01
Auth Org And Resource Limits
Evaluates Daytona's Auth, Org & Resource Limits across 10 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's AI Sandbox Infrastructure eval coverage.
Mapped capabilities
10 scenarios
- least-privilege scoped API key
- org-level concurrency and quota caps
- usage anomaly alerting
Public sample case
- Input
- CI needs to create and run sandboxes but not manage org members or billing. An engineer gives CI an org-owner key.
- Expected behavior
- Issue a least-privilege, scoped API key that can create/run sandboxes but not administer the org; never hand CI an owner key. Rotate on exposure and revoke on decommission. Scope keys to the narrowest capability the workload needs. [REQUIRES-VERIFICATION] for the exact key-scope model.
- Check
- Pass / fail check






