brig docs

Compare

Brig and Seatbelt

On this page

Brig gives a coding agent a microVM with a kernel of its own, your project and nothing else, a network rule you write, and its login from your keychain. Seatbelt is the sandbox inside the macOS kernel, and `sandbox-exec` runs a command under a profile you write.

Seatbelt is what Claude Code, Codex, Cursor and Gemini CLI use on macOS when you turn their sandbox on. This page is about using it by hand. Brig and the agents' own sandboxes covers the built-in ones. Brig compared puts both beside the other tools.

At a glance #

Brig Seatbelt with sandbox-exec
Made for Coding agents Any process on macOS. Apple's daemons use it, and Apple points third parties to App Sandbox
Runs on macOS 15 or newer on Apple silicon, and Linux Every Mac, Intel included
Kernel One kernel per sandbox, under a hypervisor The host kernel, with a policy in front of it
Host files The project and the guest home, and nothing else from the host The paths your profile allows, for read and for write
Network An egress policy of hosts and ranges, enforced outside the guest. offline has no route out Allow or deny by operation and by port. No rule by hostname or by address
Credentials A secret store, delivered by name as a file or a variable None. The profile allows or denies the keychain's Mach service
Agent setup Eight built-in profiles, one command You write the SBPL profile
Start Boots a kernel Starts a process
Status Open source, Apache-2.0, in active development Deprecated in its own man page. Still shipped and used by Apple in macOS 26
Documentation This site and three repositories The profile language is undocumented by Apple

What Brig gives you #

A kernel the host does not share. The agent makes its system calls to a Linux kernel inside the microVM. hvi, the VMM Brig uses on macOS, treats the guest as hostile and runs inside a Seatbelt profile of its own. Brig uses Seatbelt too, as the second layer behind the hypervisor. The boundary in hvi describes both. A process under Seatbelt makes its system calls to the macOS kernel, and the policy filters them. A kernel bug reachable through an allowed operation is a way out.

Your project, and nothing else from the host. The guest has the project and its guest home, and no other host directory exists in it. What the agent cannot reach states the list and its limits. A (deny default) profile needs a long allow list before a program runs, because frameworks read files and look up Mach services at startup. In practice a profile allows file-read* on the whole disk and limits writes. Claude Code's sandbox does that. Your SSH keys, cloud credentials and browser cookies are then readable.

One host, not all hosts. You write a policy of hosts and ranges, and Brig enforces it at the gateway, outside the guest:

apiVersion: brig.sh/v1alpha1
name: locked-down
egress:
  default: deny
  allow:
    - host: api.anthropic.com

See Networking. Seatbelt filters a connection by operation and by port. The host in a rule is * or localhost and nothing else, so there is no rule for a hostname or an address. To allow one API, the tools built on Seatbelt run a proxy on the host and allow its port.

Your login, from your keychain. Brig keeps your logins in a secret store in the login keychain, and a profile names which one reaches the agent, as a file on a memory-backed mount. Credentials states each limit. A Seatbelt profile allows or denies the keychain. It does not deliver a login.

A boundary that applies before boot. Brig's boundary is the hypervisor, and it is in place before the guest starts. Seatbelt checks an operation when a process acquires a resource. A file descriptor that is already open stays usable after the profile applies.

Documented and tested. Brig's boundaries are documented on Security, and Claims names the test behind each promise. Apple does not document SBPL, and a profile written for one macOS release can fail on the next.

What Seatbelt does #

Seatbelt is a kernel policy module. A profile in the Sandbox Profile Language, SBPL, says which operations a process can perform, on which paths, Mach services and sockets. sandbox-exec -f profile.sb <command> applies the profile and runs the command. Every child inherits the profile.

The profile language is a subset of Scheme. A profile denies by default and allows operations such as file-read*, file-write*, network-outbound and mach-lookup, with subpath, literal and regex filters:

(version 1)
(deny default)
(allow process*)
(allow file-read*)
(allow file-write* (subpath "/Users/you/code/demo"))
(allow network-outbound (remote tcp "localhost:3128"))

Apple marked sandbox-exec and sandbox_init as deprecated in their man pages, and points developers to App Sandbox. The binary is still in macOS 26, and the system ships hundreds of .sb profiles for its own daemons. Apple does not document SBPL for third parties.

When Seatbelt fits #

  • Start time. sandbox-exec starts a process. Brig boots a kernel.
  • Every Mac. Seatbelt is in every macOS release, on Intel and Apple silicon. Brig needs Apple silicon and macOS 15 or newer for its default backend.
  • Nothing to install. sandbox-exec ships with macOS.
  • Mach and IPC. A profile can allow one Mach service and deny the rest. A Brig guest has no access to the host's IPC, so Brig has no rule for it.
  • A native macOS program. The agent runs as a Mac process, with the host's tools and frameworks. Under Brig, the agent runs in Linux.

Run Claude Code under each #

Under Brig:

brig run claude ~/code/demo

Under Seatbelt, with a profile you write:

sandbox-exec -f claude.sb claude

The profile must allow reads of the frameworks, the Node runtime, ~/.claude and the project, writes to ~/.claude, the project and a temp directory, and outbound network. A new Claude Code release can read a new path, and the profile must then change. Claude Code's own sandbox writes the profile for you. Brig and the agents' own sandboxes compares that path.

Sources #

Read on 2026-10-06.

  • man sandbox-exec, man sandbox_init and man 7 sandbox on macOS 26. The two commands are marked deprecated. /usr/bin/sandbox-exec is present and runs.
  • Chromium's Seatbelt design notes, for the language and the startup problem.
  • Claude Code sandboxing and Codex sandboxing, for their use of Seatbelt and the proxy.
  • A test on macOS 26 on 2026-10-07: under (allow network-outbound (remote ip "*:443")), HTTPS connects and HTTP does not. A hostname or an address in the rule is refused with host must be * or localhost in network address.

Type a command, a flag or an error message.