Quick start
This walkthrough shows the smallest working Sandbox Loom flow. It is intended for local evaluation and requires no API key or external service.
Run the example
From the repository root:
Expected output includes:
The example creates a temporary workspace, applies the selected policy, performs a small change, verifies the result, and reports acceptance evidence. It does not grant the workflow access to your host or start an OCI container.
The expected output is an acceptance signal for this offline example, not a claim that an arbitrary workflow is safe to run. For a real workflow, inspect the selected profile, capabilities, limits, evidence requirements, and approval boundaries before execution.
Explore the workflow model
Validate and preview a workflow without executing it:
bin/sandbox-loom workflow check examples/workflow.yml
bin/sandbox-loom workflow plan examples/workflow.yml
Validation catches malformed tasks, unsupported actions, dependency errors, and policy mismatches. Planning shows the execution order without changing a workspace.
Browse the examples for progressively more capable workflows, including YAML composition and an opt-in model-backed agent.
Run with isolation
For an OCI-backed session:
- Choose the least-privileged session profile that can complete the work.
- Prepare a bundle containing
config.jsonandrootfs/. - Install Youki or provide
runc. - Confirm resource, network, and expiry settings.
- Run the operations smoke test.
The operations guide covers runtime prerequisites and the recommended operating posture.
Recommended first posture
Use read-only or safe-development access where possible. Keep credentials outside the workspace, use feature branches for automated changes, retain audit and acceptance evidence, and require approval for protected operations.