ISOLATION
Nothing leaks between steps.
Each step boots a clean sandbox. Only the files it declares cross over, matched by content hash. No leftover state, no dependency drift.
Every step of an agent workflow runs in its own isolated sandbox. Files carry forward, progress is checkpointed, and you can inspect any run.
WORKFLOWS
A workflow is one YAML file. Each step boots a fresh sandbox, gets only the files you declare, and checkpoints the moment it finishes. The run carries on without you.
workflow: fix-failing-testsimage: registry.caas.sh/your-org/node-agent:24egress: [github.com, api.github.com, registry.npmjs.org]inputs: repo: github.com/your-org/appsteps: - id: checkout name: Inspect repository run: - git clone ${{ inputs.repo }} . - npm ci - npm test -- --json > report.json || true outputs: [.]RECOVERYcheckpoint when it returns - id: fix name: Edit code agent: claude-code task: Make the failing tests in report.json pass. inputs: [checkout] outputs: [src/, tests/]ISOLATIONonly these files move on # A failing exit stops the run. Red tests never become a PR. - id: test name: Run test suite run: npm test inputs: [checkout, fix] - id: pr name: Open pull request run: gh pr create --fill inputs: [checkout, fix] secrets: [GITHUB_TOKEN]SECRETSattached at egressRECOVERYline 14 · checkpoint when it returns
ISOLATIONline 21 · only these files move on
SECRETSline 33 · attached at egress
ISOLATION
Each step boots a clean sandbox. Only the files it declares cross over, matched by content hash. No leftover state, no dependency drift.
RECOVERY
Every finished step is a checkpoint. If step three fails, the run resumes at step three and you pay only for what reruns. Checkpoints and resumes are free.
SECRETS
Tokens are attached after traffic leaves the sandbox, so code inside can’t print, log or leak a token it never sees.
Persistent sandboxes, network controls, and usage-based pricing.