home / use cases / it and developers / sandboxed-scripting

File crunching in a sealed sandbox

Hand your Aivell a messy export and say what you need — merge, dedupe, convert, reformat. It writes a small script and runs it in a sandbox on the box with no network access at all, shows you a sample first, and returns a new file. Originals are never touched.

Watch the demo

starts when: You hand your Aivell a file and describe what you need

The problem

Between “we have the data” and “we can use the data” sits an afternoon of drudgery. Two exports that almost match. A customer list with three flavors of the same company name. Four hundred files in a format the new system refuses to read. Too irregular for a spreadsheet formula, too small to buy software for — so someone senior does it by hand, badly, quarterly.

The obvious shortcut — paste it into some online converter or a chatbot — means mailing your customer list to a stranger. The careful people know that, which is exactly why the careful people are still doing it by hand.

How your Aivell does it

  1. You hand over the file and the ask. Attach it in chat or email, or drop it in the exports folder: “merge these two, drop duplicates by VAT number, keep the newest address.”
  2. A script is written for the job. Not a rigid template — a small program for exactly this file and exactly this ask, written on the spot by your Aivell.
  3. It runs in a sealed room. The sandbox on the box has no network access at all — a guardrail, not a setting. The script sees the files it was handed and nothing else: no share, no internet, no way to leak even by accident.
  4. You see a sample before the full run. Ten rows, transformed, for your yes. Outputs are always new files — the original is untouchable by rule — and big jobs get a row-count check so nothing disappears in silence.
  5. The result comes back the way it came. A reply, a file in the processed folder — plus the kept script, so next month’s identical favor takes one sentence.

It’s the difference between “who can write me a quick script?” and having the colleague who always could — one who works in a room with no windows and no door to the outside.

The chore, as you'd write it.

No flowcharts, no code — a chore is just a message to your Aivell, in your own words. It shapes it into a solid, guarded procedure and follows it to the letter. This one:

Giulia Aivell · crunch files on request ● active

take the file and the ask — merge, convert, dedupe, reformat

copy it into the sandbox; the sandbox has no network, by design

write the script and run it on the first ten rows only

show that sample and wait for a go before the full run

never touch the original — every output is a new file

anything over a thousand rows gets a row-count check, before and after

return the result the way it came — reply, chat, or the processed folder

keep the script, so Franca's monthly ask runs without a rewrite

You
Got it — I'll start right away, and check with you whenever something needs a human.
Giulia Aivell

The tools it uses.

Connected with single-click passkeys — no copied tokens, no OAuth hell.

Chat widget takes the file and the ask
Sandbox runs the script, no network at all
Email receives jobs, returns results
Network folders picks up and drops off big files

Sensible guardrails.

Every tool can be limited to exactly what this chore needs. For this one, you might set:

Sandbox No network access, ever. Scripts see only the files handed in and can reach nothing else — not the share, not the internet.
Network folders Reads from the exports folder, writes to processed. The rest of the share does not exist as far as this chore is concerned.
Email Results go back to the requester only; attachments are never sent outside your domain.

Questions, answered.

Do I need to read or understand the scripts? +

No. You describe the outcome — "one sheet, no duplicates, dates the European way" — and judge the sample it shows you before the full run. The script is kept and reused, but reading it is optional, like checking a colleague's formulas.

Where does the data go while the script runs? +

Nowhere — twice over. The box already keeps everything inside your office, and the sandbox is a sealed room within it — no network, no access to the rest of the share, just the files handed in and the output it creates.

What if the script has a bug? +

Then a new, wrong file exists and nothing else happened. Originals are read-only by rule, the ten-row sample catches most nonsense before the full run, and the row-count check flags anything that silently vanished.

We do the same cleanup every month. Can it just remember? +

Yes — the script is kept with the chore, so "same as last month, new file" is the entire brief. If the routine settles down, it becomes a scheduled chore and stops needing you at all.

Related.

What is an Aivell?

An Aivell is an on-premise AI colleague: a small box that plugs into your network, runs its own AI onboard and takes the repetitive work off your desk. Prompts, documents, data — nothing ever leaves your office. Unplug the internet: it keeps working.

You describe each task as a chore, in plain language. Your Aivell turns it into a solid, guarded procedure and runs it in the background — with guardrails on every tool, a complete audit trail, and approvals in your hand when you want them. One-time setup, fixed monthly fee. No tokens, no overages.

Watch the demo

onboard inference · air-gapped · fixed monthly fee