Sandbox lane
A walled-off, throwaway workspace where an agent's run gets its own dependencies, services, and limits, and cannot touch anything else.
A sandbox lane is one run's own slice of infrastructure. Its own filesystem. Its own installed dependencies. Often its own database. All of it torn down when the run ends. "Lane" adds the plumbing side of the idea. Lanes are provisioned, pooled, warmed, and reclaimed, so many runs can go in parallel without sharing state.
Isolation does two jobs at once. It protects everything outside the lane. An agent that misbehaves can at worst wreck its own throwaway copy of the world. It also protects the run's results. Checks that run in a clean room cannot pass by leaning on leftovers from a past run.
The hard part is mostly cost. Cold environments are slow to build. Warm ones drift away from clean ones. So real systems balance pooling and reuse against a known clean start for each run.