AWS introduced something this week that is close enough to the problem I have been working on that I do not think it should be casually labeled complementary.

Amazon Bedrock AgentCore added temporal policies, along with an open-source policy language called Dogwood.

Instead of asking only whether an individual tool invocation is allowed, the gateway can evaluate the sequence of actions that led to it.

Consider a purchasing agent with this rule:

purchases under $10,000 do not require escalation