About This Architecture
sandboxed.sh Self-Hosted Orchestrator provides isolated, multi-agent code execution across provisioned Linux workspaces with centralized orchestration and security controls. Developers interact via the sandboxed.sh Dashboard, which routes requests to the Workspace Orchestrator that manages provisioning, security checks via OKX, and skill libraries across isolated Linux containers running Claude, OpenCode, Codex, Gemini, and Grok agents. All workspace state, encrypted secrets, audit logs, and session data flow through a dedicated Security and Data Layer, ensuring compliance and auditability. Fork this diagram to customize workspace configurations, add provider-specific integrations, or document your internal code execution platform. The architecture demonstrates zero-trust isolation patterns ideal for multi-tenant or regulated environments requiring agent sandboxing.