Agent or application — chooses the task and sends an execution request.↓ SDK / MCPjhansi.io Runtime — owns provisioning, execution, results and cleanup.↓ controlled runtime interfaceSandbox — runs the workload inside the configured isolation boundary.↓ authorised network or credential pathExternal systems — APIs, databases, repositories and internal services.
Control boundary — the agent can request supported actions, but it does not provision infrastructure directly.Execution boundary — the workload runs inside a sandbox rather than inside the agent client or developer host.
jhansi.io’s long-term direction adds a third boundary: access to external systems should be mapped by the runtime without placing reusable secrets in the agent conversation.