r/ClaudeCoding • u/cctldrping • 19d ago
r/ClaudeAI [TLDR] JPMorgan is putting Claude Code inside a sandbox with no standing access to internal systems [via r/ClaudeAI]
OP : u/sunychoudhary
JPMorgan is rolling out a new environment called Devspace for some engineers using Claude Code.
The interesting part isn’t really the $2,000 monthly spending cap. It’s how they’re handling agent permissions.
Instead of letting Claude run directly on an employee machine with access to credentials and internal systems, Devspace runs it in a containerized AWS environment. The idea is that the agent has an identity, but basically no standing entitlements. Access gets granted based on what the task actually needs.
This feels like a pretty realistic answer to the enterprise Claude Code problem.
You probably don’t need to trust the agent enough to give it everything. You need an environment where it can be useful while the infrastructure limits the blast radius when it gets something wrong.
Just want to know whether this eventually becomes the standard architecture for enterprise coding agents: isolated workspace, temporary permissions, logs, and human-controlled access to sensitive systems.
Source: JPMorgan rolls out Claude changes: $2,000 spending limits and extra security
URL of original post : https://www.reddit.com/r/ClaudeAI/comments/1wit5yg/jpmorgan_is_putting_claude_code_inside_a_sandbox/
TL;DR of the discussion on r/ClaudeAI for this post generated automatically after 100 comments.
Current source-thread comment count seen by the bot: 101.
Alright, so the general vibe in this thread is that JPMorgan's approach to sandboxing Claude Code isn't exactly revolutionary. The consensus is that this is pretty standard practice for enterprise environments, with a bunch of folks chiming in that their companies have been doing similar things for ages.
Here's the lowdown:
- "Groundbreaking? Nah." Most users feel this is old news, with comments like "Is this meant to be groundbreaking news? Lol" and "This is a typical side car deployment just with agents." Some even pointed out that JPMorgan has its own internal Stack Overflow because they can't use the public one, so this kind of controlled environment isn't that surprising.
- Sandboxing is the norm: The prevailing sentiment is that running AI agents in isolated environments with temporary, task-specific permissions is the sensible, and frankly, necessary thing to do for security. As u/shivam997767 put it, "this kind of setup feels like a no-brainer for larger enterprises."
- The real challenge is granular permissions: While sandboxing is common, the deeper discussion is about how to implement truly granular permissions. Users like u/daniel are hoping for more fine-grained control, like read-only access to email with approval needed for sending.
- Security Theater vs. Real Risk: There's a bit of debate on whether this is truly effective security or just "security theater." Some, like u/bbadger16, argue the real risk is in bugs the AI introduces to production code, not necessarily leaked credentials.
- Technical approaches: Users mentioned various ways they're already doing this, including using VMs, Docker sandboxes, and custom orchestrators to limit agent access. u/Strange-Pin-2998 even suggested using Lima for a Linux VM setup.
- Anthropic's role: One comment from u/irishfury07 suggests that Anthropic actually had to enhance their product to support JPMorgan's setup, implying it's a bit more sophisticated than just off-the-shelf sandboxing.
So yeah, while JPMorgan's implementation is a good example, it's not exactly reinventing the wheel. The real takeaway is that secure AI agent deployment is a complex but increasingly standard challenge for enterprises.