AI Agent Factory
Enterprise samples for building, governing, and operating agentic AI on AWS with Amazon Bedrock and Amazon Bedrock AgentCore.
Pick a project
Stage, audience, validated regions, first deploy and cost, every fact linked to its source. See the full comparison.
- 1. LearnDetails about Workshop
Building an Enterprise Agentic AI Platform
Learn the platform patterns hands-on
Best for: Platform and ML engineers who want to understand and build the foundation.
- Validated regions
- AWS-run events: us-west-2. Self-paced: us-west-2 (default), us-east-1, or eu-west-1. Other regions are not supported. source for validated regions, Workshop (opens in new tab)The contentspec.yaml deployableRegions list is us-west-2, us-east-1 and eu-west-1. Workshop Studio events provision the account in us-west-2 (content/introduction/getting-started/aws-event.en.md).
- First deploy
- About 30 to 45 minutes for the self-paced deploy script (five CloudFormation stacks) source for first deploy, Workshop (opens in new tab)The self-paced guide (content/introduction/getting-started/self-service.en.md) notes that the Registry stack alone takes 20 to 30 minutes. At an AWS event the account arrives pre-provisioned, so there is nothing to deploy.
- Cost
- About $15 to $30 for a one-day run in us-west-2 (workshop estimate) source for cost, Workshop (opens in new tab)At an AWS-run event the account is provided and the cost is covered. Cost accrues per hour whether or not the environment is in use.
- 2. BuildDetails about Self-Service
AgentCore Visual Workflow Platform
Build and ship agents visually
Best for: Engineers who want to build and ship agents fast on top of AgentCore.
- Validated regions
- Any AWS region; us-east-1 is the default source for validated regions, Self-Service (opens in new tab)Outside us-east-1 the WAF web ACL is REGIONAL on the Cognito user pool and the CloudFront distribution runs without an edge ACL. APAC regions may need the model ID set explicitly.
- First deploy
- Roughly 15 to 20 minutes for a first-time deploy source for first deploy, Self-Service (opens in new tab)
- Cost
- About $0.02 to $0.39 per month for the platform infrastructure at low to moderate usage (docs/COSTS.md estimate, us-east-1 list prices) source for cost, Self-Service (opens in new tab)Excludes the WAF web ACL that infra/stacks/platform_stack.py always creates, which is billed separately and for which the repository publishes no figure, and all agent inference, AgentCore and vector-store usage.
- 3. GovernDetails about MCP Gateway
Enterprise MCP Governance Gateway
Govern every tool call
Best for: Platform and security engineers who need per-tool-call authorization and audit.
- Validated regions
- us-west-2 by default; configurable; no tested-regions list is published source for validated regions, MCP Gateway (opens in new tab)
- First deploy
- About 5 minutes for the five quickstart steps; the gateway stack itself takes about 2 minutes source for first deploy, MCP Gateway (opens in new tab)
- Cost
- not documentedThe README lists what the stack creates (AgentCore Gateway and policy engine, four Lambdas, a Cognito user pool, a Secrets Manager secret, a customer-managed KMS key, SSM parameters, and a Bedrock Guardrail) but publishes no cost figure.
- 4. ScaleDetails about Blueprint
Enterprise Agentic AI Platform Blueprint
Evaluate the enterprise reference
Best for: Platform and security engineers building enterprise-scale infrastructure.
- Validated regions
- Validated in eu-west-1; SCP allow-list us-west-2, us-east-1, eu-west-1 source for validated regions, Blueprint (opens in new tab)The SCP region allow-list comes from PLATFORM_APPROVED_REGIONS in packages/platform-baselines/src/approved-regions.ts. A different Region is a new validation target, not a configuration-only substitution.
- First deploy
- not documentedThe README documents the deployment sequence (sections 6.1 to 6.6: one-time setup, configuration, scoped bootstrap, Platform pipeline, Workstream onboarding, validation) but no duration.
- Cost
- not documentedREADME section 8 describes a two-layer cost model (shared Platform cost and Workstream cost) and recommended controls such as allocation tags, budgets and CUR reconciliation, but publishes no figure.
Who is this for?
Platform engineer
Build the LLM Gateway, registries and Tools Gateway module by module. Start with the Workshop
AI/ML engineer
Ship an agent on Amazon Bedrock AgentCore from a template on a visual canvas. Start with Self-Service
Security engineer
See Cedar ENFORCE, JWT authentication, interceptors and a Guardrail on a live MCP endpoint. Start with the MCP Gateway
Solutions architect
Compare regions, deploy time, cost and topology before recommending a project. Start with the comparison
Engineering director
Know what each sample is and is not before committing a team. Start with the support envelope
Shared capabilities
Every project draws on the same capability contracts; the implementations are replaceable.
Before you deploy
Open advisories
- Workshop: Issue #2: ghcr.io instead of docker.litellm.ai (opens in new tab)
- Blueprint: Issue #29: enterprise blueprint: migrate Agent Registry before 2026-09-17 preview cutoff (opens in new tab)
- Blueprint: Issue #30: enterprise blueprint: resolve npm audit findings before deployment (opens in new tab)
Real resources, real costs
Every project deploys real, billable AWS resources. Check the cost notes and teardown steps, the support envelope, and the license before you deploy.