AGENTS

Multistep workflows.
One sandbox per step.

Powered byConstal

Every step of an agent workflow runs in its own isolated sandbox. Files carry forward, progress is checkpointed, and you can inspect any run.

EXAMPLE WORKFLOWFIX FAILING TESTS
  1. 01Inspect repositorycomplete
  2. 02Edit codecomplete
  3. 03Run test suiterunning
  4. 04Save checkpointnext

WORKFLOWS

Close your laptop.
Wake up to a pull request.

A workflow is one YAML file. Each step boots a fresh sandbox, gets only the files you declare, and checkpoints the moment it finishes. The run carries on without you.

YAMLfix-failing-tests.yaml
4 STEPS · 4 SANDBOXESSTEP 02 OF 04
workflow: fix-failing-tests
image: registry.caas.sh/your-org/node-agent:24
egress: [github.com, api.github.com, registry.npmjs.org]
inputs:
repo: github.com/your-org/app
steps:
01 - id: checkout
name: Inspect repository
run:
- git clone ${{ inputs.repo }} .
- npm ci
- npm test -- --json > report.json || true
outputs: [.]RECOVERYcheckpoint when it returns
02 - id: fix
name: Edit code
agent: claude-code
task: Make the failing tests in report.json pass.
inputs: [checkout]
outputs: [src/, tests/]ISOLATIONonly these files move on
# A failing exit stops the run. Red tests never become a PR.
03 - id: test
name: Run test suite
run: npm test
inputs: [checkout, fix]
04 - id: pr
name: Open pull request
run: gh pr create --fill
inputs: [checkout, fix]
secrets: [GITHUB_TOKEN]SECRETSattached at egress

RECOVERYline 14 · checkpoint when it returns

ISOLATIONline 21 · only these files move on

SECRETSline 33 · attached at egress

RUN · FIX-FAILING-TESTSCompleted
Started 23:48 · Finished 00:00Select a stepTap a step
  1. hands off . (repo + report.json)sha256:9f2c1a…
  2. hands off src/ tests/sha256:4be07d…
SANDBOXES
4
WALL TIME
12 min
COST
≈ $0.04

ISOLATION

Nothing leaks between steps.

Each step boots a clean sandbox. Only the files it declares cross over, matched by content hash. No leftover state, no dependency drift.

RECOVERY

A 2 a.m. crash costs one step.

Every finished step is a checkpoint. If step three fails, the run resumes at step three and you pay only for what reruns. Checkpoints and resumes are free.

SECRETS

Your agent never holds your keys.

Tokens are attached after traffic leaves the sandbox, so code inside can’t print, log or leak a token it never sees.

CONTROLS

Decide what an agent can reach.

MCP Gateway
Connect steps to MCP servers through an authenticated endpoint.
Model Gateway
Manage keys and rules for the models an agent uses.
Network Policy
Limit outbound destinations and keep credentials out of the guest.
Operations
Status, usage, and checkpoints to resume a run.
Features

Run your first workflow.

Persistent sandboxes, network controls, and usage-based pricing.