Sign InOpen Brain
VercelEngineering PostOfficial Source

Run multiple isolated agents in a single Sandbox

Vercel Sandbox can now isolate agents as Linux users while exposing selected files through a shared group directory. This gives multi-agent harnesses a simpler permission boundary.

Vercel · Jul 30, 2026
Open Source Open MarkdownOpen JSON
Source Summary

The **@vercel/sandbox SDK** now supports multiple Linux users and groups. Each agent gets a **private home directory**; users cannot read, write, or list one another’s files, while a **shared group directory** supports collaboration.

Practical Implication

Create one user per agent and expose only the workspace they need through a group. This makes coder-reviewer or other multi-agent roles easier to separate without provisioning a sandbox for each role.

Agent-Ready Context
The **@vercel/sandbox SDK** now supports multiple Linux users and groups. Each agent gets a **private home directory**; users cannot read, write, or list one another’s files, while a **shared group directory** supports collaboration.

Create one user per agent and expose only the workspace they need through a group. This makes coder-reviewer or other multi-agent roles easier to separate without provisioning a sandbox for each role.

The boundary is user and group permissions inside one Sandbox. The material does not claim separate kernels, resource quotas, or protection from vulnerabilities that cross operating-system user boundaries.
Connected Context · Feed7 Judgment

This adds a practical middle ground between sharing one unrestricted workspace and provisioning a sandbox per agent: role separation through Linux users, private homes, and an explicit collaboration directory. It narrows the security claim to filesystem permissions within one OS boundary, so workflow verification, authority, and stronger kernel isolation remain separate concerns.

Context Map
infracodingsecurity#sandboxing#multi-agent#agent-reliability
Uncertainty
The boundary is user and group permissions inside one Sandbox. The material does not claim separate kernels, resource quotas, or protection from vulnerabilities that cross operating-system user boundaries.