At Figma, AI agents generate code, call tools, and continue working over long-lived connections. We built Nimbus to provision isolated execution environments for them, but learned that the production trust boundary extends beyond the sandbox. Every request crosses an edge layer, an agent control plane, and an execution environment, with each layer owning part of the security and lifecycle contract.
The talk also covers the control-plane systems that make agents responsive and reliable. Nimbus manages sandbox state across providers, maintains warm capacity, detects unhealthy environments, and replaces them when necessary. Warm pools reduced provisioning latency by 90%, while health checks and recovery mechanisms helped improve availability from 99% to 99.95%.
Finally, we’ll examine where the state belongs once an agent is running. Connection state, conversation history, sandbox lifecycle, and harness sessions have different owners and durability guarantees. Making those boundaries explicit enables safe reconnection and recovery—and clarifies why replaying an arbitrary tool side effect is a fundamentally different problem.
Speaker
Pratik Agarwal
Distributed Systems Engineer @Figma (Sandbox & Caching Platforms), Previously @Momento & @AWS DynamoDB, USENIX SREcon '26 Speaker & QCon SF Track Host
Pratik Agarwal is a founding engineer on Figma’s Sandbox Platform within the Agent Infrastructure team, where he builds safe, reliable compute infrastructure for AI-powered product experiences. Earlier at Figma, he worked on database and caching infrastructure. Before joining Figma, he built caching and control-plane infrastructure at Momento and worked on DynamoDB’s control plane and event-driven systems for AWS Marketplace at AWS. He holds an M.S. in Information Science from Penn State, where his graduate research focused on HCI and social computing. His work sits at the intersection of distributed systems, reliability, and ergonomics, and he writes about infrastructure, performance, and developer experience.