Seems aws also announced a sandbox solution
I used agent over 1 year and basically always give codex full permission on each thread, do not get issue so far
Why we need this layer of complexity? Or its mainly for big company that need control ?
If you have a custom agent in a product, then it needs isolation to be sure to protect the customer data.
If you have a custom agent in a product, then it needs isolation to be sure to protect the customer data.