AWS Launches Strands Box for Policy-Governed Agent Sandboxing
The open-source developer preview combines operating-system containment with rules that can govern files, networks, interpreters and MCP tools over time.
Edited by Tyronne Panaino
AWS launched Strands Box in developer preview on October 7, 2026, giving agent developers an open-source sandbox that combines operating-system containment with fine-grained rules for actions. The Apache 2.0-licensed project is aimed at coding assistants and other agents that need to read files, run commands, execute Python or call remote tools without receiving unrestricted access to a developer's machine or credentials.
The practical change is that the boundary is not limited to whether an agent can reach a resource. Strands Box also applies Dogwood policies to what the agent may do, including rules that depend on earlier actions. That makes the release relevant to developers evaluating local agent execution, security teams defining tool permissions and platform teams trying to keep policy consistent across different agent harnesses.
Containment and policy are separate layers
The AWS announcement describes two layers. Operating-system isolation defines the files, hosts and local resources that an agent can reach. Within that boundary, Dogwood evaluates requested actions and returns allow-or-deny decisions.
AWS says the initial enforcement points cover outbound network traffic, a shell interpreter, a Python interpreter and a broker for Model Context Protocol servers. Those points can distinguish operations such as reading or changing a file, running a command, calling a particular HTTP method and path, or invoking an MCP tool. They also share a history, allowing a later action to be judged in light of something the agent did earlier.
That temporal element is the most important delta from a static allow list. A policy can limit how often an agent posts to an external service, impose a cooldown, or block outbound traffic after sensitive data has been read. The agent does not have to remember the rule itself because the decision is enforced outside its process.
Credentials can stay outside the agent environment
Strands Box routes outbound requests through an egress gateway. For configured destinations, the gateway can replace a placeholder with a real credential only after policy permits the request. AWS says the actual secret does not enter the agent's environment. The announced methods include bearer tokens, custom headers, HTTP Basic authentication, query parameters and AWS request signing.
This design can reduce the need to expose long-lived secrets directly to an agent or the code it generates. It does not remove the need to configure destinations, permissions and credential sources correctly. A policy file that is too broad, an over-privileged upstream identity or a missed enforcement path could still create risk. The announcement establishes the intended architecture, not independent proof that every route is contained.
The developer preview has material limits
AWS explicitly calls Strands Box a developer preview and says it is starting on macOS. Broader operating-system support, simpler configuration and deployment to services such as container or Kubernetes platforms are described as future priorities rather than current capabilities. Teams should therefore evaluate it as an early local-development control, not as a finished cross-platform production security layer.
The implementation also makes a deliberate trade-off: its shell and Python interpreters run outside the sandbox because they enforce policy. AWS notes that this widens the trusted computing base. Policy can observe operations that pass through its enforcement points, while paths granted directly to a harness may be bounded by containment without appearing in the policy history. That gap matters for auditing and for claims that one ruleset sees every meaningful action.
What to verify next
The next useful evidence would be independent escape testing, documented threat models, platform-specific containment guarantees and results from agents other than AWS's example harness. Buyers and open-source adopters should also watch whether policy coverage expands to more actions and whether the same configuration behaves consistently when Strands Box moves beyond macOS.
Status
Confirmed. AWS has released the open-source developer preview and documented its architecture. Internal confidence is medium because one vendor source supports the feature and no independent security assessment, compatibility test or production deployment evidence was fetched.
Sources
Update note: Last reviewed 2026-10-08. We will revise this post if AWS publishes broader platform support, a formal threat model, independent security testing or production availability details.
Sources
Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.