Product capability

Workspace isolation

Keep execution inside the place where the work belongs.

View the product map

Why it matters

An agent should not gain ambient access simply because it runs on a developer machine. Clarvis gives execution a deliberate boundary and treats an unavailable boundary as a condition to surface, not silently ignore.

What it gives you

Useful outcomes, not more surface area.

01

Reduce accidental reach

Work remains centered on the workspace instead of inheriting the whole machine by default.

02

Make posture visible

The person running the agent can see which isolation posture is actually active.

03

Fail with clarity

When the expected containment cannot be provided, the run exposes that fact before continuing.

How to think about it

A simple path through the capability.

  1. 01

    Select the boundary

    Choose the level of isolation the workflow requires.

  2. 02

    Start contained

    The runtime prepares the execution environment around that choice.

  3. 03

    Keep the promise

    Every command the run executes is evaluated against the same boundary. The built-in file tools stay inside the workspace through path confinement instead.

Step-by-step guides

Put this capability into practice.

Configure the command sandbox Open the guide

Pre-release access

Put this capability against a real workflow.

Design partners work directly with Clarvis on the outcome, the operating boundary and the path into production.

Apply for early access