Can agents reach the internet from a sandbox?
Only as your deployment allows: open, a domain allow-list, or workspace-only. The posture is stated to the agent, and connectors go through the broker either way.
Sandbox egress is a deployment setting with three postures: open, a domain allow-list, or workspace-only (the sandbox can reach the platform and nothing else). Whatever the posture, connector calls are brokered through the Context server with credentials issued per action. Air-gapped deployments run closed; VPC deployments commonly allow-list the model endpoint and the systems a workflow needs.
Written for it and security, deployment engineers. Last reviewed 2026-09-15.
Related questions
Still need an answer?
Tell us what you were looking for and we reply within one business day.
Contact the team →Running a security review?
Documents, controls, and the request form live in the Trust Center.
Open the Trust Center →