How we contain Claude across products (simonwillison.net)
Anthropic published a detailed overview of their sandbox techniques for Claude.ai, Claude Code, and Cowork, using process sandboxes, VMs, filesystem boundaries, and egress controls to constrain agent actions.