# A policy compiler checks structure, not intent

[Journal](/journal/)

August 26, 2026 · [evidence](/journal/#evidence)



AWS shows where natural-language policy authoring stops: validation checks structure and tool names, while a person must confirm intent.

![Written rule cards pass through a policy compiler into validated and set-aside trays, with a review lens beside the validated tray.](/_astro/a-policy-compiler-checks-structure-not-intent.DmxmU3yf_1PY3WI.avif)

A policy compiler can reject malformed policy and still approve the wrong policy. AWS states that distinction in [Policy Authoring for Amazon Bedrock AgentCore](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). Structure belongs to the compiler. Intent stays with the person who owns the rule.

AWS says its tool [turns written rules into Dogwood policies that govern agent tool calls](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). Dogwood is [an open policy language for expressing and enforcing those controls](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

Model Context Protocol, or MCP, is [a standard for connecting tools](https://modelcontextprotocol.io/specification/2025-06-18). AWS says Policy Authoring [reads its tool manifest for exact tool names, arguments, and return values](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). Generated policy then [uses the tools available through the AgentCore Gateway](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

## Supported rules reach beyond one tool call

AWS shows policies for [argument limits and business-hour windows](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). Its examples also cover [prerequisites, cumulative caps, and rate limits](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). These rules can [inspect events from the current session](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

Free-form text gets a separate check. AWS shows a generated policy that [calls Amazon Bedrock Guardrails on a dispute description](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). The policy then [compares the returned confidence score with a threshold](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

Those examples matter because the input document must settle details that code cannot infer safely. AWS advises authors to [name the time window, event key, threshold boundary, and whether a rule covers an attempt or outcome](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

A cumulative cap shows the risk. AWS [translates “transferred” as attempted transfers because the rule omits attempts and successful outcomes](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). The source says [stating that choice in the document removes the guess](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

## Validation proves a narrower fact

AWS describes a four-step pipeline. It [splits compound prose into atomic rules, routes expressible rules, translates them, and validates each candidate](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

The final check has clear authority. AWS says the Dogwood compiler [determines whether a policy parses and whether every name exists in the supplied schema](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). Failed candidates can [return for limited translation rounds with the compiler diagnostics](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

A valid name proves that the policy refers to a real tool or field. A valid expression proves that the language can parse it. Neither result proves that “attempt” should replace “outcome” or that a boundary includes the third action.

AWS therefore tells users to [review each generated policy beside its source sentence](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). Under AWS’s process, [a person must still confirm that the compiled policy matches the written rule](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). AWS states that [validation cannot establish what the author meant](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

## Set-aside rules preserve the boundary

AWS says Policy Authoring [sets aside rules that Dogwood or AgentCore Policy cannot enforce](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). The source names four types:

1.  AWS sets aside [a principle without a condition on an action, field, or principal](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).
2.  AWS sets aside [a request to change data, such as redaction, when the engine can only permit or deny a call](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).
3.  AWS sets aside [a rule outside Dogwood’s expressions, such as weekend or federal holiday restrictions](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).
4.  AWS sets aside [a rule outside session enforcement, including a cumulative cap across concurrent sessions](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

AWS says the output [keeps validated policies separate from atomic rules that were set aside](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/). The routing step [keeps an inexpressible rule from becoming valid syntax with different meaning](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/).

AWS and its services are neither Muniment customers nor endorsers. The AWS post supplies public evidence for a strict operating rule: give compiler output authority over structure, never author intent.

## Sources

1.  [AWS: Authoring Dogwood policies from natural language in Amazon Bedrock AgentCore](https://aws.amazon.com/blogs/machine-learning/authoring-dogwood-policies-from-natural-language-in-amazon-bedrock-agentcore/) aws.amazon.com
2.  [Model Context Protocol Specification](https://modelcontextprotocol.io/specification/2025-06-18) modelcontextprotocol.io
