Basically, sandbox was meant to replace HIPS because it should give you higher protection with fewer alerts.
In my opinion it's better to keep both sandbox and HIPS enable (which is what happens if you enable the Proactive Security configuration).
The problem with sandbox is that it's not working as expected with Windows 10. You can check the details here:
https://forums.comodo.com/bug-reports-cis/spyshelter-test-t115145.0.html;msg837475#msg837475Because of this problem, I have delete the sandbox rules to "run virtually" unknown apps and I have added a rule to block unknow apps instead.
If the sandbox blocks an app, I can check "don't sandbox it again", then re-launch the app. Like this the HIPS will tell me what the app is trying to do.
If I'm not sure about the app, I can always use the sandbox (meaning run virtually) as on-demand feature only.