Live
From App‑Level LLMs to a Shared Platform: Redesigning the Stack to Tame HallucinationsFrom Ad‑hoc Checks to a Production‑Ready Agent Evaluation FrameworkReal‑Time Observability for Claude Code Sessions with the Statuspane ModEnforcing US Data Residency with Cloudflare D1AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersFrom App‑Level LLMs to a Shared Platform: Redesigning the Stack to Tame HallucinationsFrom Ad‑hoc Checks to a Production‑Ready Agent Evaluation FrameworkReal‑Time Observability for Claude Code Sessions with the Statuspane ModEnforcing US Data Residency with Cloudflare D1AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturers
AWS

Amazon Bedrock AgentCore Adds Temporal Policy Enforcement via Dogwood

AI SummaryPowered by AI

Policy in Amazon Bedrock AgentCore now supports enforcing restrictions that constrain agent actions across time, including rate limiting and sequential ordering of tool calls. This update allows engineers to translate natural language compliance rules into formal specifications without manual coding.

Amazon has expanded the capabilities within Policy for Agent Core, introducing a new ability to enforce restrictions that constrain agent actions across time. Previously, teams could implement controls applied across agents running in Amazon Bedrock AgentCore using Dogwood policies; however, this launch specifically addresses temporal constraints and trajectory requirements.

The Shift from Static Rules to Temporal Controls

The core change involves the introduction of capabilities for enforcing restrictions that constrain agent actions over time. This supports specific policy patterns such as rate limiting, prerequisites, sequential ordering of tool calls, and cumulative effects on system state.

Previously available controls focused on static conditions or single-call arguments. The new feature set allows practitioners to define policies where a decision depends not just on the current input but also on what has already happened in the same session.

Natural Language Policy Authoring


The update expands Policy Authoring, an AI-driven tool designed to convert natural language policy specification documents into syntactically and semantically correct Dogwood formal specifications. This capability is particularly relevant for teams that maintain controls as written prose rather than code.

This authoring process functions primarily as a translator, not a summarizer or designer of new logic from scratch.

  • Provide clean rule documents: Lists of policies, rules sections in operating procedures, or paragraphs defining permitted/restricted actions work best. Documents interleaving rationale and commentary should be pared down to the specific rules before processing.
  • The tool generates a schema carrying exactly this information (tool names, arguments accepted, values returned) from the agent's Model Context Protocol (MCP) manifest.
  • It also incorporates available Amazon Bedrock Guardrails checks for detecting inappropriate content in free-form text semantics and identity claims allowed by policy.

Architecture Implications

The policies are expressed in Dogwood, an open source governance language. These specifications are applied to agent actions in real time by the Dogwood monitor, which is built into the AgentCore Gateway.

This architecture implies that policy enforcement happens at the gateway layer before tool execution occurs. The system evaluates conditions against both the call being decided and historical session data (formerly within a specific timeframe). For example, an agent might be permitted to initiate a transfer only if identity verification occurred for that same account within the previous 15 minutes.

Security Considerations


The ability to invoke Amazon Bedrock Guardrails services adds another layer of defense. This allows policies to detect inappropriate content in the semantic meaning of free-form text, distinguishing this from simple keyword filtering or downstream service authorization boundaries.
Note: While these controls enhance safety and compliance alignment for agentic systems, they do not replace standard IAM/STS session tags or OAuth token exchange mechanisms. They function as application-layer governance constraints that complement existing identity management layers.

What This Means For Practitioners


If you operate agents in Amazon Bedrock AgentCore and rely on compliance teams to maintain controls, this feature reduces the friction of translating operational procedures into enforceable code. You can now import policy documents written directly by your team without needing a dedicated security engineer to manually write Dogwood formulas for every new constraint.

For platform engineering roles involving MCP tool manifests, ensure that the schema generated from these tools accurately reflects argument names and return values used in policies like context.input.amount. Misalignment here could cause policy evaluation errors when enforcing constraints on specific arguments.

Evaluate your current agent workflows for scenarios requiring sequential ordering or cumulative state checks. If you are currently managing rate limits via external circuit breakers, consider whether these native temporal controls can replace that complexity within the AgentCore Gateway context.

Originally published atAWS Machine Learning Blog