Safety & Security · Data artifact
Runtime Security Policy
Data artifactSafety & SecuritySafety, Security & Governancearc:RuntimeSecurityPolicy
A declarative rule set specifying permitted system calls, accessible file paths, spawnable processes and reachable network destinations for sandboxed execution.
Responsibility. Defines which runtime operations sandboxed code may perform.
Also known as: Sandbox policy
Relationships
configures structural
is audited by assurance
Design guidance
- SHOULD start restrictive and relax incrementally based on observed false positives, treating refinement as ongoing.
- SHOULD be reviewed quarterly and whenever agent capabilities change.
Classification
- Patterns
- Start restrictive, relax on observed false positivesLeast privilege
- Risks mitigated
- Permission creepPermission staleness
Sources
- Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.