The environment, and what a backend is
Everything in this module follows from one sentence, so it goes first.
Sandboxes are backends
“In Deep Agents, sandboxes are backends.”
Not a separate security layer. Not a wrapper you bolt on afterwards. The backend parameter from the module 1 delta list.
The backend provides the agent’s filesystem and its execution environment, and a sandbox backend is what grants the execute tool.
The filesystem is the same story
Every filesystem tool, ls, read_file, write_file, edit_file, glob, grep and delete, operates through the backend. So the backend answers a question you have to answer deliberately: when the agent writes a file, where does that file go, and who else can see it.
That is the whole design decision, and the honest framing is that it is a blast-radius decision rather than a storage one. A backend that is your actual working directory means an agent’s write_file lands in your repository. A backend that is an isolated environment means it does not.
Module 1 gave you the reason the agent needs a filesystem at all: it is the retrieval half of offloading, the place oversized tool results go so the context window does not have to hold them. So this is not an optional feature you can decline. Every deep agent has a filesystem somewhere, and backend decides where.
Two things v0.7 changed here
Backend factories were removed. That is a shape change in how you supply a backend, and it sits alongside the release’s other removals: write_todos out of the base harness, the base system prompt emptied.
delete was added to the default filesystem tools. Small, and worth noticing for what it implies: the default tool surface now includes a destructive filesystem operation, which raises the stakes on both the backend choice and the permission list two lessons from now.
The thing not to memorise
The overview page and the reference page currently disagree with each other about sandbox backend protocol versioning, and no resolution has been published.
When two official pages contradict each other on a detail, the honest position is to know the contradiction exists and not to build a memorised answer on either side. You met the same shape in module 0 with the stale deepagentsjs README, and there the resolution was clean: source beats hand-written prose. Here there is no clean tie-break, because neither page is confirmed as the generated one.
Spend the memory budget on the next two lessons instead. The default shell policy and the fail-open permission rule are unambiguous, documented, and genuinely load-bearing in production as well as in an exam.
Try it yourself
What the backend parameter buys you
One sentence that reorganises the whole module. Learn it as written, because the rest of module 2 is consequences of it.
What does the backend parameter provide to a deep agent, and what is the relationship between backends and sandboxes?
Reveal answer
The backend provides the agent's execution environment: its filesystem and its ability to run code. In Deep Agents, sandboxes are backends. A sandbox is not a separate security product bolted on top of the agent, it is what you pass as backend. That means a sandbox backend is the thing that grants the execute tool, so the sandbox is not restricting a power the agent already had, it is the source of that power.
Registered against granted
All of these are registered on a deep agent by default. Which one does nothing useful unless the backend supports it?
ls read_file write_file edit_file glob grep execute task deleteShow answer
Correct answer: C — execute, because execution is granted by the backend
execute is registered by default but only means anything when the backend provides execution. Read that the right way round: the backend is the source of the capability, not a restriction on it. task is the tempting distractor because delegation sounds like it needs somewhere to run, but a subagent is another graph invocation in the same process, not a separate execution environment.
A v0.7 removal
v0.7 removed something from the backend surface. Which of these is the actual change?
Show answer
Correct answer: A — The backend factory functions were removed
v0.7 removed backend factories, alongside making TodoListMiddleware opt-in, emptying the base system prompt, trimming tool descriptions and adding delete. The third option is the plausible-sounding one and it inverts the central claim of this module: sandboxes are backends, and splitting them into a separate parameter would undo the framing the whole design rests on.
When two official pages disagree
The overview page and the reference page currently tell different stories about sandbox backend protocol versioning, with no published resolution. What is the right posture for the exam?
Show answer
Correct answer: D — Know the contradiction exists, and spend the memory budget on the unambiguous facts
Know that the contradiction exists and do not build a memorised answer on either side of it. The second option is genuinely tempting, because generated references usually do beat hand-written prose, and that heuristic is right often enough to feel like a rule. Here neither page is confirmed as generated, so the heuristic has nothing to bite on. Meanwhile the policy default and the two security lines are unambiguous and load-bearing, which is where the revision time should go.
Draw the boundary
One diagram in a scratch file, three boxes and two arrows. This is about where things live, not about syntax.
Your diagram shows the agent process, the backend, and the host, and you can point at which boundary the execute tool crosses and which one a sandbox is supposed to defend.