cd /news/ai-agents/aws-offers-local-open-source-leash-f… · home › topics › ai-agents › article
[ARTICLE · art-143350] src=machinebrief.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

AWS offers local, open source leash for agent harnesses

AWS published the Dogwood Local Engine (DLE), an open source Rust library that checks AI agent tool calls against user-defined temporal policies and returns allow/deny verdicts before the harness executes them. DLE embeds the Dogwood governance language AWS open sourced in August and added to Amazon Bedrock AgentCore, and AWS measured evaluation times of about 20 microseconds with a 15-minute window at the 12-hour mark, rising to roughly six milliseconds with a 24-hour window. AWS said the library persists each tool-call event to disk before policy evaluation so state survives a crash or restart, and that enforcement itself remains the harness's responsibility.

read3 min views1 publishedOct 1, 2026
AWS offers local, open source leash for agent harnesses
Image: Machinebrief (auto-discovered)

Source:

The Register Dogwood Local Engine checks AI tool calls against user-defined temporal rules before they run

If you don't want your AI agents running out of control and changing files or transferring data outside your rules, AWS has published an open source software library that it claims can add a new layer of policy control. Just as a dog’s harness is useless without a leash to keep it under control, the Dogwood Local Engine promises to put AI agenttool calls on a leash, blocking actions that don’t meet user-defined temporal conditions. The DLE comes in the form of a Rust library that can be embedded into an agent’s harness or gateway and, to boil a long explanation down to a single sentence, simply issues allow/deny verdicts each time an agent tries to make a tool call. DLE doesn’t do the enforcement itself, AWS explained in its announcement writeup - that’s up to the harness itself - but it does check each tool call against policies defined using Dogwood, the open source governance language that AWS published in August. When AWS introduced Dogwood, it open sourced the language and reference tooling and added support for it to Amazon Bedrock AgentCore; DLE’s release makes the policy engine directly embeddable into agent harnesses. A key feature of both DLE and Dogwood is their awareness of temporal conditions. DLE tracks agent tool call events over time, stamping them into a log step by step. Those logs are persisted to a disk as each entry is made, allowing DLE to retain its state even if the entire system crashes or is restarted. The persistence step happens before DLE evaluates the applicable policy, and at the end of that process it returns a result: allow the action, or deny it, based on what the engine’s policies state. AWS gives the example of controlling coding agent Git pushes using DLE, defining a policy that only allows a push when the most recent test run has passed, and requiring that pass to have occurred within the past 15 minutes. If that’s not the case, the push is denied. “To accurately handle verdict enforcement, the harness intercepts every tool call, submits a request event to the engine, and runs the tool only if the engine’s verdict is allow,” AWS explained. This naturally raises the question of how much of a delay DLE introduces into agentic workflows; AWS claims the added delay is minimal. In tests simulating sessions from five minutes to 12 hours, DLEevaluationtime was around 20 microseconds with a 15-minute window at the 12-hour mark, rising to about six milliseconds with a 24-hour window. DLE is also designed to prevent concurrent submission collisions by relying on a lock that only allows one event submission at a time, and that lock persists until policy evaluation is complete. AWS didn’t make clear from its writeup how that would handle a situation where, say, two concurrent submissions were made in which one fulfilled pass conditions and one caused a failure. We asked how incorrect enforcement could be prevented in those situations, but didn’t hear back prior to publication. Given repeated revelations of late that AI agents appear to regularly go off the (safety) rails imposed on them by human operators, the question of how durable DLE is also merits discussion. AWS admits that such situations are part of its reason for publishing the new library. “Left unchecked … tool calls can have irreparable consequences,” the DLE announcement concludes. “As agents scale to settings where they work autonomously for longer intervals with more tools, we need safeguards that can regulate how those tools are used.” AI agents finding holes in Dogwood and the DLE is likely a matter of time. Until then, feel free to give Dogwood and DLE a shot through its GitHub page. ® Get AI news in your inbox

Daily digest of what matters in AI.

── more in #ai-agents 4 stories · sorted by recency
── more on @aws 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/aws-offers-local-ope…] indexed:0 read:3min 2026-10-01 · —