ToolingPublished All news from that day
Ongoing case: Sandboxes for coding agents 5 storiesAWS launches open source Strands Box sandbox with action-level policy for agents
AWS says Strands Box, in developer preview under Apache 2.0, starts on macOS and can limit things like how often an agent posts to Slack.
Check our sources · 8 facts from 1 sourceAWS launched Strands Box in developer preview on 7 October 2026, an open source sandbox licensed under Apache 2.0. It combines operating-system isolation with fine-grained policies, written in the Dogwood policy language, that govern what an agent does. AWS says containment uses OS-level isolation such as macOS Seatbelt and that it is starting with macOS.
Policy is applied at four points: network egress, a Python interpreter, a shell interpreter and a broker for Model Context Protocol servers. AWS says rules can depend on what the agent has already done, and gives the example of letting an agent post to an incident channel in Slack no more than three times every 10 minutes.
For API-key routes the agent receives a placeholder and the egress gateway swaps in the real secret, so the secret does not enter the agent's environment.
AWS says the same configuration and policy files can be used across agent applications, because Box enforces from outside the agent's own process. It describes the Strands harness as the one used in its example and says Box itself is harness agnostic.
Your reaction
We count reactions per story and day, never who reacted. The counts help us choose what goes in the monthly issue. If you are signed in, your own page shows yours too.
Check our sources
Every sentence above is checked against this source.
1 Introducing Strands Box: AI agent sandboxes powered by Dogwood
Open the source archived copy-
The AWS Open Source Blog post introducing Strands Box was published on 7 October 2026 (page metadata datePublished 2026-10-07). Quote: "Introducing Strands Box: AI agent sandboxes powered by Dogwood"
citeIntroducing Strands Box: AI agent sandboxes powered by Dogwood by Fernando Dingler on 07 OCT 2026 in Announcements
-
AWS says it is launching Strands Box in developer preview, an open source sandbox licensed under Apache 2.0 that combines operating-system isolation with fine-grained policies for governing agent actions. Quote: "in developer preview, an open source sandbox licensed under Apache 2.0 that combines operating-system isolation with fine-grained policies for governing agent actions"
citeToday, we’re launching Strands Box in developer preview, an open source sandbox licensed under Apache 2.0 that combines operating-system isolation with fine-grained policies for governing agent actions.
-
AWS says containment uses OS-level isolation such as macOS Seatbelt. Quote: "Containment uses OS-level isolation, such as macOS Seatbelt, to define what the agent can reach"
citeContainment uses OS-level isolation, such as macOS Seatbelt, to define what the agent can reach, on the host machine and on the network.
-
AWS says it is starting with macOS and expanding to other operating systems is one of its next priorities. Quote: "We’re starting with macOS, and expanding support to other operating systems is one of our next priorities."
citeWe’re starting with macOS, and expanding support to other operating systems is one of our next priorities.
-
AWS says policy is applied at network egress, a Python interpreter, a Shell interpreter and a broker for Model Context Protocol (MCP) servers. Quote: "Policy is applied at multiple enforcement points: network egress, a Python interpreter, a Shell interpreter and a broker for"
citePolicy is applied at multiple enforcement points: network egress, a Python interpreter, a Shell interpreter and a broker for Model Context Protocol (MCP) servers.
-
AWS gives an example of a policy that lets an agent post to Slack no more than three times every 10 minutes. Quote: "A policy can let the agent post, but no more than three times every 10 minutes."
citeWe want it to post progress updates to the incident channel in Slack as it finds things, but not to flood the channel and bury the updates from humans. A policy can let the agent post, but no more than three times every 10 minutes.
-
AWS says that for configured API-key routes the agent receives a placeholder token which the gateway replaces with the real secret, and the real secret never enters the agent's environment. Quote: "The real secret never enters the agent’s environment; the gateway attaches it on the way out."
citeFor configured API-key routes, the agent receives a placeholder token, which the gateway replaces with the real secret before forwarding a permitted request. The real secret never enters the agent’s environment; the gateway attaches it on the way out.
-
AWS says Box enforces from outside the process and the same box.toml and policy.dw can be used across agent applications; it says Box itself is harness agnostic. Quote: "though Box itself is harness agnostic"
citeBox enforces from outside the process, at the OS and network boundary, and the same box.toml and policy.dw can be used for consistent configuration and policy enforcement across agent applications.
Topics
The morning email
On the mornings we publish: the three top stories and up to four short ones. Free.
We email you a link to confirm. An issue may include one sponsor, always labelled Sponsored · Advertisement. Our emails count opens and clicks, not who made them. Unsubscribe in one click. What we keep
