AWS releases Dogwood, an open-source policy language for the tool-call sequences agents run
AWS has released Dogwood, an open-source policy language and reference interpreter aimed at the space between an agent's individual tool calls, per a report in The New Stack. The operational read: if you have started letting agents open pull requests and push infrastructure changes on their own, the guardrail you have been reaching for is on the sequence of tool calls, not on any single call. The…
AWS has unveiled Dogwood, an open-source policy language and reference interpreter designed to govern the sequence of tool calls agents perform, according to The New Stack. This release addresses the gap left by existing policy-as-code frameworks, which typically focus on individual tool calls rather than the overall sequence. The New Stack highlighted the August 6 launch as a solution for failures where each individual call an agent makes is technically valid, but the order or combination of them is incorrect.
Examples include rotating a credential and pushing a build with an outdated version, approving a merge and running a release script from a stale branch. Dogwood consists of two components: a policy language and a reference interpreter, both of which are open source. The policy language allows users to define rules for valid sequences of tool calls, while the reference interpreter consumes these policies and checks if a given sequence of actions adheres to them.
The new release marks a shift in the industry's approach to securing CI/CD systems, treating agents as their own identities with their own audit trails. However, the implementation details of Dogwood, such as syntax, license, target runtimes, and integrations with specific agent frameworks, remain unclear. Platform teams must consider whether Dogwood will complement existing OPA and Cedar policies or replace them entirely.
The primary benefit of Dogwood lies in its ability to encode rules that a human reviewer would apply instinctively, ensuring that the overall sequence of tool calls is valid before allowing any changes to be deployed. Adoption of Dogwood requires a thorough audit of an agent's behavior on your systems, and a phased rollout starting with a report-only mode to identify any silent bypasses.
While Dogwood addresses a critical gap in CI/CD security, it does not eliminate the risk of agents reaching shell escapes or unmonitored side channels.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.