Use when letting AI agents run code, install packages or touch real systems. Covers sandboxing, least privilege and quarantine basics.