Amazon Web Services has released Dogwood Local Engine (DLE), an open source software library designed to give developers fine-grained policy control over the tool calls made by AI agents. The library, written in Rust, can be embedded into an agent's harness or gateway and issues allow or deny verdicts each time the agent attempts to invoke a tool.
DLE does not enforce the policies itself; that responsibility falls to the harness. Instead, it checks each tool call against rules written in Dogwood, an open source governance language AWS released in August. DLE's key innovation is its awareness of temporal conditions: it tracks tool call events over time, stamps them into a log that is persisted to disk after each entry, and evaluates the policy before returning a verdict. This persistence means DLE retains its state even if the system crashes or restarts.
AWS provided the example of controlling coding agent Git pushes. A policy could allow a push only when the most recent test run passed, and require that pass to have occurred within the past 15 minutes. If not, the push is denied.
Performance appears minimal: in tests simulating sessions from five minutes to 12 hours, DLE evaluation time was around 20 microseconds with a 15-minute window at the 12-hour mark, rising to about six milliseconds with a 24-hour window.
One open question is how DLE handles concurrent submissions. The library uses a lock that allows only one event submission at a time, but AWS did not clarify how the system would prevent incorrect enforcement if two submissions arrived simultaneously where one fulfilled conditions and the other did not. AWS did not respond to a request for comment before publication.
"Left unchecked, tool calls can have irreparable consequences," the DLE announcement concluded. "As agents scale to settings where they work autonomously for longer intervals with more tools, we need safeguards that can regulate how those tools are used." DLE and Dogwood are available on GitHub.