AI Agent Authorization Beyond Authentication: A Look At AWS Dogwood
TL;DR: Credentials conflate authentication and authorization : Long-lived API keys, tokens, and certificates grant standing access to whoever holds them, making blast radius depend on permissions, not just validity. AWS Dogwood adds temporal policy for agents : Released in August 2026 and built on Cedar, Dogwood evaluates sequences of prior actions, not just point-in-time requests, to authorize…
Long-lived API keys, tokens, and certificates provide standing access to anyone who obtains them, thereby expanding blast radius based on permissions rather than validity. AWS Dogwood, launched in August 2026, addresses this issue by considering the sequence of prior actions when authorizing AI agent tool calls. Built upon Cedar, Dogwood evaluates the entire history of actions taken by an agent, rather than relying solely on a single point-in-time request.
GitGuardian provides an additional layer of security for the credential layer. Its Secret Analyzer adds permission context, while the Exploration Map tracks consumers and resources, helping teams transition away from long-lived secrets as AI-related leaks have surged by 81% in 2025. Credentials always represent a combination of authentication and authorization, but this conflation has led to significant security challenges.
Historically, credentials have been used as access paths, carrying associated permissions that remain accessible through copied secrets into CI/CD pipelines, application configurations, or local development environments.
As the industry progresses towards workload identity, short-lived credentials, and stronger separation between identity verification and permission decisions, standards such as SPIFFE and SPIRE have emerged to provide practical solutions for identity and authentication. While cloud-native approaches have been moving in this direction for years, AWS Security Token Service enables workloads to obtain temporary security credentials, reducing the risks associated with long-lived keys.
However, AI agents have intensified the urgency surrounding authorization. Even if an agent successfully authenticates and uses an approved tool within its permitted boundaries, it may still pose a risk by making a dangerous decision based on its historical actions. To tackle this challenge, AWS Dogwood serves as a groundbreaking effort specifically designed to address the authorization concerns of AI agents.
By evaluating sequences of events through temporal policy, Dogwood expands upon Cedar and enables runtime policy evaluation based on comprehensive context. This innovation goes beyond traditional authorization methods by incorporating the agent's action history, thereby enhancing security measures for autonomous agents in an increasingly complex digital landscape.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.