> Markdown version of [/videos/100550-manufacturing-trust-speed-and-safety-in-the-age-of-agents](https://www.wearedevelopers.com/videos/100550-manufacturing-trust-speed-and-safety-in-the-age-of-agents). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manufacturing trust: speed and safety in the age of agents Stop relying on AI to police itself. Discover how Docker's new micro-VM sandboxes help developers embed deterministic boundaries to safely scale multi-agent production and secure autonomous code. - **Speakers:** [Mark Cavage](https://www.wearedevelopers.com/@mark-cavage), [Michael Irwin](https://www.wearedevelopers.com/@michael-irwin), [Hervé Bizira](https://www.wearedevelopers.com/@herve-bizira) - **Event:** World Congress 2026 North America - **Published:** September 24, 2026 - **Duration:** 31:59 - **URL:** https://www.wearedevelopers.com/videos/100550-manufacturing-trust-speed-and-safety-in-the-age-of-agents ## Summary While AI agents accelerate software development, their nondeterministic nature breaks traditional, human-speed trust models like code reviews and continuous integration. Agents act autonomously, proactively probing system boundaries and executing semantic actions that can jeopardize security and data privacy. Rather than relying on a probabilistic model to police itself, developers must manufacture trust by embedding enforceable, deterministic boundaries directly into the infrastructure. To separate standard application containers from true agent containment, Docker introduces a micro-VM sandbox architecture designed specifically for AI workloads. This sandbox provides the foundational layer of deterministic reality, strictly gating network traffic, file access, and secrets via explicit intent-based policies. Building on this foundation, the new Docker Sandbox Kit specification—an open standard migrating to the CNCF—extends familiar Dockerfile concepts to define agent environments, routing, and Model Context Protocol (MCP) gateways. This standardization allows teams to seamlessly swap models or tools while maintaining a durable trust layer. Transitioning from using single agents as isolated tools to operating a multi-agent production factory requires four pillars: containment, control, choice, and capacity. With integrations like Hermes Enterprise capturing organizational traces to post-train sovereign models, developers are effectively becoming managers of their own autonomous agent teams. As Docker Cloud Sandboxes enable zero-friction scaling from local laptops to cloud infrastructure, human engineers remain the ultimate arbiters of quality. The core engineering skill shifts from writing boilerplate to exercising architectural judgment, designing agent handoffs, and ultimately deciding what ships to production. **Keywords:** ai agent sandboxing, deterministic security boundaries, docker sandbox kit specification, model context protocol gateways, micro-vm container isolation, intent-based agent policies, agent factory architecture, hermes enterprise collective wisdom, sovereign ai model training, docker cloud sandboxes, autonomous agent infrastructure, nondeterministic software controls, ai workflow reproducibility, cncf open governance standards ## Chapters 1. **Security risks of running autonomous AI agents** (00:49) — Probabilistic models given access to local systems will inevitably probe and dissolve standard container boundaries. 1. **Isolating agents with micro virtual machine sandboxes** (03:57) — Replacing standard containers with shared-nothing micro VMs ensures hard boundaries that autonomous models cannot rewrite. 1. **Enforcing deterministic policies to prevent semantic agent attacks** (07:01) — Grounding probabilistic agent actions in deterministic rules prevents models from abusing legitimate access permissions. 1. **Managing collaborative agent workflows as software production factories** (11:34) — Scaling from individual tools to agent teams requires engineering explicit roles, handoffs, and operational definitions. 1. **Core requirements for scalable agent production architectures** (13:29) — Effective agent factories depend on strict containment, operational control, tooling choice, and reproducible compute capacity. 1. **Standardizing agent environments with Docker Sandbox Kits** (15:26) — Extending Dockerfiles to define agent capabilities, network access, and tools ensures reproducible execution across platforms. 1. **Capturing institutional knowledge using self-learning agent traces** (18:06) — Deploying sovereign AI stacks allows organizations to safely capture problem-solving traces and build collective wisdom. 1. **Injecting credentials and applying network proxies in sandboxes** (22:55) — Executing agents within strict micro VMs allows developers to securely proxy network requests and inject credentials without leaking secrets. 1. **Scaling autonomous workflows with Docker Cloud Sandboxes** (28:04) — Transitioning local agent workloads to cloud infrastructure provides the necessary capacity to run large-scale collaborative models. ## Related Moments - [Mitigating operational risks through robust agent sandboxing](https://www.wearedevelopers.com/videos/100448-don-t-kill-my-vibes-simple-steps-to-stay-secure-when-vibe-coding) (from "Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding") - [Securing open source agents and orchestrating multiple models](https://www.wearedevelopers.com/videos/100429-from-stateless-to-self-improving-building-agent-workflows-that-get-better-every-session) (from "From Stateless to Self-Improving: Building Agent Workflows That Get Better Every Session") - [Core architectural pillars of an agent sandbox environment](https://www.wearedevelopers.com/videos/100555-kubernetes-is-not-your-sandbox) (from "Kubernetes Is Not Your Sandbox") - [Scaling and managing multiple AI models in sandboxes](https://www.wearedevelopers.com/videos/100532-give-the-agent-its-own-machine) (from "Give the Agent Its Own Machine") - [Setting up local AI sandboxing with Docker SBX](https://www.wearedevelopers.com/videos/100532-give-the-agent-its-own-machine) (from "Give the Agent Its Own Machine") - [Generating engineering impact through sandboxed multi-agent experimentation](https://www.wearedevelopers.com/videos/100266-ai-won-t-fix-your-engineering-culture) (from "AI Won't Fix Your Engineering Culture") ## Related Articles - [ I Gave a Video Editor More Autonomy Than a Trading Bot. On Purpose.](https://www.wearedevelopers.com/magazine/773-i-gave-a-video-editor-more-autonomy-than-a-trading-bot-on-purpose) - [Never delegate the understanding](https://www.wearedevelopers.com/magazine/749-never-delegate-the-understanding) - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [Building AI Solutions with Rust and Docker](https://www.wearedevelopers.com/magazine/494-building-ai-solutions-with-rust-and-docker) ## Related Jobs - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2161904-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2145616-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2145730-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes](https://www.wearedevelopers.com/jobs/48460-senior-software-engineer-sandboxes) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2159298-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Staff Software Engineer, Agentic Platform](https://www.wearedevelopers.com/jobs/48464-staff-software-engineer-agentic-platform) at **Docker, Inc.**