An agent that can call tools is only safe to run if something other than the model's own judgment decides what it is allowed to do. Amazon Bedrock AgentCore gives you different places to enforce that decision: a tool with no code behind it that simply cannot be completed without a human answering it, and a policy engine that evaluates a rule before a tool is ever reached. None of this depends on the system prompt telling the agent to be careful.
In this lab, you will build an expense claims agent from the ground up and use it to enforce controls. You will create a Lambda function backing agent operations and expose them through an AgentCore gateway. You will then test the agent from the harness playground and watch a request get refused before your Lambda function is ever invoked, and a second request pause indefinitely because there is no way to answer it from the console.
Upon completion of this intermediate-level lab, you will be able to:
Familiarity with the following will be beneficial but is not required:
The following content can be used to fulfill the prerequisites: