Skip to content
Signpost
ProposedAI

Agent execution sandbox

An isolated environment where agents can run code and call internal tools without holding standing credentials to production systems.

Lifecycle

Next: in development on 16 November 2026, in 6 weeks. Each audience arrives on its own schedule, below.

  1. Proposed (current stage)4 weeks ago
  2. In developmentplanned, in 6 weeks
  3. Rolling outplanned, in 5 months
  4. Generally availableplanned, in 8 months

By audience

Next up: Platform engineers building agents.

  • Platform engineers building agents

    Phase 1 — agent builders

    Proposed
    Rolling out
    1 Mar 2027
  • Teams already running agents against internal APIs

    Phase 2 — existing internal-API agents

    Proposed
    Rolling out
    10 May 2027
  • Any team, without asking us first

    Phase 3 — self-serve

    Proposed

Detail

What is being proposed

A sandbox with no standing access: an agent requests a short-lived, scoped credential per task, and everything it runs is recorded.

Status

Proposed only. Scope and timing may change entirely, and it may not be built at all — the dates below are an estimate, not a commitment.

Updates

Info

Proposal is open for comment until 9 October

We particularly want to hear from teams already running agents against internal APIs, and from Security on the credential model.