AI agents are moving into the enterprise, but giving them more autonomy means giving them more access. They need corporate data, search, applications and tools, and eventually the ability to take actions without waiting for a human at every step.
As we discuss in the latest episode of the Shared Everything podcast featuring a chat with VAST Data co-founder and CTO Alon Horev, all of this creates a basic infrastructure question: how do you let agents do useful work without losing control of what they can see and do?
Horev makes the case for agent sandboxes as part of that answer. An agent needs a controlled runtime with clear boundaries around its access, but it also needs enough freedom to complete the task it was given.
And because an agent can make a bad decision that might not be discovered until much later, enterprises need an observability layer that records what it accessed, what it produced and what actions it took.
Those sandboxes also have to persist, he argues, and for good reason. An agent may create files, analyze data or build up a working environment that is still useful after the immediate task is finished. It may stop working and return a day or a week later.
As he explains, this data cannot simply live on whatever machine happened to run the agent. Supporting large numbers of persistent agent environments turns the sandbox itself into a data platform problem.
Scale makes this more interesting. Instead of a person occasionally querying a database or opening a dashboard, enterprises could have thousands of agents constantly searching structured and unstructured information. Systems built around human access patterns were not designed for that pressure.
Agents also need current information, making fast search and real-time access to enterprise data increasingly important. Horev details why they also need a controlled way to act on what they find and points to MCP tools as an increasingly common way to give agents access to outside systems and actions.
That makes the architecture more than a sandbox around a model. It becomes a combination of runtime, data access, security, search, observability and tools, all of which have to work together without creating another unmanageable layer of infrastructure.
Horev also sees the architecture extending beyond the datacenter. Physical AI will split work between agents running locally at the edge and larger models running in centralized AI infrastructure, adding latency, throughput and data movement to the problem.
Agents may be the visible part of this shift, but putting them into production will depend heavily on what sits underneath them: somewhere controlled to run, fast access to the right data, a record of what they did and infrastructure capable of supporting them at scale.



