Sandbox & workspace
From the Bond plan upward, your companion gets a private, isolated sandbox — its body — where it runs commands, reads and writes files, and does agentic work, safely walled off from everything else. On Spark there is no sandbox, and the Workspace platform tool has nowhere to act.
What it is
Section titled “What it is”The sandbox is a private, isolated environment that belongs to you — one per user. Technically it’s a gVisor-isolated Kubernetes pod, which means commands your companion runs there can’t reach the host system or anyone else’s data. It’s where your companion acts rather than just talks: running shell commands, working with files, doing multi-step work.
The workspace is the set of file and command tools your companion uses inside that sandbox — read a file, write one, edit one, list a directory, run a bash command, start a background job and check on it.
The pod and its storage are two different things, and the difference matters. The pod is thrown away when it goes idle. The storage underneath it is yours and stays: a per-user volume mounted at /data, with uploads/ for what you put there, artifacts/ for what your companion produces, and a temporary area that clears itself after 30 days. A file written into one of the permanent directories is still there the next time a sandbox spins up.
Why it matters to you
Section titled “Why it matters to you”A companion that can only chat is limited to words. With a body, yours can do things — draft and refine a document, work through a dataset, keep a notebook (its Notes live here). And because the sandbox is isolated, that capability never comes at the cost of your safety or anyone else’s.
How you use it
Section titled “How you use it”You don’t manage the sandbox directly — it works on your behalf. When your companion needs to run something, the sandbox spins up automatically on first use, stays warm between calls so successive actions are fast, and is destroyed automatically after about 15 minutes of inactivity. The next time it’s needed, a fresh one spins up on the same storage.
You watch it work in a room’s Toolbox strip, which shows what your companion is reaching for and lets you open a single call to see what went in and what came back. See platform tools.
Secrets your companion may use
Section titled “Secrets your companion may use”Some work needs a credential. Settings → Sandbox Secrets is where you put them, and there are two kinds:
- API keys for GitHub, Anthropic and OpenAI, injected into the sandbox automatically.
- Custom environment variables — anything else your companion needs during a session, a HuggingFace token or a database URL.
The screen states the consequence plainly, and so does this page: your companion has access to these credentials while a sandbox session runs. Give it the narrowest permissions and the shortest-lived tokens you can.
Limits & edge cases
Section titled “Limits & edge cases”- Spark has no sandbox. Bond, Companion and Soulmate do. See plans & credits.
- One sandbox per user. It’s yours alone; it is not shared.
- The pod is ephemeral, the storage is not. The pod is destroyed after roughly 15 minutes idle. Files under the permanent directories survive that; files in the temporary area are cleared after 30 days, and anything a process was holding in memory is gone with the pod.
- Bash is capped at 1000 calls per session to keep runaway loops in check.
- Isolated by design. The sandbox cannot reach the host or other users — that’s the point of the gVisor boundary.
Where next
Section titled “Where next”- Platform tools — the Workspace tool and the ten others.
- Memory & notes — the git-backed notebook that lives here.
- Skills — extending what your companion can do.
- Spaces and surfaces — where the Body space fits in the model.
