Video summary
WWC26-NA - Manufacturing trust: speed and safety in the age of agents
Main summary
Key takeaways
Summary
The keynote argues that AI agents’ autonomy creates a trust problem: agents can generate and run changes faster than people can review them, and the same ability to explore systems that makes them useful can also expose data or cross security boundaries. Trust should therefore come from the system around an agent, not from assuming the model will behave safely.
Main Technical Points
- Containers alone may not be a sufficient boundary for autonomous agents. The speaker demonstrates an agent accessing host secrets because a container was launched with the Docker host socket mounted. The issue is not that containers are inherently unsafe, but that agents act autonomously and may probe their environment in ways ordinary application workloads do not.
- Use a sandbox with a stronger boundary. Docker’s approach, as described in the talk, is a micro-virtual-machine sandbox. The agent can have broad privileges inside it—such as installing packages or changing its environment—while the host and its data remain isolated.
- Apply explicit, deterministic policies. Sandboxes can control access to files, networks, and secrets. The speaker emphasizes that permissions should be enforced by the system rather than left to the agent’s judgment. For example, an email agent might be allowed to read messages and create drafts but not send them.
- Protect credentials and mediate network access. In the demo, outbound requests pass through a policy-enforcing proxy. Requests to destinations outside an allowlist require approval. The proxy can also inject credentials so the agent can use a service without directly seeing its secrets.
- Measure whether an agent stayed within its authority—not just whether it completed its task. The keynote notes that technically permitted actions can still be dangerous in context, and that hard-to-define intent-based policies remain an open challenge.
- Treat multi-agent workflows as production systems. Teams need to define which agents can act, how they hand off work, what they test, and where human approval is required. The speaker frames the engineering requirements as containment, control, choice, and power:
- Containment: Isolate agents and define security policies.
- Control: Observe activity and costs, and be able to stop work when needed.
- Choice: Switch models, tools, or frameworks without rebuilding the trust layer.
- Power: Make environments reproducible, portable, and scalable.
Products and Announcements
- Docker SBX: A free, laptop-based sandbox environment described as a micro-VM designed for running agents.
- Docker Sandbox Kit specification: An open, Dockerfile-extension-style format for describing an agent’s environment and permissions, including runtime needs, models, MCPs, capabilities, and network access. Kits can be inspected and shared. Docker said it planned to bring the specification to the CNCF under neutral, open governance.
- Docker Cloud Sandboxes: Announced as a way to run the same sandbox setup in the cloud. The presentation described rapid startup, per-second billing, and built-in secrets, policies, networking, agent configurations, and cloud gateways. A local sandbox can be moved to the cloud and scaled while retaining the same interface and trust model.
- Hermes Business / Enterprise: Presented as an organizational agent product. Its proposed features include capturing useful skills and best practices from employee-agent work, sharing them across an organization with permission, and collecting and analyzing agent traces so companies can retain and learn from their own data.
Demo and Practical Guidance
The demo showed a Claude agent failing to access host secrets from a micro-VM sandbox, even after trying the Docker socket and other routes. It also demonstrated approval-gated network access, proxy-based credential injection, and configuring sandboxes through reusable kits and a YAML environment file that can be committed and shared with a team. A remote cloud sandbox was then used to run Hermes without keeping the laptop open.
Practical takeaway: Run agents inside enforceable sandboxes, make their permissions explicit, and build workflows that can be observed, stopped, reproduced, and scaled. Sandboxing is presented not simply as a restriction, but as a way to let agents work with less continuous human supervision.
Reviews, guides, or tutorials: No formal review or step-by-step tutorial was presented. The talk included a security demonstration and product walkthrough.
Main Speakers and Sources
- Mark Cavage — Docker President and COO; delivered the keynote and announced the sandbox products and specification.
- Michael Irwin — Docker colleague; demonstrated the sandbox workflow.
- Hervé Bazer — Introduced Hermes Business/Enterprise and its organizational features.
- Chris — WeAreDevelopers host; opened the event.
- Ed and Tom Paminger — WeAreDevelopers leadership; gave opening remarks and discussed the organization’s developer-learning platform.
Rate this summary
Your feedback will help improve summaries.
Improve this summary
Reprocess with a stronger model when the summary feels incomplete or inaccurate.
Translate summary in another language
Ask questions to this video
Chat for follow-up questions, clarifications, and source-backed answers.