Safety gate
Runtime isolation
Dedicated machine, VM, container, or separate OS user is used where practical.Use Partial or Not sure when the control exists but has not been tested.
The agent does not have unnecessary access to personal or work files.Use Partial or Not sure when the control exists but has not been tested.
The test workspace is separate from production repositories and synced folders.Use Partial or Not sure when the control exists but has not been tested.