The workspace is the computer
One workspace equals one Stoic OS instance. Agents are residents of that machine. Snapshot, pause, destroy and network policy apply to the workspace. The account is not a shared PC.
App coming soon
A sealed Linux for a team of coding agents. Isolation is the workspace, not the account.

One workspace equals one Stoic OS instance. Agents are residents of that machine. Snapshot, pause, destroy and network policy apply to the workspace. The account is not a shared PC.
A declared roster: role, runtime, cwd, MCP, network, secrets. Restartable. Not a chat tab that happens to have a terminal.
Fast engine first, Chrome on promotion. Agents attach over loopback CDP. They do not each spawn Playwright-Chrome.
Immutable /usr. Updates are a new Stoic OS version. Workspace data survives. Snapshot before a risky run.
As observed in August 2026, Grok Bot runs a shared per-account pod (Cursor pod-daemon), not one VM per bot. Screens are not a security boundary. Cookies, files and CLI creds are shared.
1AgentBox gives every workspace its own Stoic OS instance. Agents are residents of that machine. You pick the model runtime per agent. Isolation and multi-model assignment are the product. Computer use is a tool, not the identity.
"A few GB" is a disk image target, not a RAM promise. Chrome dominates RAM. These are creation-sheet SKUs, not a checkout with a popular middle tier.
| SKU | RAM | vCPU | Browser | For |
|---|---|---|---|---|
| Lite | 2 GB | 2 vCPU | Fast engine only | Docs, crawl, structured sites, CLI agents |
| Standard | 8 GB | 4 vCPU | Fast + Chrome on demand | Real SaaS, login, watch and takeover |
| Dense | 16 GB | 4-8 vCPU | Chrome headed | Several agents plus a human looking |
The work runs in the guest. The Mac or Windows app is a spectator: chat, live view, approvals, lifecycle.
Stoic OS is an immutable Linux userspace. Read-only /usr, agent supervisor as the session, browser and MCP as OS services.
No Hyprland rice, no GNOME, no Steam. Humans watch through the host app. Computer use is a kiosk, not a coworker desktop.
Default: one browser profile per agent. A shared profile is an opt-in inside a workspace, never the default across the account.

Agents in one workspace can read /workspace. That is the contract. If they should not share a login, they do not share a workspace, or they do not share a browser profile.
As observed in August 2026, Grok Bot puts every bot on one shared per-account pod (Cursor pod-daemon), not one VM per bot. 1AgentBox gives every workspace its own computer, and lets you pick the model runtime per agent. Isolation and multi-model assignment are the product.
Not unless you opt in. Default is one browser profile per agent. They share /workspace files and the MCP bus. Separate credentials means a separate workspace or a separate profile. The UI has to say this where the checkbox is, not only in a doc.
It is a sealed, versioned, agent-shaped Linux image, not a new kernel. Base is Ubuntu Server 24.04 LTS minimal, arm64. Calling it an OS is honest about the contract. It is a lie if it is Ubuntu plus a wiki.
No. The fast engine will lose some pages. Compat Chrome exists for those. Lite is fast-engine-only. Standard promotes to Chrome on demand.
Disk image, not RAM. Chrome dominates RAM. The creation sheet sells Lite 2 GB, Standard 8 GB, Dense 16 GB. The UI must show live guest memory, not only the SKU.
They are backends, not the product. Same Stoic OS image on a local VM or on a Linux box you already have, over SSH.