Skip to content
worth noting AI agents

Amazon Bedrock AgentCore enables writing governance policies for AI agents in natural language

clearly official source

Amazon Bedrock AgentCore has expanded Policy Authoring, a tool that converts written rules in natural language into formal Dogwood policies for governing AI agent behavior – including time constraints, tool call order, and integration with Amazon Bedrock Guardrails.

Amazon Bedrock AgentCore has expanded Policy Authoring, an AI-powered tool that converts documents describing rules written in natural language into formal specifications in Dogwood. Dogwood is an open source language for AI agent governance whose rules are enforced in real time by the so-called Dogwood monitor built into AgentCore Gateway, a component of Amazon Bedrock AgentCore. According to Amazon, the aim is to enable even nontechnical policy authors – such as compliance teams – to specify constraints on AI agent behavior without having to write in a formal language manually.

New Policy Authoring capabilities include generating policies with time and sequence constraints (temporal and trajectory constraints), meaning rules such as rate limits on tool calls, mandatory prerequisites, a fixed order of tool calls, or cumulative effects across a session. The tool can also generate policies that call Amazon Bedrock Guardrails to detect inappropriate content based on the meaning of free text, as well as policies that restrict tool input parameters, which were already available in the previous version of Policy in AgentCore.

According to Amazon, Policy Authoring works best where rules already exist in written form (for example, a section of an operating procedure containing rules) and the task is more about transcription than design from scratch – a document interspersed with rationale and commentary should therefore first be reduced to just the rules. Alongside the text document, Policy Authoring also takes a schema of the agent tools (their names, arguments, and return values), generated from the MCP protocol tool manifest, and a list of available Amazon Bedrock Guardrails checks and identity claims that the policy is allowed to reference. The company demonstrates the feature using a banking customer service agent with tools for identity verification, transfers between accounts, refunds for disputed payments, opening disputes, and requests for supervisor approval – for example, a rule limiting refunds to business hours and amounts up to 2 500 dollars is converted into a single policy with two conditions, because Dogwood denies by default and a "forbid" rule takes precedence over "permit".

The source article is longer and contains additional technical examples of policies; details can be found in the source article.

What changed

Why it matters

For companies deploying AI agents in regulated sectors (such as finance), this feature, according to Amazon, reduces reliance on technical specialists familiar with the formal language Dogwood when defining and enforcing rules such as transaction limits, mandatory identity verification before a sensitive action, or time windows for certain operations. Compliance teams can thus maintain rules in the form they already use for human employees and have them automatically converted into an enforceable form applied in real time to agent tool calls.

Relevant practical impact

What this means

01

For a business

Companies running AI agents through Amazon Bedrock AgentCore can now enter agent governance rules as ordinary written text instead of manually writing in the formal language Dogwood, lowering the barrier for compliance and operations teams without a technical background when defining and enforcing constraints such as time windows, amount limits, call order…

Risks and compliance
What to decide If a company deploys AI agents through Amazon Bedrock AgentCore, it can have its compliance team test whether existing written rules (operating procedures, limits, approval processes) can be imported directly into Policy Authoring and…
More business impacts →
AI agents Amazon Bedrock Dogwood Governance guardrails Policy Authoring

Check the original

Event sources

clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
AWS Machine Learning Blog primary source · first detected Authoring Dogwood policies from natural language in Amazon Bedrock AgentCore