and agent audience.
  • Test and monitor tools and generated scripts, and audit environment configuration regularly.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.