AWS releases Strands Box preview for policy-controlled AI agents
The open-source developer preview pairs operating-system isolation with Dogwood rules for agent actions, but initial local support is limited to Apple-silicon Macs.
Containment plus action policies
AWS introduced Strands Box in developer preview on October 7 as an Apache 2.0-licensed sandbox for AI agents. It combines operating-system isolation with policies written in Dogwood, allowing decisions to depend on an action and on events the agent performed earlier. AWS says the system can govern outbound network requests, shell and Python operations, and configured MCP tool calls. A gateway can attach approved credentials to permitted requests without exposing the underlying secret to the agent process.
Preview limits matter
The project’s README says local execution currently supports macOS on Apple silicon; support for other operating systems is planned. AWS also notes that files granted directly through the box configuration are constrained by operating-system containment but do not enter Dogwood’s policy history. That means the policy layer does not observe every possible file access. AWS’s examples show how the controls are intended to work, not an independent security evaluation of the preview. Developers considering it for sensitive workloads should inspect the documented enforcement boundaries and test their own agent tools against them.