brig docs

Compare

Brig and Strands Box

On this page

Brig gives a coding agent a microVM with a kernel of its own, your project and nothing else, a network rule you write, and its login from your keychain. Strands Box runs the agent as a process on your Mac under Seatbelt, and a policy engine decides each command, file and request the agent sends through its shell and gateway.

Strands Box is AWS's sandbox for agents, in developer preview since October 2026. Both tools wrap Claude Code and other agents from the outside. Strands Box also decides each action inside the sandbox with a policy. Brig compared puts both beside the other tools.

At a glance #

Brig Strands Box
Made for Coding agents Any agent program. Examples for Claude Code, Codex CLI, pi and the Strands CLI
Runs on macOS 15 or newer on Apple silicon, and Linux with KVM macOS 15 or newer on Apple silicon. Linux is planned
Kernel One kernel per sandbox, under a hypervisor The host kernel, with a Seatbelt profile in front of it
Host files The project and the guest home, and nothing else from the host Deny by default. The paths you grant in box.toml, and the files a policy lets its shell open
Network An egress policy of hosts and ranges, enforced at a gateway or in nftables outside the guest. offline has no route out HTTP and HTTPS through a gateway on the host that terminates TLS. Rules by host, port, method and path
Credentials A secret store in the keychain, delivered by name as a file. The agent holds the value. v0.5.0 adds secret brokerage, and the guest then holds a placeholder A placeholder the gateway swaps for a value from an environment variable, or a SigV4 signature from an AWS profile. The agent never holds the value
Action rules None. The agent's own permission mode governs each action A permit or forbid rule per command, file operation, request and MCP call. A rule can read past events
Agent setup Eight built-in profiles You write box.toml and policy.dw. The repository has examples
Start Boots a kernel Starts a process
Needs Homebrew on macOS. KVM and the runtime bundle on Linux A download script, or a Rust build. Node.js for the Strands CLI example
Status Open source, in active development Developer preview, release 0.1.0
Licence Apache-2.0, three repositories Apache-2.0

What Brig gives you #

A kernel the host does not share. Under Brig, the agent's system calls go to a kernel inside the microVM. hvi, the VMM Brig uses on macOS, treats the guest as hostile and runs inside a Seatbelt profile of its own. The boundary in hvi describes it. Under Strands Box, the agent's system calls go to your kernel, and Seatbelt filters them. Its documentation says that "an exploit that defeats the kernel defeats the box".

The agent's shell runs inside the boundary. Under Brig, every command the agent runs, and every file it opens, happens in the guest. Under Strands Box, the agent's shell commands run in Strands Shell, and its Python in Monty. Both run in a trusted process outside every sandbox, with the gateway and the policy engine. Its documentation says "no sandbox contains their defects". It also says that a broad filesystem permit lets the interpreters reach paths that the agent's own grants never can, including credential stores.

Every protocol, outside the guest. Brig enforces its policy at the gateway on macOS and in nftables on Linux, below the protocol, for every packet the guest sends. A run on a backend that cannot enforce it is refused with exit code 7. See Enforcement. Strands Box sets the proxy variables, and Seatbelt lets the agent reach the gateway's local port and nothing else on the network. A tool or local MCP server marked contain_egress = false connects directly, and the gateway never sees that traffic.

Your project, with the agent's own tools. The guest has the project at /work/<name> and its guest home, and the agent's file tools work there. See Project mounts. Strands Box grants the agent's process the paths you list. In its Claude Code example, the project is not among them. Claude Code's Read, Write and Edit tools fail with EPERM, and the agent falls back to its Bash tool. There, the box's shell asks the policy about each file.

Linux hosts. Brig runs on Linux with KVM, on x86-64 and arm64. Strands Box runs on macOS, with Linux planned.

One command per agent. brig run claude ~/code/demo opens Claude Code in its sandbox, with its login from the secret store. Strands Box needs a box.toml with the agent's install paths, state directories and environment, and a policy.dw with its rules. The repository has examples for Claude Code, Codex CLI, pi and the Strands CLI.

A test for each claim. Claims names the test behind every sentence of the security model, and a check runs on every pull request. hvi is in process for an external security audit, with no formal third-party review published at this time. Strands Box lists the protections it does not provide, among them resource limits and a tamper-proof audit trail. It says its action vocabulary can change before 1.0.0.

What Strands Box does #

Box reads box.toml, builds a Seatbelt profile from the paths and programs it names, and starts the agent under it through a small launcher. The profile denies by default. The agent's process reads, writes and lists only the paths you grant, plus the system paths the program needs to run. Programs the agent starts inherit the restrictions. If the profile cannot be applied, the agent does not start.

The agent's shell commands do not run in your macOS shell. They go to Strands Shell, Box's own shell interpreter, which implements common commands itself. Python goes to Monty, Pydantic's Python interpreter written in Rust. A program on your Mac, such as git, needs a [tool.<name>] table and runs in a sandbox of its own.

Each command, and each file a command opens, is a request to the Dogwood policy engine. Dogwood takes Cedar-style permit and forbid rules, denies by default, and lets a forbid beat any permit. A rule can read past events. The launch post's example lets an agent post to Slack no more than three times in ten minutes. A denied request returns the rule's @id and description to the agent, and every decision goes to a log in OTLP JSON.

Network traffic leaves through an egress gateway on the host. Each run creates its own certificate authority, and the gateway terminates TLS, so a policy can match the host, port, method and path of each request. The gateway resolves hostnames itself and verifies the upstream certificate against public roots.

Credentials never enter the sandbox. An [egress.<name>] table binds a destination to a secret from an environment variable of the shell that runs the box, or to an AWS profile. The agent gets a placeholder, and the gateway swaps in the value, or signs the request with SigV4, after the policy permits it. Copies of the secret in a response are redacted. Every process in a box can use every route, because the gateway identifies destinations, not callers.

When Strands Box fits #

  • A rule per action. Box decides each command, each file operation, each request and each MCP call, and a rule can depend on what happened before. Under Brig, the agent's own permission mode governs each action inside the sandbox.
  • The agent never holds the key, today. Box swaps a placeholder at the gateway. Brig hands the agent its credential as a file on a memory-backed mount until v0.5.0 adds secret brokerage. Credentials states that limit.
  • Finer network rules. Box matches method and path, after it terminates TLS. Brig filters a connection by hostname and range.
  • Start time. Box starts a process. Brig boots a kernel.
  • MCP servers under policy. A broker checks each MCP call and its arguments, and starts each local server in a sandbox of its own.
  • Your macOS programs, each in a sandbox. A tool table lets the agent run a program on your Mac, such as git or a compiler, in a sandbox of its own. Under Brig, the agent runs in a Linux guest image.

Run Claude Code under each #

Under Brig:

brig run claude ~/code/demo

Under Strands Box, with the example from its repository. Write your home directory into its box.toml and export a Bedrock key first:

./box-core/box run --config claude-code/box.toml -- -p "Summarize README.md in one sentence."

The example runs Claude Code with --dangerously-skip-permissions, against Claude on Amazon Bedrock with a key from AWS_BEARER_TOKEN_BEDROCK. The policy decides each command in place of the prompts. Under Brig, the login comes from the secret store, and the agent's permission mode is its own setting.

Sources #

Read on 2026-10-07.

Type a command, a flag or an error message.