Lesson 4 / 29
Where Agents Run: Editor, Terminal, Cloud and CI
Compare the main environments and their trade-offs.
Closer to you, or further away
Agents run in several places. In the editor/IDE they work beside you with visible diffs and quick approvals: great for interactive work. In the terminal, a command-line agent works in your local repository with your shell and tools, which is powerful but runs with your permissions. In the cloud, an agent runs in a remote sandbox on a copy of the repository, can work in the background on many tasks in parallel, and returns a branch or pull request: convenient and isolated, but it cannot see your local state and needs the repository and secrets set up carefully. In CI or automation, an agent reacts to events (a failing build, a new issue) under strict, pre-set permissions. Pick the place by how much autonomy you want, how risky the task is, and how much isolation you need: the more autonomous, the more isolated it should be.
Choosing an environment
Starting points only.
Environment Autonomy Isolation Good for Watch out for
editor / IDE low-medium none interactive edits, learning the code approving too fast
terminal medium none repo-wide changes with local tools runs with YOUR permissions
cloud sandbox high strong parallel/background tasks -> PRs no local state; secrets setup
CI automation scoped strong triage, flaky-test fixes, upgrades strict permissions, budgetsMatch isolation to autonomy
Interactive in your editor can be lightly isolated; unattended cloud runs should be heavily sandboxed.
Quick check: Which pairing follows the rule "more autonomy, more isolation"?
- A fully autonomous agent with admin rights on your laptop
- A background cloud agent working in a sandbox on a repository copy
- An unreviewed agent pushing to main
- An agent holding production credentials
Answer
A background cloud agent working in a sandbox on a repository copy — Isolation limits the damage an autonomous agent can do.