The Admin Panel has a dedicated Sandbox section for the settings that apply across your workspace. If you self-host Quor, first configure the runtime described in Deploying Sandbox. The deployment guide covers sandboxes, the proxy, workers, networking, storage, resources, and environment variables.

Control access

Open Admin Panel → Sandbox → Access. For a limited rollout, turn off Enable Sandbox by default, then enable the users who should have access. Per-user exceptions remain in place if you later change the workspace default.
Removing access prevents the user from starting new Sandbox work and skips future Scheduled Task runs they own. It does not stop a turn already in progress or delete their sessions, files, Skills, Apps, or Scheduled Tasks.

Add workspace instructions

Open Admin Panel → Sandbox → Instructions to add guidance that every Sandbox agent in your workspace should follow. Quor appends these instructions to Sandbox’s built-in instructions as an Organization instructions section. Good workspace instructions describe stable expectations that should apply to all Sandbox work: For example:
The editor accepts up to 4,000 characters. Select View base instructions to see the built-in prompt your text is added to, or Reset to default to remove the workspace instructions.
Workspace instructions supplement Sandbox’s built-in behavior. They cannot override its hard rules, App policies, user permissions, or other enforced controls.
Changes apply when a Sandbox session starts or is restored. They do not alter a session while it is actively running. Use Try in Sandbox to test the saved instructions in a new session.

Configure models

Sandbox supports Anthropic, OpenAI, and OpenRouter providers. Users also need access to the provider and at least one visible model. Give users provider access publicly or through a group. Agent whitelists apply to Quor Agents, not Sandbox. See Language Model Access Controls for provider visibility settings.

Anthropic

Configure an Anthropic provider and choose visible models.

OpenAI

Configure an OpenAI provider and choose visible models.

OpenRouter

Configure OpenRouter and select the models available through it.

Configure Apps and Skills

Apps

In Admin Panel → Sandbox → Apps, configure external services, credentials, and action policies.

Skills

In Sandbox → Skills, review reusable instructions and share custom Skills with users or groups.

Troubleshooting

Confirm you are signed in as an Admin. The section is hidden when Sandbox is unavailable on the deployment. Self-hosted operators should review Deploying Sandbox.
Confirm the user can access an Anthropic, OpenAI, or OpenRouter provider with at least one visible model. A provider limited only to an Agent whitelist is not available in Sandbox.
Check the user’s setting under Admin Panel → Sandbox → Access. A per-user exception takes precedence over the workspace default until you change it.
Start a new session to test the saved instructions. They do not update an actively running session. Also confirm the guidance does not conflict with Sandbox’s built-in hard rules or an enforced App policy.

Deployment

Configure the runtime required for self-hosted Sandbox.

Architecture

Review sandbox isolation, credential injection, approvals, and sharing boundaries.