Capability 01 of 04 · Infrastructure

Agent Runtime & Sandboxing

Where and how AI agents execute code - isolation, security, and resource management.

5
maturity levels
15
practices
15
guides
L1 · Stage 01Assisted
L2 · Stage 02Delegated
Criteria - what to measure
  1. 01Dedicated development environments exist for agent execution (separate from developer's primary workspace)
  2. 02Agents run inside a container, not directly on a developer machine
  3. 03Agent credentials are scoped per project (not a single org-wide key)
  4. 04Container images for agent environments are versioned and reproducible
  5. 05Credential rotation schedule exists for agent-scoped keys
L4 · Stage 04GovernedMost teams aim here
L5 · Stage 05Self-improving

Which level is your team at in Agent Runtime & Sandboxing?

The criteria above are what we check in a facilitated assessment. Run it yourself to place this capability, see which gates you have passed, and compare it against the other 3 in Infrastructure.

Start the assessment →