Skip to content

Safety model

Autonomy is a power tool. Daedalus is built so that even a fully autonomous run is bounded on three independent axes and confined to a disposable sandbox.

The three brakes

Autonomy is off by default. Even fully autonomous, three independent limits bind, and they are independent on purpose — defeating one does not defeat the run.

  1. auto_dispatch / autonomous — off means nothing starts without a human pressing go. The master switch also gates auto-submission of flags.
  2. max_concurrent — a hard ceiling on simultaneous agent processes.
  3. Budget tree — every team has a spend ceiling in the ledger. A turn is reserved before the process starts (an in-flight request can't be recalled), then settled against measured usage. A child can never be granted budget its parent doesn't already have.

Local (Ollama) turns are off-budget — they cost nothing against a subscription — so the budget brakes apply to the cloud path, and a wall-clock run_deadline bounds local agents instead.

Sandbox network modes

Every command runs in a container whose network reach is chosen per run. The default is the safe one.

Mode Network Reaches
isolated (default) isolated container net internet yes, your LAN no
vpn isolated + a tunnel from an uploaded profile the VPN's target range (e.g. a CTF range)
lan host network full LAN — a deliberate bypass, gated behind an explicit allow_lan setting

lan is never reached by accident: it requires an operator to flip an explicit setting, and it is one of the RBAC-gated features so not every role can enable it.

Loop and cost guards

  • Cross-turn de-duplication. If an agent re-issues an identical command it already ran, the cached result is returned instead of re-executing — this stops a confused model from burning the clock in a loop.
  • Per-turn step cap. Each agent turn is limited to a fixed number of ReAct steps.
  • Sandbox timeouts. Every sandboxed command has a default and a hard-maximum wall-clock timeout, so a hung tool cannot pin a slot indefinitely.

Why the split matters

The control plane holds state and never runs a target-facing command. The executor is the only thing that runs untrusted, agent-authored input, and it does so in throwaway containers on an isolated network. The blast radius of a rogue command is one disposable container — not the orchestrator, not your findings, not your LAN.

This is offensive tooling

The sandbox protects your infrastructure from the agent. It does nothing to make the agent's actions authorized against a target. Only point Daedalus at systems you own or are explicitly authorized to test.