Most serious writing about AI agent security comes from companies with a platform team. On May 25, 2026, Anthropic's engineering group published how it contains Claude across its products, using sandboxes, virtual machines, and egress controls. It is worth your time. It also assumes people whose full-time job is building that infrastructure.
A small team contains an AI agent the way it would contain any new user with too much access: give the agent its own scoped account, keep it on staging credentials, restrict where its traffic can go, and point it at a workspace you can throw away. Containment means limiting what an agent is able to do through the environment it runs in, rather than supervising each action. Approval prompts help, but they are not the boundary.
We build agentic delivery pipelines on client systems, most of them legacy applications that predate any of this. The containment question comes up on every engagement, and it is rarely "how does a frontier lab do this." It is "what does blast-radius control look like when the whole engineering team is ten people and none of them is a security engineer."
Are approval prompts enough to contain an AI agent?
Approval prompts are not enough on their own. The tempting answer is supervision: the agent proposes, a human approves, and the dialog becomes the security model.
Two published findings argue against leaning on that alone. In the same May 25 post, Anthropic reported that its telemetry showed users approving roughly 93% of permission prompts, and that the more approvals people see, the less attention they pay to each. On July 8, 2026, Wiz published GhostApproval research showing that six mainstream coding assistants could be steered by a planted symlink into writing files outside their workspace. In some cases the approval dialog showed the user a harmless local filename. Wiz called it "a category-level blind spot across AI coding tools," not one vendor's bug. We covered the repository side of that finding in what we check before pointing a coding agent at a repo.
None of this takes humans out of the loop. It means the loop is a probabilistic control, and probabilistic controls miss. The boundary you set in the environment before the agent runs is what catches the miss. Anthropic's own rule is to design for containment at the environment layer first.
What agent containment looks like for a small team
Environment-layer containment is mostly access control and network hygiene applied to a new kind of user. A competent small team already knows how to do all of it, and none of it needs a platform group.
Give the agent its own identity. Use a scoped service account, never a developer's credentials. Match the grants to the task and nothing more. When something goes wrong, you revoke one account, and the audit log separates what the agent did from what a person did.
Default to staging credentials. The agent works against staging or a replica. Production access is a deliberate exception with a scope and an expiry, not a standing grant. The review before that exception is its own discipline, covered in our audit before an AI agent gets production credentials.
Decide where traffic may go. The incidents worth studying share one shape: data leaves through a permitted path. An agent that can read sensitive files and reach any endpoint is an exfiltration route waiting for a bad instruction. An egress allowlist is not exotic infrastructure. It is a firewall rule set somebody has to sit down and write.
Assume the workspace gets damaged. Point the agent at something you can regenerate: a branch, a snapshot, a disposable environment. If losing the workspace would hurt, the workspace was too big.
Why legacy systems make containment harder
Legacy systems rarely support the clean version of these controls. The application uses one shared database login for everything. Staging drifted away from production years ago. The batch jobs run as domain admin because that was easier in 2014. Containment on legacy systems is remediation under another name, and it belongs in the same plan and the same budget.
Here is the uncomfortable symmetry. Every hour spent scoping accounts, separating credentials, and writing egress rules for the agent also makes the system safer for the people who use it. The agent did not create the exposure. It made the exposure impossible to keep ignoring.
If an agent is headed anywhere near systems that matter, containment is part of the implementation, not an add-on at the end. Our AI implementation framework treats it that way from the first scoping conversation.

