Seems aws also announced a sandbox solution
I used agent over 1 year and basically always give codex full permission on each thread, do not get issue so far
Why we need this layer of complexity? Or its mainly for big company that need control ?
The main usecase for an average developer is preventing confused agents making mistakes like removing sensitive folders, resetting git branches or using API tokens they shouldn't be using
A ~month ago, auto-review (rightfully) blocked a rm that would've nuked my home directory, due to shell mangling (amongst other issues).
If you have a custom agent in a product, then it needs isolation to be sure to protect the customer data.
It's very useful to ensure that code under test has limited access to resources both to avoid making a mess outside the intended workspace. Otherwise there's risk of deleting or killing stuff it shouldn't, or just using too much memory or CPU and causing OOM kill or other issues. If a runaway command turns into a nice error for the agent then it becomes something that will self-resolve without fuss.