Agent sandbox
Phase: design — complementary to the approve gate. Stops many MCP/token issues; sandbox adds isolation for what still runs after you approve.
Layers
Approve gate (shipped) · Live
Human deny/approve before secret injection — latchkey run & MCP.
Tool allowlists (shipped) · Live
.latchkey.toml secret names + MCP approve env.
Isolated tool runtime · Planned
Optional sandbox for MCP/tool child processes — no broad filesystem/network by default.
Policy export · Planned
Enterprise: SIEM-friendly audit export, org templates (E2/E3).
CLI preview (M22-cli)
latchkey run --sandbox -- node your-agent.js # Warns + sets LATCHKEY_SANDBOX_REQUESTED=1 — isolation NOT enforced yet.
# Planned (not active yet) # latchkey run --sandbox -- agent-tool ... # LATCHKEY_SANDBOX=1
Until this ships, use approve/deny + Latch Check waitlist for pre-flight scans.
Dashboard shows sandbox status · Threat model