Aether does not build a second sandbox inside it. These stances are documented so they are not re-raised as findings.
The mount policy and the credentials mounted in. That is the whole boundary, and everything else follows from it.
If you run agents you do not trust, put the data directory on a filesystem mounted nosuid,nodev.
aether gui serves the dashboard locally and proxies the API over your own SSH connection to the server. SSH stays the only network surface the server exposes.
The identity is your own SSH key, held by the same process that serves the page.
Each container gets a unix socket it can message other overlapping runs through. Whoever connects on a run's socket is that run, so no token enters a container.
Runs in one workspace already share a repository, so influencing each other through file contents needs no authorization at all.
Server setup, agents, runs, the dashboard, and the branch that comes back.