← All speakers

Bio, Work & Ideas

Rowan Christmas

Conference affiliation: Staff Product Manager · Docker · 2026

On this page

Rowan Christmas’s work spans scientific software, native applications, enterprise consulting and analytics products. As a staff product manager at Docker in 2026, he presented Docker Sandboxes, which gives AI coding agents an isolated environment for executing code while controlling their access to a developer’s computer. His writing explores two related product questions: how to identify work worth building, and how to make software useful within the constraints of the platforms where it runs.

From biological networks to product discovery

Christmas worked on Cytoscape from 2002 to 2005, contributing to software for exploring biological networks. At the Institute for Systems Biology, he developed the Network Filter plugin, which let researchers select and remove relationships using their attributes—for example, excluding lower-confidence interactions before analyzing a network. He also co-authored research on integrating biological networks and gene-expression data.

His subsequent development work included OmniFocus between 2006 and 2010, followed by mobile and enterprise projects at Deloitte between 2010 and 2016. He later worked with web technologies at Mentor Creative Group and chose Vue for Rezza, his analytics-automation startup. These experiences underpin his comparison of native and web application development, including the practical differences in distribution, efficiency and support across operating systems.

Rezza sharpened his thinking about product discovery. Christmas concluded that its data-science service had lacked a sufficiently specific industry or use case. He subsequently applied those lessons at Qualtrics, Genomic Life and in consulting engagements with Mentor Creative Group. His approach to product research begins with deciding what deserves to be built before committing to implementation.

Testing demand and choosing a platform

  • Product research before implementation: Christmas combines broad idea generation with progressively more demanding tests. MaxDiff analysis tests customers’ relative preferences; interviews and design work explore what those preferences mean in practice; conjoint analysis examines what customers would pay for. His restaurant example explains why these distinctions matter: a dish ranked third may receive almost no orders when diners must actually choose between alternatives. A favorable feature ranking can conceal a weak product opportunity.
  • Better support for web applications: Christmas favors web technologies for many desktop applications because they simplify distribution, linking to particular application states and serving users across operating systems. His case for better operating-system support acknowledges native applications’ efficiency while challenging the overhead of running a separate browser engine for each Electron application. He argues that platform vendors should improve support for a development model already widely used.

Giving coding agents room to work safely

Christmas’s security concern includes what an agent can read, as well as what it can change. In his self-directed test of an unsandboxed coding agent, five prompts led it to sensitive information accessible on his laptop, including browser history and banking information. The example motivates his argument that harness-level guardrails are insufficient protection when the agent’s execution environment still permits access to the host.

Docker Sandboxes addresses that exposure through microVM isolation: an execution environment with its own kernel, filesystem isolation, controlled networking and secret placeholders. Christmas presented the product as a way to run agents such as Claude Code or Codex with enough autonomy to perform development work while limiting access to the surrounding computer.

The sandbox architecture explains how that separation works. An agent can install packages and use its own Docker daemon inside the VM. A host-side proxy checks network access and substitutes real API credentials for placeholders after requests leave the sandbox. The agent can therefore make authorized requests without receiving the credentials themselves.

Isolation still requires deliberate choices about shared resources. Under Docker’s security model, files explicitly mounted with write access remain available for the agent to modify. Christmas’s product focus is making these controls usable in everyday development, so developers can grant an agent useful freedom while choosing which resources it can reach.

Read the topics behind these talks

1 conference talk

Key ideas

Scroll to read ↓

Rowan Christmas shows how a coding agent reached sensitive information on his Mac, then repeats the browser-history search inside Docker Sandboxes. The difference comes from controlling what the agent can access, while preserving a familiar coding workflow.

  • A warning does not remove file access. In Christmas’s five-prompt experiment, changing the request’s framing let the agent continue investigating sensitive local information.
    1:23 ↗
  • MicroVM isolation changes what the agent can discover. The browser-history search succeeded on the host and found no browser inside the demonstrated sandbox.
    3:53 ↗
  • Secret placeholders, network policy and audit trails address different parts of agent execution: credential exposure, permitted connections and recorded activity.
    4:23 ↗
  • Read-only mounts let an agent understand related repositories while requiring its solution to work with their existing APIs.
    10:16 ↗

References