Home icon

Introducing Strands Box: AI agent sandboxes powered by Dogwood

Open Source Blog



This article introduces Strands Box, an open source sandbox that combines operating-system isolation with fine-grained policies to safely govern AI agent actions.

  • Combines OS-level containment with Dogwood policy language for contextual access control
  • Enforces policies at multiple points: network egress, Python interpreter, Shell interpreter, and MCP servers
  • Supports temporal policies that depend on agent history, such as rate-limiting Slack posts to three per 10 minutes
  • Embeds Strands Shell and Monty Python interpreters to intercept and authorize operations like file access and network calls
  • Manages credentials securely by replacing placeholders with real secrets at the gateway, keeping them out of agent environment
  • Configured via box.toml for environment setup and policy.dw for Dogwood authorization rules
  • Roadmap includes expanding OS support beyond macOS, easier setup with CLI generation, and deployment to platforms like Amazon Bedrock

Strands Box enables developers to safely delegate work to AI agents by enforcing both isolation boundaries and contextual policy rules across all agent actions.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

May 16
2025
Introducing Strands Agents, an Open Source AI Agents SDK
Aug 6
2026
Introducing Dogwood: runtime verification for AI agents
Sep 30
2026
Introducing the Dogwood Local Engine: temporal governance for agent actions
Sep 22
2026
Evaluate skill-equipped agents with Strands Evals and Amazon Bedrock AgentCore

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.