Amazon has expanded the capabilities within Policy for Agent Core, introducing a new ability to enforce restrictions that constrain agent actions across time. Previously, teams could implement controls applied across agents running in Amazon Bedrock AgentCore using Dogwood policies; however, this launch specifically addresses temporal constraints and trajectory requirements.
The Shift from Static Rules to Temporal Controls
The core change involves the introduction of capabilities for enforcing restrictions that constrain agent actions over time. This supports specific policy patterns such as rate limiting, prerequisites, sequential ordering of tool calls, and cumulative effects on system state.Previously available controls focused on static conditions or single-call arguments. The new feature set allows practitioners to define policies where a decision depends not just on the current input but also on what has already happened in the same session.
Natural Language Policy Authoring
The update expands Policy Authoring, an AI-driven tool designed to convert natural language policy specification documents into syntactically and semantically correct Dogwood formal specifications. This capability is particularly relevant for teams that maintain controls as written prose rather than code.
This authoring process functions primarily as a translator, not a summarizer or designer of new logic from scratch.
- Provide clean rule documents: Lists of policies, rules sections in operating procedures, or paragraphs defining permitted/restricted actions work best. Documents interleaving rationale and commentary should be pared down to the specific rules before processing.
- The tool generates a schema carrying exactly this information (tool names, arguments accepted, values returned) from the agent's Model Context Protocol (MCP) manifest.
- It also incorporates available Amazon Bedrock Guardrails checks for detecting inappropriate content in free-form text semantics and identity claims allowed by policy.
Architecture Implications
The policies are expressed in Dogwood, an open source governance language. These specifications are applied to agent actions in real time by the Dogwood monitor, which is built into the AgentCore Gateway.
This architecture implies that policy enforcement happens at the gateway layer before tool execution occurs. The system evaluates conditions against both the call being decided and historical session data (formerly within a specific timeframe). For example, an agent might be permitted to initiate a transfer only if identity verification occurred for that same account within the previous 15 minutes.
Security Considerations
The ability to invoke Amazon Bedrock Guardrails services adds another layer of defense. This allows policies to detect inappropriate content in the semantic meaning of free-form text, distinguishing this from simple keyword filtering or downstream service authorization boundaries.
Note: While these controls enhance safety and compliance alignment for agentic systems, they do not replace standard IAM/STS session tags or OAuth token exchange mechanisms. They function as application-layer governance constraints that complement existing identity management layers.
What This Means For Practitioners
If you operate agents in Amazon Bedrock AgentCore and rely on compliance teams to maintain controls, this feature reduces the friction of translating operational procedures into enforceable code. You can now import policy documents written directly by your team without needing a dedicated security engineer to manually write Dogwood formulas for every new constraint.
For platform engineering roles involving MCP tool manifests, ensure that the schema generated from these tools accurately reflects argument names and return values used in policies like context.input.amount. Misalignment here could cause policy evaluation errors when enforcing constraints on specific arguments.
Evaluate your current agent workflows for scenarios requiring sequential ordering or cumulative state checks. If you are currently managing rate limits via external circuit breakers, consider whether these native temporal controls can replace that complexity within the AgentCore Gateway context.


