Goal: Let organizations connect their own OpenSandbox service instead of relying on one deployment-wide endpoint and credential.
Define the tenant-scoped Sandbox connection and driver contract. Sandbox creation, reuse, policy, lifecycle, and cleanup must use the selected organization's connection, with cross-organization isolation verified end to end.
Out of scope: additional Sandbox providers; E2B is tracked separately. Detailed design will follow in a separate spec.
Goal: Let organizations connect their own OpenSandbox service instead of relying on one deployment-wide endpoint and credential.
Define the tenant-scoped Sandbox connection and driver contract. Sandbox creation, reuse, policy, lifecycle, and cleanup must use the selected organization's connection, with cross-organization isolation verified end to end.
Out of scope: additional Sandbox providers; E2B is tracked separately. Detailed design will follow in a separate spec.