Answering what waits for you
Approvals, objections and questions, and how the sandbox keeps agents in.
Agents run real commands on your machine. Two things keep that safe: a sandbox round every tool, and you.
The sandbox
Every tool an agent runs is inside a sandbox: bubblewrap on Linux, Seatbelt on macOS. Inside it, an agent’s tools can write only to that agent’s own workspace.
Tools have no network access to begin with. To give it, turn on Tools network access under Agents in Settings.
Windows has no sandbox yet. Hamlet starts there only with --insecure, and
tools then run with your own rights.
When something waits
A command that reaches past the sandbox does not run. It waits in Petitions, with the agent’s name, the command and three answers.
| Answer | What it does | As a command |
|---|---|---|
| Allow once | Runs this one command | /allow [reason] |
| Always allow | Runs it, and the like from now on | /always [reason] |
| Deny | Refuses it | /deny [reason] |
A reason is optional. The agent is told it, so a reason with a refusal helps it try something else.
Other things wait there too:
- An objection. An agent disagrees with something you told it to do.
/gotells it to go ahead, and/withdrawtakes your instruction back. - A question.
/reply <text>answers it. - A fault. Something went wrong.
/dismissputs it away.
/queue lists everything that waits.
Taking it back
/undo reverse the latest thing that can be reversed
/stop scout stop one agent's work
/stop all stop everyone's
/grants list what agents are allowed for good
/revoke scout network take back a lasting permission