Inside a Production Coding Agent

A thread you can test

Permissions, Sandbox & Security

3 notes move from the word to a real choice at work — understand it first, then decide whether to use it.

READING THREADOPEN
3notes
HOW TO READStart where you are stuck, then follow the evidence and trade-offs

Each note stands alone, or becomes the next step in this thread.

Inside a Production Coding AgentNo login

THE QUESTION THIS PAGE ANSWERS

ANSWER FIRST

What is Permissions, Sandbox & Security, and which AI decisions does it change?

Comparing workspace, devbox, read-only, strict, off, and custom Profile boundaries This page keeps the related concepts, common mistakes, and practical notes in one reading thread.

DECISION RULE

First decide whether you are blocked by a definition, a choice, or verification; then choose the closest of the 3 notes below.

TRY NEXT

Start with “Five Sandbox Profiles,” then restate the conclusion using your own task.

WATCH FOR

Do not treat every method in a topic as interchangeable. The answer changes with the input, risk, and acceptance bar.

THIS QUESTION THREAD

Put the word back inside the choice it changes.

3 notes
Security

Five Sandbox Profiles

Comparing workspace, devbox, read-only, strict, off, and custom Profile boundaries

Inside a Production Coding Agent 5 min →
Security

From Tool Request to Restricted Execution

Tracing the full authorization chain through ToolKind, permission decisions, and platform sandboxing

Inside a Production Coding Agent 6 min →
Hands-on

Hooks: Only Explicit Deny Blocks

Verifying lifecycle events, matchers, PreToolUse blocking, and fail-open semantics on errors

Inside a Production Coding Agent 6 min →