Chapters

Chapter 10

What the agent can do: permissions and the network

A sandbox has no network card. Its only way out is a proxy in Dozer's host, on your Mac, which checks every connection against the sandbox's permissions — a short list of plain-language switches — and logs it.

On this page
  1. Concepts
  2. See what the agent can do
  3. Change it — in the terminal
  4. Change it — in the dashboard
  5. The network kinds
  6. The raw rules
  7. Settings
  8. Limits and security
  9. Troubleshooting

A sandbox has no network card. Its only way out is a proxy in Dozer's host, on your Mac, which checks every connection against the sandbox's permissions — a short list of plain-language switches — and logs it. You decide what the agent may reach; the agent can't change it.

Concepts#

  • Permissions are what an agent may do, each a switch:

    permissionidwhat it allowsin Standard
    Talk to its AI modelmodelAnthropic's APIalways on
    Talk to OpenAImodel:openaiCodex's model (chatgpt.com, api.openai.com) — Codexalways on in a Codex sandbox; never in another agent's
    Sign insign-inClaude's sign-in pages, for signing in inside the sandboxoff (Dozer supplies the credential)
    Update itselfupdatenew versions of Claude Code or pion
    Install software — system packagesinstall:systemapt / apkon
    Install software — Node, Python, Go, Rust, Java, Ruby, .NETinstall:node, install:python, install:go, install:rust, install:java, install:ruby, install:dotnet (install = all)that language's package registryyour base's language
    Use GitHubgithubclone and fetch code; Claude Code's pluginson
    Use GitHub as yougithub:as-yougit and gh signed in as you — read-only (GitHub as you)off, in every preset
    Push to GitHubgithub:pushalso push and change things on GitHub as youoff, in every preset
    Send error reportserror-reportsthe agent reporting its own crashes to its makeron
    Browse the webwebany websiteoff — the agent could send your code anywhere
    Sites you allowsite:HOSTone host (api.example.com, or *.example.com)none

    doz net permissions lists every permission with the exact hosts behind it in your version of Dozer.

  • Presets: Locked (its AI model only), Standard, Open (everything, still logged). Your GitHub login is never part of a preset — not even Open: it's switched on by name, and a preset you choose later keeps it as it was. New sandboxes get the setting defaults.permissions (standard).

  • Stored by name. A sandbox remembers "Update itself", not a list of hosts, so when a new version of Dozer adds a host to a permission, every sandbox that has it gets it.

  • Live. A change applies to the sandbox's next connection — no restart — and is kept for its next start.

  • Everything is logged: host, verdict, rule, bytes. Never the contents.

See what the agent can do#

sh
doz net my-app            # the checklist, its sites, and what it was refused lately
doz net log my-app        # the connection log
doz net log my-app --denied --follow

When the agent was refused something a permission would allow, doz net says so — "the agent tried to install Python packages (PyPI), 3 times" — with the command that allows it.

Change it — in the terminal#

sh
doz net allow my-app install:python          # switch a permission on
doz net allow my-app site:api.example.com    # one site
doz net deny my-app github                   # switch one off
doz net deny my-app site:tracker.example.com
doz net allow my-app locked                  # or standard, open: a preset
doz net allow my-app web --yes               # asks first without --yes
doz create my-app --allow install:rust,site:api.example.com,-error-reports

--allow on create and up adds to the default: permission ids, -PERMISSION to remove one, site:HOST, or a preset name.

Change it — in the dashboard#

On a sandbox's page, the details' Network tab › What the agent can do shows the presets (Locked · Standard · Open) and the permissions as switches, with its sites below. Flip a switch and it applies at once; each permission's hosts unfold beneath it. When the agent was refused something, a line says so — "The agent tried to install Python packages (PyPI)" — with Allow (or Allow this site). Browse the web asks you to confirm first. Details: the rules and hosts shows every host behind the switches, and Edit policy… edits the raw rules with a preview of exactly what changes.

What the agent can do
What the agent can do

New sandbox shows the same switches (preset from the base you chose), and the Settings page edits defaults.permissions with them.

The network kinds#

--network on create (and network: in doz_project.yaml) chooses how a sandbox is connected:

--networkwhat it is
agentproxied, with the Standard permissions (the default for agent images)
lockedproxied, Locked: the agent's model only
openproxied, Open: everything, still logged
bakeproxied, package registries only (the default for lab, and what image preparation uses)
nata real network card through macOS's NAT: not filtered or logged
noneno network at all

The proxied kinds have no network card: every connection, DNS included, goes through the proxy. nat and none are the virtual machine's make-up, fixed when the sandbox is made.

The raw rules#

Under the permissions there are rules, which you can still edit directly:

sh
doz net policy my-app                                   # show
doz net policy my-app --allow github.com --allow '*.githubusercontent.com'
doz net policy my-app --deny example.com --remove github.com
doz net policy my-app --preset open                     # replace with a preset: locked, bake, agent, open

Your own rules win over a permission's hosts. A host your rules can't allow doesn't even resolve.

Settings#

keydefaultwhat it does
defaults.permissionsstandardWhat a new sandbox's agent may do: standard, locked, open, or Standard with changes like +web,-error-reports.
images.claude-code.network · images.pi.network · images.lab.networkagent · agent · bakeThe network kind of a new sandbox of each image.
defaults.nat_subnet(a free one)The subnet of a new nat sandbox ($DOZ_SUBNET).

Limits and security#

  • Browse the web and Open let the agent send your code and data anywhere. Prefer a site:HOST for what the agent really needs.
  • A Dockerfile build runs outside this policy (in Apple's builder); the sandbox made from it doesn't. See Images and bases.
  • IPv4 only; HTTP/2 isn't passed through on the hosts whose traffic the proxy inspects; UDP is refused (programs fall back to TCP).
  • There are no general port forwards from your Mac into a sandbox. The one exception is a sign-in's callback, briefly — see Signing in from a sandbox.
  • A sandbox made with an older version of Dozer keeps its rules; doz net NAME shows them as the permissions they amount to, and its first permission change stores them as permissions (anything no permission covers stays as your own site rules).

Troubleshooting#

symptomwhat to do
A package install failsdoz net NAME says what was refused and which permission allows it: doz net allow NAME install:python.
The agent can't reach your company's APIdoz net allow NAME site:api.example.com.
A site works in your browser but not in the sandboxdoz net log NAME --denied shows the refused host — sites often use a second host for assets or APIs.
Claude Code can't update itselfupdate must be on (it is in Standard).
You need the whole web for a whiledoz net allow NAME web, then doz net deny NAME web when done.

Edit this page on GitHub · Chapter 10 of 25