AWS Dogwood Local Engine: Rust-Based Policy Control for AI Agent Harnesses
Seed story: "AWS offers local, open source leash for agent harnesses" (The Register) · search original Written from facts verified across 3 report(s) — original explainer, not a copy or translation. Sources at the end.
As autonomous AI agents gain broader access to production systems, developers face the urgent challenge of securing these tools without sacrificing local control. AWS has addressed this by releasing the Dogwood Local Engine (DLE), an open-source Rust library that issues allow or deny verdicts for each tool call an agent attempts to make. By running locally and leveraging the Dogwood governance language, DLE enables developers to inspect and modify behavior rules directly, reportedly evaluating policies in as little as 20 microseconds for a 15-minute window.
Introducing Dogwood Local Engine
AWS has released Dogwood Local Engine (DLE), an open-source Rust library designed to embed policy control directly into AI agent harnesses. By operating locally rather than as a hosted cloud service, DLE allows developers to inspect and modify agent behavior rules without external dependencies. This approach gives engineering teams direct oversight over how autonomous agents interact with their environments.
The library works by issuing allow or deny verdicts for every tool call an agent attempts. It evaluates these actions against policies defined in Dogwood, an open-source governance language AWS published in August 2026. Key capabilities include:
- Tracking tool call events over time to maintain context.
- Persisting logs to disk to retain state across system crashes or restarts.
- Using a lock mechanism to prevent concurrent submission collisions during evaluation.
For developers, this means adding a deterministic safety layer to agent workflows. You can enforce strict operational boundaries locally, ensuring that agent actions align with your specific governance requirements before they execute.
Mechanics of Allow/Deny Verdicts
When an agent attempts a tool call, DLE intercepts the request to issue a binary allow or deny verdict. This evaluation checks the action against rules defined in the Dogwood governance language. Because agents often operate in high-concurrency environments, the library employs a strict locking mechanism. This ensures that only one event submission is processed at a time during policy evaluation, effectively preventing concurrent submission collisions that could corrupt state or bypass restrictions.
The engine maintains temporal awareness by tracking tool call events over time. This allows policies to enforce complex conditions, such as rate limits or sequential dependencies, rather than just static permissions. For developers, this means you can implement granular guardrails that adapt to the agent’s recent history.
- Intercepts tool calls for immediate policy checks
- Enforces a single-threaded submission lock
- Evaluates actions against Dogwood-defined rules
- Prevents race conditions in concurrent agent workflows
Performance and State Persistence
The 20-microsecond evaluation latency for a 15-minute policy window is a critical metric for high-throughput agent systems. This speed ensures that policy checks do not become a bottleneck in the agent's decision loop. For developers, this means the harness can enforce complex governance rules without introducing perceptible delays in tool execution.
State persistence is handled through a disk-based logging strategy. DLE tracks tool call events over time, writing logs to disk to retain state across system crashes or restarts. This approach guarantees that policy context survives unexpected interruptions, preventing agents from bypassing controls after a reboot.
- Low Latency: ~20 microseconds for short policy windows.
- Crash Resilience: Disk logs preserve state across restarts.
- Concurrency Control: Lock mechanism prevents submission collisions.
This combination allows teams to ship agents with robust, auditable guardrails that remain consistent even under failure conditions.
Local Execution vs. Cloud Services
Running policy checks locally eliminates the network latency inherent in hosted cloud services. For developers, this means DLE can intercept tool calls with minimal overhead, keeping the agent’s execution loop tight. Instead of waiting for a remote API response, the Rust library evaluates rules directly on the host machine, ensuring that safety constraints do not become a bottleneck in high-frequency agent workflows.
This architectural choice also grants teams direct control over their governance logic. By keeping the engine local, you can:
- Inspect and modify agent behavior rules without exposing sensitive data to external endpoints.
- Iterate on Dogwood policies in real-time during development.
- Maintain full visibility into the decision-making process for compliance auditing.
Ultimately, local execution transforms policy control from a distant gatekeeper into an integrated component of your application’s runtime.
Integration with Amazon Bedrock AgentCore
AWS has aligned Dogwood Local Engine with the existing governance capabilities of Amazon Bedrock AgentCore to create a unified security stack. When AWS initially open-sourced the Dogwood governance language in August 2026, it simultaneously added support for this language to AgentCore. This integration ensures that developers can define consistent policy rules across both cloud-hosted and local environments.
- Unified Language: Both DLE and AgentCore utilize the same Dogwood syntax for policy definitions.
- Consistent Enforcement: Developers can apply identical allow/deny logic whether agents run locally or in the cloud.
- Simplified Management: A single governance framework reduces the complexity of maintaining separate security rulesets.
For developers, this alignment means that security policies written for cloud-native agents can be directly ported to local harnesses without translation. It streamlines the workflow for teams building hybrid AI systems, ensuring that the "leash" applied to an agent remains consistent regardless of where the inference or tool execution occurs.
Implementing DLE in Your Stack
Integrating Dogwood Local Engine into your stack requires embedding the Rust library directly within your agent harness. Since DLE operates locally, you can inspect and modify behavior rules without relying on external cloud services. This direct access simplifies debugging and allows for rapid iteration on governance logic.
To monitor agent activity, DLE tracks tool call events over time, persisting logs to disk. This ensures state retention across system crashes or restarts, providing a reliable audit trail. When implementing the library, note that it uses a lock mechanism to prevent concurrent submission collisions, allowing only one event submission at a time during policy evaluation.
Key integration considerations include:
- Defining policies using the Dogwood governance language.
- Handling the single-threaded submission constraint to avoid blocking.
- Leveraging local execution for immediate feedback on allow or deny verdicts.
FAQ
What is AWS Dogwood Local Engine and what is it used for?
AWS Dogwood Local Engine (DLE) is an open-source Rust library designed to add policy control to AI agent harnesses. It issues allow or deny verdicts for each tool call an agent attempts to make by checking them against policies defined in the Dogwood governance language.
How fast is the AWS Dogwood Local Engine at evaluating policies?
The engine has an evaluation time of approximately 20 microseconds for a 15-minute policy window. For a 24-hour policy window, the evaluation time is about six milliseconds.
Does AWS Dogwood Local Engine run as a cloud service or locally?
The tool is designed to run locally rather than as a hosted cloud service. This allows developers to directly inspect and modify agent behavior rules while the engine persists logs to disk to retain state across system crashes or restarts.
Sources
Put an AI coding agent to work in your own workspace
MeshCode is an AI coding agent workspace — delegate the tedious parts of shipping software and stay in control. Free to start.
Try MeshCode →