Agent security and policy

dogwood-policy/

dogwood-local-engine

A Rust library that evaluates Dogwood temporal policies incrementally, storing state durably so verdicts survive process restarts.

What’s new here

The Dogwood reference interpreter in dogwood-policy/dogwood processes a complete event trace in one shot and is explicitly not meant for production. This engine flips that: it watches events arrive in real time, updates its internal monitor state incrementally, and writes durable checkpoints to the filesystem. A process can crash, restart, and pick up authorization correctly because the engine replays from its last snapshot rather than from scratch.

What it does

The library evaluates Dogwood policies against a stream of agent events. Dogwood policies can refer to an agent’s past actions and their outcomes, so the engine must maintain ordered history. It does that durably: state is checkpointed to disk periodically, and snapshots preserve derived monitor state rather than a complete event history. That means it can recover after a crash and keep issuing accurate verdicts.

The workspace ships three crates. dogwood-local-engine is the core library. dogwood-server is a demo daemon that listens on two Unix sockets, one for control-plane operations (loading and removing policies) and one for data-plane events and decision requests. dogwood-performance contains benchmarks.

The README is detailed about what the library does not do: it issues verdicts but does not enforce them, does not authenticate event provenance, and does not retain a complete audit log. Those responsibilities stay with the embedding application.

Who it’s for

Rust developers building agent runtimes, sandboxes, or tool brokers that need to enforce temporal access policies. The immediate consumer is strands-agents/box, which embeds the engine to gate agent operations. Anyone deploying Dogwood policies in a long-running service, rather than in a batch script, needs this library rather than the reference interpreter.

Try it

Add the crates to Cargo.toml:

[dependencies]
dogwood-local-engine = "1.0"
dogwood-language = "1.0"

Build and test the workspace:

cargo build --workspace --all-targets
cargo test --workspace

For a full walkthrough from policy definition to opening a store and submitting events, see dogwood-local-engine/README.md in the repo.

How mature is it

Created August 2026, last pushed September 2026. 33 stars, 2 forks, 1 contributor, 1 commit in the past 90 days. No GitHub releases, but a v1.0.0 tag exists and version 1.0.0 of both crates is on crates.io. No open issues or pull requests. Licensed Apache-2.0. The README notes it is a published, read-only mirror of an upstream repository.