Skip to content
Security & Trust Talking point

Docker's Jim Clark: agent safety comes from what the sandbox lets in

Docker's Jim Clark argued that risk depends on the tools, context and credentials an agent can reach.

W
WebPulse Newsroom
AI-assisted · 2 min read
Share on X LinkedIn
Docker's Jim Clark: agent safety comes from what the sandbox lets in
In brief
  • Jim Clark of Docker argued that an agent's risk is set by the sandbox around it: which tools, context and credentials it can reach.
  • His rule is that an unsupervised agent should start with zero credentials, with access granted through a central gateway only when the task needs it.

Jim Clark, a principal software engineer at Docker, argued that how safe an AI agent is depends on the sandbox around it, not on the harness inside. He made the case on the AI Engineer show. His rule for agents nobody is watching is to start them with no credentials at all.

What was said

Clark described the agent harness, the program that runs the agent, as a loop. It takes in context and asks for tool calls. He called that a slight oversimplification, but not far off. The risk comes from what flows into it.

He said early agent sandboxes were a whole laptop. Teams are now shrinking them to fit one task. A smaller sandbox, he argued, makes people more willing to let an agent run for long stretches.

His main example was a newsroom split into three sandboxes. The researcher can roam the web but has no tools to publish. The fact-checker has no network and can read the research and a fact database. The publisher has no network but holds the publishing tool. He said this mirrors how complex systems are already split into parts.

Asked how many credentials a sandbox should hold, Clark said "the right answer is always zero." With none inside, he said, an agent's mistakes do less damage. Once a sandbox is defined by its tools and network rules, "You almost make the harness a parameter of the sandbox." He also described XAA, a Docker, Anthropic and Okta effort that grants agents access through a company's existing identity provider.

Why it matters

Our reading: this moves the safety question from the vendor's model to your own setup. A manager buying or approving an agent can ask what it can read, what it can change and which keys it holds. Those questions have answers a team controls.

It also suggests designing by role. An agent that reads untrusted web pages should not also hold publishing rights. Clark named that pairing as the dangerous one. Because the harness plugs into the sandbox, teams can swap harnesses without redoing the safety work.

The other side

Clark works at Docker, and he closed by pointing to Docker's own tool for building these containers. The argument fits his employer's product. He also spoke in terms of feeling safer, and he gave no incident data or measurements.

Zero credentials is also not zero access. The agent still needs to act, so trust moves to the gateway and the identity system behind it. The excerpts do not show how that central point is itself protected. They also do not say what happens when a single task truly needs both untrusted input and powerful tools.

Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.

The conversation this talking point comes from

Share this insight