Code and files
Modules, paths, packages, services, and generated artifacts that a run is allowed to inspect or modify.
Agent work should know what it may touch, what it must avoid, and what review is required before changes leave a contained workspace.
Modules, paths, packages, services, and generated artifacts that a run is allowed to inspect or modify.
Datasets, regulated information, production records, exported files, and synthetic or redacted alternatives.
Which environment-provided credentials are present, absent, or deliberately unavailable for this run.
Pushes, deploys, ticket writes, cloud mutations, notifications, billing changes, and other effects outside local state.
LexRunner's contained execution direction is about keeping blast radius small while allowing parallel agent work. Promotion out of containment should be gated, receipted, and easy to review.