hands-on lab

Enforcing Controls on an Amazon Bedrock AgentCore Agent

Difficulty: Intermediate
Duration: Up to 1 hour
Students: 5
Rating: 5/5
On average, students complete this lab in40m
Get guided in a real environmentPractice with a step-by-step scenario in a real, provisioned environment.
Learn and validateUse validations to check your solutions every step of the way.
See resultsTrack your knowledge and monitor your progress.

Description

An agent that can call tools is only safe to run if something other than the model's own judgment decides what it is allowed to do. Amazon Bedrock AgentCore gives you different places to enforce that decision: a tool with no code behind it that simply cannot be completed without a human answering it, and a policy engine that evaluates a rule before a tool is ever reached. None of this depends on the system prompt telling the agent to be careful.

In this lab, you will build an expense claims agent from the ground up and use it to enforce controls. You will create a Lambda function backing agent operations and expose them through an AgentCore gateway. You will then test the agent from the harness playground and watch a request get refused before your Lambda function is ever invoked, and a second request pause indefinitely because there is no way to answer it from the console.

Learning objectives

Upon completion of this intermediate-level lab, you will be able to:

  • Configure an Amazon Bedrock AgentCore gateway target backed by a Lambda function
  • Write Cedar policy rules in a policy engine that gate a gateway tool by a field in the request
  • Attach a schema-only tool to a harness so a sensitive action halts until code supplies a result
  • Test all controls from the harness playground

Intended audience

  • Candidates for the AWS Certified Machine Learning Specialty certification
  • Cloud Architects
  • Software Engineers

Prerequisites

Familiarity with the following will be beneficial but is not required:

  • Amazon Bedrock AgentCore

The following content can be used to fulfill the prerequisites:

Environment before

Environment after

Covered topics

Hands-on Lab UUID

Lab steps

0 of 6 steps completed.Use arrow keys to navigate between steps. Press Enter to go to a step if available.
  1. Logging In to the Amazon Web Services Console
  2. Creating the Claims Lambda Function
  3. Creating the Claims Gateway and Target
  4. Writing Policy Rules for the Claims Gateway
  5. Configuring the Claims Agent Harness
  6. Testing the Agent's Tool-Use Controls