One tenant, one sandbox
Every assistant runs in its own isolated Kubernetes namespace with locked-down pod security, its own service account, and network policies that keep it off our internal network, the cloud metadata server and every other tenant. Agent workloads run under kernel-level gVisor sandboxing on a dedicated node pool. Assistants cannot see each other. By construction, not by convention.
