AWS Open-Sources Dogwood, Extending Cedar to Govern Sequences of Agent Tool Calls

AWS has open-sourced Dogwood, a tool designed to extend the Cedar policy language to govern sequences of agent tool calls. By introducing temporal conditions, Dogwood allows developers to enforce constraints based on an agent's event history rather than just individual actions.
Why it matters
As AI agents become more autonomous, managing multi-step workflows and preventing unauthorized sequences of actions is critical for enterprise security and safety.
InfoQ Homepage News AWS Open-Sources Dogwood, Extending Cedar to Govern Sequences of Agent Tool Calls
AgentCore Policy launched at re:Invent last year. It sits outside the model as a deterministic control layer. The model proposes a tool call, the policy engine accepts or rejects it, and the model never touches enforcement. Cedar is the language those decisions are written in. AWS contributed it to the CNCF as a sandbox project in late 2025.
Cedar looks at one request at a time. Feed it the same request twice, and you get the same answer, regardless of what happened before or the order the policies ran in. Audit and automated reasoning both lean on that. The cost is that Cedar can fence off a single action and nothing more. A sequence of actions is outside what it can describe.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in