Why not? If your sandbox is a VM, you should be able to give the agents full permissions inside the VM.
It’s because you sandbox in a VM doesn’t mean you give it admin access to the VM
Maybe doesn't mean that when _you_ do it, but do you work in this team at OpenAI?