2 min lesson
Egress control: default-deny by design
Use the lesson to explain "How is a Cloud Agent's network egress governed?" Then make the next move clear.
Step 1 of 3
Egress control for cloud agents
Sandbox mode turns the network off by default for a local agent. For Cloud AgentsAgents that run in a Cursor-managed virtual machine, check out the repo, do the work and open a pull request, then shut down, with no load on your laptop. Press Enter for the full definition., outbound access is an access mode you choose, and the two restrictive modes work the way model and tool access does: anything not on the list is refused.
- Allow all network access
- The agent can reach any external host; no domain restrictions apply
- Default + allowlist
- The default domains plus any domains you add to your allowlist
- Allowlist only
- Only the domains you add; Cursor's own services and SCM providers stay reachable so the agent can function
- Where it's set
- Per user from the Cloud AgentsAgents that run in a Cursor-managed virtual machine, check out the repo, do the work and open a pull request, then shut down, with no load on your laptop. Press Enter for the full definition. dashboard, and per saved environment so one repo can run stricter than the rest; Enterprise admins can lock the policy org-wide
- Artifact host
- Add the exact cloud-agent-artifacts S3 host to the allowlist; do not wildcard the S3 region, which would open an exfiltration path for a prompt-injected agent
- Planned layer
- Cursor has described a denylist plus DNS filtering and an HTTP proxy as planned; confirm availability before quoting it
Allowlist-only egress means a misbehaving or prompt-injected agent has few places to send data it shouldn't.
Learn more
Full explanation
Why the controls have to scale with the code
Why the controls have to scale with the code
More agency means more security surface, and that math does not stay small. At NVIDIA-scale (on the order of 40,000 engineers using agents daily) the governance question stops being "is this safe for one developer" and becomes "how do we govern responsibly at scale."
There is a second-order effect to name. When a team ships materially more code, faster, with agents, the controls that gate code, from review capacity to access policy, have to scale with that volume. Governance that was sized for human throughput becomes the bottleneck, or worse, the gap. The three layers exist so the boundaries scale as deterministic policy.
"The privacy foundation (Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition., ZDRZero Data Retention. A contractual guarantee that the model provider won't store your code or train on it. Press Enter for the full definition., SOC 2, your IdP and MDM) is what gets you to yes on where code goes. On top of that we give you three agent controls: hooks you write and check into the repo, model and MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. allowlists down to the individual tool with auto-run or approval per tool, and a sandbox that scopes file access, turns off network by default and makes git read-only. All three are org-enforced. As you ship more code with agents, those boundaries scale as policy."
If an interviewer asks how you'd govern agents for a 40,000-engineer customer, do not list features. Lead with the principle (more agency is more surface, so controls scale with code), then name the three layers and that each is org-enforced. Close on cloud-agent egress: pick Default + allowlist or Allowlist only per user or per environment, lock it org-wide as an Enterprise admin, and allowlist the exact artifact host, never a wildcard. That shows you can govern the blast radiusHow much breaks if a change goes wrong; the scope of potential damage. Press Enter for the full definition. in practice.