isolated: true on a task step or requireIsolation: true on a plan path that routes into the sandbox adapter.
Behavior
harness/swarm/sandbox.ts uses the Daytona integration in runtime/src/mesh/sandbox.ts.
Explicit isolation never silently downgrades to in-process execution.