The repository is the source material, the sandbox is the execution boundary, and the pull request is the review contract. Reliable cloud-agent workflows keep those roles separate.
This guide focuses on the engineering decision behind coding agent sandbox workflow: what to standardize, what to constrain, and what evidence a reviewer should expect before accepting the result.
The core decision
The sandbox should begin from a known commit and receive only the dependencies, network routes, and credentials required for the task. The agent edits a branch rather than the default branch. The pull request then exposes the exact change to existing review, CI, and branch-protection controls.
A workflow that holds up in review
Design the loop so reruns are cheap. Setup belongs in versioned scripts, tests should be callable with one documented command, and generated artifacts should not depend on hidden workstation state. When a run fails, the team should be able to reproduce it locally or in another sandbox.
The failure mode to design around
Giving an agent broader repository or organization access because setup is inconvenient weakens the main benefit of isolation. Solve missing context with explicit files and scoped tools before expanding permissions.
Implementation checklist
- Start from a named commit or branch.
- Use a disposable environment.
- Push only to an isolated branch.
- Merge through normal review and CI.
Turn the checklist into operating controls
- Start from a named commit or branch: name the owner, the evidence that proves it happened, and the condition that should stop the run.
- Use a disposable environment: name the owner, the evidence that proves it happened, and the condition that should stop the run.
- Push only to an isolated branch: name the owner, the evidence that proves it happened, and the condition that should stop the run.
- Merge through normal review and CI: name the owner, the evidence that proves it happened, and the condition that should stop the run.
The list becomes useful when every item produces visible evidence. Store that evidence with the task or pull request rather than in a private chat. A future reviewer should be able to tell which repository revision was used, which permission profile applied, what stopped or failed, and who accepted the remaining risk. For coding agent sandbox workflow, a short, complete record is more valuable than a long narrative that cannot be reproduced.
Move from one run to a repeatable practice
Introduce the practice with one task class and one repository. Compare the delegated path with the way the team completes the same work today, including waiting, review, and rework. Make the handoff visible in the issue tracker so the experiment does not create a second, private backlog. After several runs, write down which characteristics predicted success and which required live engineering judgment. That evidence should determine the next task class, not a general mandate to use an agent.
Before expanding the workflow, ask three review questions:
- What evidence shows that start from a named commit or branch was satisfied, and would that evidence survive a rerun from the recorded commit?
- What evidence shows that use a disposable environment was satisfied, and would that evidence survive a rerun from the recorded commit?
- What evidence shows that push only to an isolated branch was satisfied, and would that evidence survive a rerun from the recorded commit?
Write the answers in the same place as the code review. That creates a compact decision record and lets the team compare later runs without relying on memory.
A practical acceptance test
Run the workflow from a clean checkout at a recorded commit. Give the agent only the documented task packet and the intended permission profile. Then ask a reviewer who did not launch the run to reproduce the important checks, explain the changed behavior, and identify the rollback path. The task passes only when the artifact, evidence, and repository state agree. Keep the failed examples as regression cases; they are more useful than a polished demo because they reveal where instructions, environment, permissions, or tests need improvement.
Related reading
- Agentic Coding in the Cloud: The Complete Guide
- What Makes a Coding Task Agent-Ready?
- Human-in-the-Loop Coding Agents Without Review Theater
Primary references
Vendor features, limits, preview labels, and pricing can change. Recheck the linked first-party documentation for the current state before making a purchase or rollout decision.
