The AgentJail Working Boundary

The AgentJail Working Boundary A workflow diagram generated by Archify. 01 / Inputs 02 / Agent Runtime 03 / AgentJail Boundary 04 / Execution EX / Blocked Path 06 / Evidence Receive context Evaluate locally Run or stop Deterministic enforcement Observable outcome Instruction · work you asked for · Inputs › Receive context Instruction work you asked for Untrusted · repo · web · MCP · Inputs › Receive context Untrusted repo · web · MCP Coding Agent · reasons + acts · Agent Runtime › Receive context · Claude · Codex Coding Agent reasons + acts Claude · Codex Tool Policy · command · path · tool · AgentJail Boundary › Deterministic enforcement › Evaluate locally · allow · ask · deny Tool Policy command · path · tool allow · ask · deny OS Sandbox · files · net · children · AgentJail Boundary › Deterministic enforcement › Evaluate locally · Seatbelt · Landlock OS Sandbox files · net · children Seatbelt · Landlock Allowed Work · inside the project · Execution › Run or stop Allowed Work inside the project Useful Result · patch · tests · Execution › Run or stop Useful Result patch · tests Action Blocked · nothing executes · Blocked Path › Run or stop Action Blocked nothing executes Decision Log · what happened and why · Evidence › Observable outcome › Run or stop Decision Log what happened and why request context tool call allow sandboxed deny record denial record outcome Legend User UI Agent logic Policy Context / trace External system

The boundary is outside the model

  • • A prompt can ask for care; policy can require it
  • • Tool checks see intent before execution
  • • The OS sandbox constrains the real process

Routine work stays routine

  • • Allowed actions run without constant prompts
  • • Denied actions stop before side effects
  • • Each decision leaves useful evidence