Agent workspaces
An agent that works in your repositories shouldn't commit as you, push with your GitHub sign-in, read the rest of your Mac or reach every host it can. A Parallex agent workspace gives it an identity of its own: its own git author and SSH signing key, its own GitHub token, its own Claude Code and Codex config, a browser of its own, and network rules, with a snapshot before every run and a report of what it did after. New agents are Sealed: each run goes inside a macOS sandbox Parallex writes for it, which keeps it to the folder you run it in and its own home. It's a macOS sandbox, not a VM. Agent workspaces are part of Parallex Pro, and the free trial includes them.
Facts about other apps checked against their own sites on October 6, 2026.
Set one up
- Make it:
parallex agent new reviewer --email reviewer@example.com --repo acme/api --allow github.com --allow api.anthropic.com, or New Agent Workspace in the app. Add--browser chromefor a Chrome of its own. - Add its signing key on GitHub:
parallex agent key reviewerprints the public key. Add it as a Signing Key on the account whose verified email its commits use, and its commits show as Verified. - Give it a GitHub token:
parallex agent github revieweropens GitHub's new fine-grained token page with the name, owner, expiry and permissions filled in. Pick its repositories there (GitHub doesn't let a link choose them), generate the token and paste it. It goes to the agent's ownghconfig, not the keychain, and never to Parallex. - Run it:
parallex agent run reviewer --in ~/code/api -- claude -p "review PR 12". It runs as the agent, through its network rules, after a snapshot. - See what it did with
parallex agent report reviewer, and put it back withparallex agent rewind reviewer.
Sealed: a macOS sandbox for each run
With Sealed on (the default for new agents), parallex agent run starts the agent through macOS's own sandbox, with a profile Parallex writes for that run. It can read and write the folder you run it in and its own home, and read its signing key, the tools it needs (nvm, Claude Code, Bun, cargo, rustup, Go, pyenv, Volta, a Homebrew in your home) and any folder you grant it, read only or read and write. It can't read the rest of your home folder: your documents, other repositories, dotfiles, SSH keys, cloud and registry sign-ins. It can't read your keychain, Parallex's own folder, or other programs' temporary files, and it can't write anywhere else, your tools and apps included.
It can't open apps, read your clipboard, change settings, or signal or look at your other programs: macOS services are limited to a short allowlist, taken from Codex's own sandbox policy. Its network goes through its proxy or nowhere, because macOS refuses any other connection and name lookups, with one exception: a Local servers switch, on unless it's offline, lets it reach what's listening on your Mac, like a dev server or a database, without going through the proxy (so a local proxy there could fetch onward for it), and lets it start servers, which can be reached from your network unless your firewall blocks them. Turn it off when it doesn't need them.
A page it asks to open (to sign in, say) is never opened for it: your browser isn't behind its proxy and has your sign-ins. The run's terminal and its page in Parallex show the whole address, marked when it's outside its network rule, and opening it is your choice. Sign-ins that show a link or a code, like Claude Code's /login or codex login --device-auth, work that way.
- What it can reach: its page lists it plainly, with Grant Folder… for more and what the seal refused in its last run (from the system log, best effort).
parallex agent showsays the same, andparallex agent check --sealedruns a real sealed run on your Mac and tries each way out from inside it. - Git: in the folder it works in,
.git/hooksand.git/configstay read only, and it can't make a new repository there. Its own git runs with no hooks at all. - Sign-ins: turning Sealed on copies the agent's own Claude Code sign-in from the keychain into a file in its home (macOS may ask once), so it stays signed in. If that's declined, sign it in once inside the seal.
- Codex and Claude Code: macOS's sandbox can't be nested, so inside the seal Codex runs its commands without a sandbox of its own and Claude Code's
/sandboxis off. The seal around them is stricter about what can be read. - Agents made before Sealed: their page offers to turn it on, once. Nothing changes until you say so.
What Sealed isn't
It isn't a VM. It runs as you on your Mac's kernel, so a bug in macOS's sandbox could let it out. Apple marks the sandbox tool deprecated: Parallex tries it before every sealed run, and if it stops working, the run is refused rather than run unsealed. It can read anything you grant it, and files outside your home that any program can (like /Applications). What it writes into your repository runs as you when you run it, so review its work before you run it.
What it has of its own
- Git: commits as "reviewer (agent)", signed with an ed25519 SSH key kept in its own folder. Its git config holds nothing of yours, and its runs read only that file. Its one credential helper, for every host, gives the token in its own
ghconfig and nothing else: none of your credential helpers. - SSH: its git uses
sshwith no config file, no SSH agent and no key files, so none of yourHostaliases or SSH keys. GitHub's SSH addresses go over HTTPS with its own token. That's its git: a plainssh,scporrsyncin a run can still use your SSH keys. Signing still works with its own key. - GitHub: a fine-grained token limited to the repositories you picked, kept in its own
ghconfig. Without one, its tools get a placeholder GitHub refuses, inGH_TOKENand in itsghconfig for every host yourghknows, so they find it before they'd look in the keychain, and GitHub access is blocked. Your keychain itself is still readable by anything running as you, the agent included, if it tries. - Claude Code and Codex: a config of its own (
CLAUDE_CONFIG_DIR,CODEX_HOME): its own sign-in, history and settings, with your CLAUDE.md, skills and plugins shared if you like. - A browser: optionally a Chrome of its own, outlined in the agents' red, signed in to nothing of yours.
- Shared: unsealed, everything else in your home, as with any workspace: it runs as you and can read your files and keychain if it tries. For a boundary, turn on Sealed. Either way it reads its own signing key, token and decoys (it has to, to use them). If you share your Claude setup with it, those shared files are yours: unsealed, what it changes there changes yours, and a rewind doesn't undo it; sealed, it can only read them.
Network rules, and their limits
Each agent is online, limited to some hosts (and their subdomains), or offline. Parallex keeps the rule with a proxy on your Mac, started for each run and given to its tools, with a password made for the run, through HTTP_PROXY, HTTPS_PROXY, ALL_PROXY and git's own setting. git, gh, curl, npm, pip, Claude Code and Codex keep to it, like other tools that use a proxy when told to, and connections it refuses are logged. A host that isn't a plain host name is refused, and a plain HTTP connection carries one request.
Unsealed, a program that ignores those variables can go around the proxy; sealed, macOS refuses any connection that doesn't go through it, except to what's listening on your Mac while Local servers is on. The agent's browser isn't covered. HTTPS isn't opened: the proxy sees which host is asked for, never what's sent.
Snapshots, reports and the kill switch
Before every run, Parallex takes an APFS snapshot of the agent's own state: its git and gh settings, sign-ins, and Claude Code and Codex config and history. Not your repositories: for those, the report lists the agent's commits, and git can undo them. Its GitHub token is never in a snapshot, so a rewind keeps the one it has. Rewinding refuses while the agent runs, never writes through a link, and keeps what it replaces. Deleting an agent removes its signing key, its token and its Claude Code sign-in for good; revoke the token and key on GitHub too. In a repository whose own git config holds a token (in a remote URL, say), the agent's git uses it there, as git does; parallex agent run warns when it sees one.
A run's report comes from the agent's own Claude Code transcripts and Codex sessions (the files they read and edited and the commands they ran), the hosts in its proxy log, and the git commits made in the folder it ran in. It lists those sources. It isn't a full audit of your Mac: a program can read files or reach the network without showing up in any of them, and the transcripts are the agent's own files, which it could change.
parallex agent pause --all, the menu bar or a shortcut you choose pauses the processes Parallex has seen an agent run start, including detached ones it saw, and cuts their network. Parallex records a run's processes a few times a second, with their start times, so a program that drops the run's tag (as Node, Bun and Python do for their children) is still caught; one started and detached between two looks can slip through, and so can apps opened through macOS (open, LaunchServices). While a run goes on, Parallex holds the pause itself, so deleting the pause file doesn't bring the network back; only a resume from outside the run does. A process of the agent's that pause never saw could still send one, so this guards against accidents, not a determined agent. The shortcut only pauses; resume from the menu bar or the command line. Optionally, decoy credentials in an agent's home flag any attempt to read or use them.
From Claude Code and Codex
Parallex's MCP server lets Claude Code, Codex and other MCP clients list workspaces, open a clean browser or a throwaway copy of an app, snapshot an agent, read a report, and ask who they're running as. Rewinding asks you first, in clients that support it. Add it with claude mcp add parallex -- parallex mcp, or in Codex's config.toml under [mcp_servers.parallex] with command = "parallex" and args = ["mcp"]. It redacts the secrets it recognises from its answers.
Inside an agent run, the MCP server keeps to that agent's network rule: a clean browser or a throwaway copy only when the agent is online, or a browser for an address on its allowed hosts, and neither goes through the agent's proxy. Reports from inside an agent are that agent's own.
Questions
Does an agent workspace sandbox the agent?
Sealed, yes: each run goes inside a macOS sandbox Parallex writes for it, which keeps it to the folder you run it in, its own home, the tools it needs and the folders you grant it, keeps it out of your keychain and other programs, and sends its network through its proxy or nowhere (but for what's listening on your Mac, while Local servers is on). It's a macOS sandbox, not a VM: it runs as you on your Mac's kernel. Unsealed, it isn't a sandbox: it runs as you and can read your files and keychain if it tries. New agents are sealed.
Why not a virtual machine?
A VM is a harder boundary, but the agent then needs its own copy of your tools and repository, and a macOS VM is large and limited to two per Mac. Sealed keeps your Mac's tools and a real folder, at the cost of sharing macOS's kernel. For code you don't trust at all, use a VM as well.
Can Parallex make the GitHub token for me?
No. GitHub doesn't let other apps make fine-grained personal access tokens. Parallex opens GitHub's page with everything a link can fill in, says which repositories and permissions to pick, and signs the agent's own gh in with the token you paste.
Do the network rules work for every program?
Sealed, for everything but your own Mac: macOS refuses any connection that doesn't go through the agent's proxy, so a program that ignores the proxy settings reaches nothing out there. With Local servers on (the default), any program in it reaches whatever is listening on your Mac without the proxy, a local proxy that fetches onward included; turn it off when it doesn't need them. Unsealed, only programs that use a proxy when told to through HTTP_PROXY, HTTPS_PROXY or ALL_PROXY keep to them, which includes git, gh, curl, npm, pip, Claude Code and Codex.
Get Parallex
Try it free for 14 days, then a one-time purchase, for macOS 14 and later. In Terminal:
curl -fsSL https://parallex.mandip.dev/install | sh
Or download the disk image, or with Homebrew: brew install --cask mandipadk/parallex/parallex.