AWS open sources Dogwood Local Engine to leash AI agent tool calls

Rust-based policy engine checks tool actions against temporal rules before allowing execution

By LineZotpaper
Published
Read Time2 min
AWS has published Dogwood Local Engine (DLE), an open source Rust library that allows AI agent harnesses to block or allow tool calls based on user-defined temporal policies, adding a layer of control to prevent autonomous agents from taking unintended actions.

Amazon Web Services has released Dogwood Local Engine (DLE), an open source software library designed to give developers fine-grained policy control over the tool calls made by AI agents. The library, written in Rust, can be embedded into an agent's harness or gateway and issues allow or deny verdicts each time the agent attempts to invoke a tool.

DLE does not enforce the policies itself; that responsibility falls to the harness. Instead, it checks each tool call against rules written in Dogwood, an open source governance language AWS released in August. DLE's key innovation is its awareness of temporal conditions: it tracks tool call events over time, stamps them into a log that is persisted to disk after each entry, and evaluates the policy before returning a verdict. This persistence means DLE retains its state even if the system crashes or restarts.

AWS provided the example of controlling coding agent Git pushes. A policy could allow a push only when the most recent test run passed, and require that pass to have occurred within the past 15 minutes. If not, the push is denied.

Performance appears minimal: in tests simulating sessions from five minutes to 12 hours, DLE evaluation time was around 20 microseconds with a 15-minute window at the 12-hour mark, rising to about six milliseconds with a 24-hour window.

One open question is how DLE handles concurrent submissions. The library uses a lock that allows only one event submission at a time, but AWS did not clarify how the system would prevent incorrect enforcement if two submissions arrived simultaneously where one fulfilled conditions and the other did not. AWS did not respond to a request for comment before publication.

"Left unchecked, tool calls can have irreparable consequences," the DLE announcement concluded. "As agents scale to settings where they work autonomously for longer intervals with more tools, we need safeguards that can regulate how those tools are used." DLE and Dogwood are available on GitHub.

§

Analysis

Why This Matters

  • AI agents are increasingly deployed to perform autonomous actions such as editing files, transferring data, or running commands, creating risk if they operate outside intended boundaries.
  • DLE gives developers a way to embed policy checks directly into agent workflows without relying solely on model-level guardrails, potentially reducing harmful or unintended tool calls.
  • The open source nature of Dogwood and DLE means the approach can be adopted, audited, and extended beyond AWS's ecosystem, influencing how agent safety is implemented industry-wide.

Background

AI agents that can call external tools have grown rapidly in capability and deployment, but reports of agents taking unexpected actions have raised safety concerns. Companies have experimented with various approaches to limit agent behavior, including prompt-based restrictions, separate oversight models, and policy engines. AWS's Dogwood language, introduced in August 2026, provides a declarative way to define governance rules, and DLE makes those rules enforceable at the harness level.

Key Perspectives

AWS: Positions DLE as a necessary safeguard for scaling autonomous agents, offering a lightweight, embeddable solution that persists state across crashes and enforces temporal conditions without adding significant latency.

Developers and platform teams: Gain a standardised, open source tool to restrict agent tool use declaratively, but must integrate DLE into their own harness logic and define appropriate policies themselves.

Critics and security researchers: May question the effectiveness of any local policy engine against determined adversaries or agents capable of exploiting gaps in rule definitions. The concurrent submission handling question suggests edge cases that could lead to incorrect enforcement.

What to Watch

  • Community feedback and adoption on the Dogwood/DLE GitHub repositories, including reported bugs or bypasses.
  • Whether AWS adds official support for DLE in Amazon Bedrock or other managed services.
  • Emergence of alternative policy engines or competing approaches from other cloud providers as agent safety becomes a central issue.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.