# ctx.sandboxPolicy `SandboxPolicyService` — provided by `@deepseek-ai/dsh-sandbox-policy`. The sandbox-policy service (`ctx.sandboxPolicy`). Owns the deployment default mode and workspace root; enforcing implementations read defaultMode and workspaceRoot, and the tool layers fold each session's `sandbox/mode` override with effectiveSandboxMode on top. [Source](https://github.com/deepseek-harness/deepseek-harness/blob/master/packages/sandbox/sandbox-policy/src/index.ts#L60) ### ctx.sandboxPolicy.defaultMode ```ts website-api /** The deployment default mode — the fallback beneath a session override. */ readonly defaultMode: SandboxMode ``` The deployment default mode — the fallback beneath a session override. [Source](https://github.com/deepseek-harness/deepseek-harness/blob/master/packages/sandbox/sandbox-policy/src/index.ts#L70) ### ctx.sandboxPolicy.workspaceRoot ```ts website-api /** The absolute `workspace-write` boundary root both families fence against. */ readonly workspaceRoot: string ``` The absolute `workspace-write` boundary root both families fence against. [Source](https://github.com/deepseek-harness/deepseek-harness/blob/master/packages/sandbox/sandbox-policy/src/index.ts#L72)