---
title: "Delegate · intentic"
description: "Run the sandbox on a server you own and hand it end-to-end operation: an image overlay you approve, a private tunnel your browser dials, a spend ledger the platform never sees, and the platform off the command path."
url: "https://intentic.dev/product/delegate/"
---

Delegate

# Delegate the running. Keep the owning.

A sandbox is a Docker container on your own laptop, desktop or VPS. Put it on a server, hand it end-to-end operation — and because the platform sits off the command path, you give up none of the control.

[Get started free](https://app.intentic.dev) [Open the live workspace](https://intentic.dev/demo/)

acme-shop · /sandbox

![The sandbox hub: the acme-shop sandbox online with its installed version and URL, and an at-a-glance list of its agent account, secrets, capabilities, running services and access.](https://intentic.dev/_astro/sandbox-overview.GCqFN3zD_2eHIot.webp)

- No code

 the platform never stores your source, your prompts or your credentials
- MIT

 all of intentic is open source, platform included
- No ports

 nothing inbound is opened; the tunnel dials out

## It runs on hardware you own

The sandbox dials out over a private Cloudflare tunnel and your browser talks to that address. Put the machine on a VPS and it keeps working without you — the platform never relays a file, a keystroke or a credential.

Your browser

Chat, files, editor, terminal

private tunnel, direct. Nothing in between

Your machine

Sandboxes, repos, credentials, capabilities

intentic platform

Identity + sandbox URL only. Off the command path.

## The image is a file you approve

Everything past the base image is an overlay Dockerfile. The agent can propose a line and then waits: you read the diff and approve before a rebuild applies it.

acme-shop · /sandbox/environment

![The sandbox Environment tab: an overlay Dockerfile diff awaiting review, adding an imagemagick install, with Reject and Approve buttons.](https://intentic.dev/_astro/sandbox-environment.DI5PrqmE_Z1L1s8A.webp)

## The bill is measured where it is spent

Every turn's tokens and cost land in the sandbox's own ledger, by day, provider and model. It is your subscription, so the platform never meters it.

acme-shop · /sandbox/usage

![The sandbox Usage tab: a stacked spend-per-day chart split by Claude Code and Codex, with cost broken down by model and by agent.](https://intentic.dev/_astro/sandbox-spend.DqO3lVId_ZxB2op.webp)

## What the platform actually holds

Identity, the sandbox's URL, and the grants that let a teammate reach it. Not your code, not your keys, not your transcripts.

### Stays inside your sandbox

- Your code and repos
- Every credential and token
- The agent's transcripts
- The container and its image

### All the platform holds

- Your identity (Google sign-in)
- The sandbox's name and URL
- Billing state
- Grants to invited teammates

What it stores is AES-256-GCM encrypted, with no decrypt path in the product.

## One sandbox, several people

The owner installs the tools; invited teammates share that same sandbox, each signed in as themselves. Setup stays owner-gated.

- Invite by email; grants are enforced by the daemon, fail-closed.
- Teammates chat, drive and review, and mirror the sandbox's ports.
- Revoking or leaving takes effect the moment you press it.

Y

You Owner

installs tools · connects systems · full control

S

Sam Teammate

chats, drives & reviews · mirrors ports

A

Ada Teammate

chats, drives & reviews · mirrors ports

each over its own private tunnel

one specialized sandbox

release-captain · on the owner's machine

running

[Next Orchestrate → Run ten agents at once and see which one needs you](https://intentic.dev/product/orchestrate/)

[Get started free](https://app.intentic.dev) [Read the quickstart](https://intentic.dev/docs/quickstart/)
