---
title: "Sandboxes for background agents: full dev environments that pause when idle"
description: "Promigence gives background agents a full development environment forked from a verified snapshot, pauses it while the agent waits on a person, a queue or a timer, and never bills paused time."
url: "https://www.promigence.ai/for/background-agents"
site: "Promigence"
---

# Background agents with a full dev environment, and no bill while they wait

Promigence gives background agents a full development environment forked from a verified snapshot: your repository, its services and its build, ready when the agent starts. A long-running agent can pause while it waits on a person, a queue or a timer, and paused time is not billed.

**Who this is for:** Platform teams building internal background agents, and teams running vendor coding agents on their own pool.

## What breaks today
### A real task needs the whole dev environment
Databases, queues and a built frontend, not just a repository. Setting that up for every task takes longer than the task.

### Agents spend most of their time waiting
On the model, on a tool, on a reviewer. A sandbox billed for every second of that wait costs more than the work it does.

### Secrets and network access need a boundary
An agent with production-like access must reach the hosts it should and nothing else, with credentials that are not baked into the environment.

## What changes with Promigence
### One snapshot of the full environment
Set up the services and the build once, verify them, and fork the finished environment for each agent run.

### Pause while the agent waits
Set an idle rule and a sandbox pauses itself when nothing is happening, then wakes on the next request. Paused time is not billed.

### Allow-listed network and secrets at run time
An outbound allow-list, with every refused host recorded, and secrets injected at run time, never stored in the snapshot your build produces.

## A dev environment that pauses itself when idle
```bash
# Store a credential once; it is injected at run time, never stored in the snapshot your build produces
promigence secrets set GITHUB_TOKEN --from-env GITHUB_TOKEN

# Fork the environment and let it pause itself when idle
promigence fork --snapshot devenv@9b0d3f1 --count 1 --cap 1
promigence sandbox autopause "$SANDBOX" --after 30s

# What it may reach, and every host it was refused
promigence sandbox network "$SANDBOX"
```

