
AWS open-sources Dogwood Local Engine to check AI agent tool calls
AWS has published the Dogwood Local Engine, an open source Rust library that checks AI agent tool calls against user-defined temporal policies and returns allow or deny verdicts before a tool is run.
AWS has published the Dogwood Local Engine (DLE), an open source library that it says can add a new layer of policy control over AI agents. The library is written in Rust and can be embedded into an agent's harness or gateway, where it issues allow or deny verdicts each time an agent tries to make a tool call.
DLE checks tool calls against policies written in Dogwood, the open source governance language AWS published in August and added to Amazon Bedrock AgentCore. The new release makes the policy engine directly embeddable into agent harnesses. DLE does not enforce anything itself: that part is left to the harness.
Temporal conditions, logged step by step
A key feature of both DLE and Dogwood is their awareness of temporal conditions. DLE tracks agent tool call events over time, stamping them into a log step by step, and each entry is persisted to disk as it is made, so the engine retains its state even if the whole system crashes or is restarted. The persistence step happens before DLE evaluates the applicable policy, after which it returns a verdict.
AWS gives the example of controlling a coding agent's Git pushes: a policy can allow a push only when the most recent test run passed, and only if that pass happened within the past 15 minutes. Otherwise, the push is denied. "To accurately handle verdict enforcement, the harness intercepts every tool call, submits a request event to the engine, and runs the tool only if the engine's verdict is allow," AWS explained.
Measured overhead and an unanswered question
In tests simulating sessions from five minutes to 12 hours, DLE evaluation time was around 20 microseconds with a 15-minute window at the 12-hour mark, rising to about six milliseconds with a 24-hour window. To prevent concurrent submission collisions, DLE relies on a lock that allows only one event submission at a time, and that lock persists until policy evaluation is complete. AWS did not make clear how it would handle a conflict between two concurrent submissions where one fulfills the pass conditions and one causes a failure; The Register asked about preventing incorrect enforcement in such situations but had not heard back prior to publication.
Why AWS published it
Recent revelations that AI agents regularly go off the rails, despite the guardrails their operators impose, make the durability of DLE worth discussing: AWS admits that such situations are part of its reason for publishing the new library. "Left unchecked … tool calls can have irreparable consequences," the announcement concludes. "As agents scale to settings where they work autonomously for longer intervals with more tools, we need safeguards that can regulate how those tools are used." The Register notes that AI agents finding holes in Dogwood and DLE is likely a matter of time; for now, both are available on GitHub.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.