Overview
How might we design sandbox preview so people can trust and act on AI output?
When to use
- Essential for agentic automation, bulk admin tools, and cross-app workflows where users need to trust a manifest of effects before granting execution rights.
When to skip
- Read-only assistants with no side effects to preview.
- Trivial single-line edits where a full sandbox is slower than an inline diff.
- When the sandbox cannot faithfully mirror production permissions, false previews are worse than none.
Rules
Previews that omit irreversible effects present in the real plan.
Execute buttons that skip sandbox after the first approval forever.
Sandboxes that mutate production data “just a little.”
Walls of logs with no human-readable summary of blast radius.
Evidence
| Product | Implementation |
|---|---|
| Terraform plan | Infrastructure dry-run listing creates/updates/destroys before apply. |
| CI dry runs | Pipeline simulation or plan jobs before merging agent changes. |
| Email merge previews | Sample personalized messages before bulk send. |
| Agent plan-then-act modes | Visible plan and file diffs prior to apply in coding agents. |