What’s new here
Dogwood adds temporal predicates (formerly within 1h, since, and windowed aggregations) to Cedar’s permit/forbid syntax, letting a policy look back across an agent’s recent event history. It compiles down to standard Cedar, so the temporal logic gets resolved at runtime into context.* slots that a Cedar-compatible engine can evaluate.
What it does
Dogwood is a governance language for AI agents. Its syntax derives from Cedar (permit/forbid, when/unless) and adds temporal conditions that match against a logged sequence of past agent actions.
This repo ships the reference implementation: a Rust parser, interpreter, and lowering pass. The CLI provides three commands:
dogwood validatechecks a policy and its schemas for errorsdogwood lowercompiles a.dwpolicy to Cedar, emitting the lowered outputdogwood replayruns a policy against a trace file and prints per-event verdicts
Information providers (Rhai scripts) can inject computed facts into the authorization context at evaluation time. The engine design is pluggable: the policy backend (local Cedar or remote) and the temporal engine (in-memory or database-backed) are swapped independently.
The README is explicit that this interpreter is for testing and understanding language semantics, not for production authorization. It lists the gaps: no timestamp validation, no event authentication, unbounded in-memory trace storage, and no audit logging.
Who it’s for
Teams designing or evaluating Dogwood-based authorization for AI agents. Useful for policy authors who want to validate and replay policies against event traces before wiring up a production engine, and for developers building on the dogwood-language Rust crate to integrate policy evaluation into an agent harness.
Try it
The README’s Quick start uses the dogwood CLI but does not say how to get it. The CLI is built from the dogwood-cli crate in this repo’s workspace, for example with cargo build --release -p dogwood-cli from a clone, which produces target/release/dogwood. Then validate, lower, and replay:
# Validate a policy against its schemas:
dogwood validate policy.dw --policy-schema schema.cedarschema
# Lower to Cedar and see the output:
dogwood lower policy.dw --policy-schema schema.cedarschema --emit both
# Replay a trace and see verdicts:
dogwood replay policy.dw --policy-schema schema.cedarschema --trace events.logTo use the language as a Rust library instead, add the crate to Cargo.toml:
[dependencies]
dogwood-language = { git = "https://github.com/dogwood-policy/dogwood.git" }See the Getting Started guide for full setup instructions.
How mature is it
456 stars, 29 forks, 2 contributors. Created July 2026, last pushed September 2026. 16 commits in the last 90 days. No GitHub releases; the README pulls the library from git, though version 1.0.0 of dogwood-language is also on crates.io. One open issue and no open pull requests. Licensed Apache-2.0.