Two execution models
Verification presets run in disposable project copies with network disabled. Live terminal commands and managed processes operate on the approved workspace through the platform's AI sandbox.
- Linux: Bubblewrap
- Windows: AppContainer + Job Object
- macOS: Seatbelt sandbox-exec compatibility backend
Managed processes
Long-running builds, dev servers, and workers get durable RepoTunnel IDs, bounded output, stop/restart support, and process-state tracking. Linux supports validated process reattachment across a complete RepoTunnel restart; Windows and macOS do not claim that capability yet.
Use the Commands screen
Select the intended project in Commands. The screen combines a live one-shot terminal, persistent processes, application launches, managed browser automation and monitoring.
Use a one-shot command for finite work, a managed process for a development server or worker, and a discovered disposable preset for isolated verification.
Follow a real development task
- Inspect the project’s detected commands and readiness.
- Run the appropriate build/test in the disposable sandbox when persistent writes are unnecessary.
- Start the preview server as a managed process when UI testing needs it.
- Inspect the process output and real application state before reporting completion.
- Stop or restart that specific managed process when the task requires it.
Keep runtime recovery evidence
Managed processes expose identity, status and bounded incremental logs. Connection/UI reconnection is different from a full application restart; complete restart reattachment is currently advertised on Linux only.
The native sandbox must be available for AI execution. A policy denial is a reported boundary, not permission to fall back to an unrestricted host shell.