Give an AI coding agent only the files, network access, credentials, and tools needed for its current task. Keep write access inside the project, restrict network access unless the work requires it, avoid exposing broad credentials, and require approval before actions that cross those boundaries. The important question is not just what a permission is called, but what the host environment actually allows the agent to reach.
Use this checklist to set an agent’s permissions
Start with the smallest useful scope, then widen it deliberately if the task cannot be completed. These are recommendations, not universal product settings: permission labels and enforcement vary by agent, version, operating system, and deployment.
As an Amazon Associate I earn from qualifying purchases.
- Workspace: Allow access to the repository or task directory the agent needs. Keep writes outside it restricted, and require approval before expanding the scope. OpenAI describes writable roots for Codex in its account of its internal developer tools; GitHub documents repository access boundaries for its cloud agent in its Copilot coding agent documentation.
- Network: Leave network access off or limited when the task can be done locally. If the agent needs to fetch dependencies, consult documentation, or call an API, allow only what that task requires where the host supports it. Filesystem and network controls are separate boundaries: Anthropic describes both in its Claude Code sandboxing article, while Microsoft documents permitted domains in the VS Code agent tools documentation.
- Credentials: Keep general-purpose personal and production credentials out of the agent’s environment. When authentication is necessary, use an identity limited to the relevant repository, service, or task, through the environment’s supported secure mechanism. OpenAI warns that agent-generated code can access credentials made available to its executor in its agent sandbox guidance.
- Tools: Expose only tools needed for the task. Before approving an invocation, inspect both the tool and its parameters; a familiar tool can still perform a risky action depending on what it is asked to do. Microsoft describes input review and different approval scopes in its VS Code documentation.
- Approvals: Ask for confirmation before granting access outside the workspace, enabling network access, changing permissions, or making consequential external changes. The exact prompt and available approval scopes depend on the product.
- Isolation: For unfamiliar work or parallel sessions, use a separate workspace, worktree, container, or other enforced sandbox. Check whether it restricts both filesystem and network access; isolation in one area does not automatically constrain the other.
- Review: Inspect the changes the agent made and, where available, its tool activity and approval record. OpenAI’s description of internal practice includes logs for tool activity, approval decisions, results, and network-policy outcomes in its developer tools account.
Why filesystem and network permissions need separate limits
An agent can only act through the environment and tools available to it, but code it generates can also use resources exposed to that environment. A workspace restriction is therefore not a substitute for controlling network access, and a network restriction does not stop access to files that remain reachable.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Anthropic describes the relationship in its October 20, 2025 engineering article: “Without network isolation, a compromised agent could exfiltrate sensitive files like SSH keys; without filesystem isolation, a compromised agent could easily escape the sandbox and gain network access.” The practical lesson is to check both boundaries rather than treating “sandboxed” as a complete description of protection.
#1 Best Overall
What to compare when choosing an agent setup
Evaluate the actual controls available in the host environment, not just the product’s permission names. These dimensions capture the differences that matter when deciding whether a setup fits a task:
| Control | What to check |
|---|---|
| Filesystem | Which paths can the agent read, and which can it change? |
| Enforcement | Is the boundary enforced by an operating-system sandbox or container, or only by application policy? |
| Network | Is access off by default, and can specific destinations be allowed? |
| Credentials | Which credentials and identities can code running in the environment use? |
| Approvals | Which actions trigger a prompt, and can approvals be limited to a particular scope? |
| Isolation and audit | Are sessions separated, and can you review actions and approval outcomes? |
Product controls are examples, not a universal standard
Vendor documentation illustrates different ways these boundaries can be implemented. OpenAI describes writable roots, secure storage for CLI and MCP OAuth credentials, and network-policy decisions in an account of its internal Codex deployment; those details should not be assumed to describe defaults for every Codex user or coding agent. Its separate sandbox guidance explains that generated code can access files, credentials, and network resources available to its executor.
GitHub documents that Copilot cloud agent responds to users with repository write access and describes workspace isolation and permission checks. Anthropic’s Claude Code article covers filesystem and network isolation together and explains that sandboxing can reduce permission prompts while retaining safety controls. Microsoft’s VS Code documentation covers approval levels, tool-input review, sandbox paths, and network-domain restrictions. These are examples of product-specific behavior, not a shared permission model.
Because settings and enforcement can change across versions and host environments, consult the current documentation for the specific agent you use before applying a configuration. No single permission setup is established as best for every coding task.
Quick Recap
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




