M4 · Identity and security
Defense in depth
30 / 61

Sandbox, policy and posture tools answer different security questions

GKE Sandbox isolates selected workloads with gVisor. Policy Controller enforces organization rules. The security posture dashboard surfaces configuration concerns and security bulletins.

GKE Sandbox

Adds a user-space kernel boundary for untrusted or multi-tenant code.

Policy Controller

Audits or denies resources that violate declared constraints.

Security posture

Finds risky workload configuration and surfaces actionable recommendations.

Security Command Center

Aggregates supported findings with broader cloud security context.

Detection, prevention and isolation complement each other; no single dashboard is the security boundary.