Evaluate the enterprise reference

Scale

Enterprise Agentic AI Platform Blueprint

Multi-account AWS CDK reference blueprint for an enterprise Agent Factory with AWS Organizations, SCPs, CDK Pipelines, evaluation gates and a documented support envelope.

First deploy
not documented
Validated regions
Validated in eu-west-1; SCP allow-list us-west-2, us-east-1, eu-west-1 source for validated regions (opens in new tab)
Infrastructure as code
AWS CDK (TypeScript) with CDK Pipelines; 12 service control policies; Python and shell utilities source for infrastructure as code (opens in new tab)

What it is

Status

Status
Version 1.0.0 (README badge); two open advisories (issues #29 and #30) README.md (opens in new tab)

Recent changes: commit history for enterprise-agentic-ai-platform-blueprint on GitHub (opens in new tab)

Advisory: GitHub issue #29

Opened 2026-09-15. The blueprint still provisions and consumes Agent Registry through the preview bedrock-agentcore-control APIs, and AWS support for those APIs ended on 2026-09-17. Treat Registry-dependent paths as unverified until the issue is closed.

enterprise blueprint: migrate Agent Registry before 2026-09-17 preview cutoff (opens in new tab)

Evidence: platform-registry-construct.ts (opens in new tab)

Advisory: GitHub issue #30

Opened 2026-09-15. The lockfile resolves aws-cdk-lib to 2.251.0; advisory GHSA-vcrf-j523-4mrf (CVE-2026-13760, high) is fixed in aws-cdk-lib 2.260.0. This is a build and deployment toolchain risk; run npm audit and update before deploying.

enterprise blueprint: resolve npm audit findings before deployment (opens in new tab)

Evidence: package-lock.json (opens in new tab)

At a glance

Blueprint facts with a source for every value
FactValueSource
Validated regionsValidated in eu-west-1; SCP allow-list us-west-2, us-east-1, eu-west-1 The SCP region allow-list comes from PLATFORM_APPROVED_REGIONS in packages/platform-baselines/src/approved-regions.ts. A different Region is a new validation target, not a configuration-only substitution.README.md: 5. Prerequisites (opens in new tab)
Default regioneu-west-1README.md: 6.1 One-time setup (opens in new tab)
What it deploysA multi-account reference: AgentCore Runtime, Gateway, Identity, Memory, Policy, Registry and Evaluations; Bedrock with Guardrails and application inference profiles; Cognito, IAM Identity Center and Cedar; Organizations SCPs; CodePipeline, CodeBuild and CodeConnections; VPC with endpoints; Lambda; KMS, S3, DynamoDB, Secrets Manager and ECR; CloudWatch, OAM and X-Ray; CloudTrail, Config, Security Hub, GuardDuty and Inspector; Budgets and CUR README section 4 calls this the deployable and live-tested reference implementation, not a universal mandatory product list. Not every optional construct is inside the Ireland support envelope.README.md: 4. AWS services used (opens in new tab)
First deploynot documented The README documents the deployment sequence (sections 6.1 to 6.6: one-time setup, configuration, scoped bootstrap, Platform pipeline, Workstream onboarding, validation) but no duration.none
Hands-on timenot documented The README lists organizational prerequisites (a Platform product owner, an account-vending process, governance and approval policies) but gives no time figure.none
Costnot documented README section 8 describes a two-layer cost model (shared Platform cost and Workstream cost) and recommended controls such as allocation tags, budgets and CUR reconciliation, but publishes no figure.none
Infrastructure as codeAWS CDK (TypeScript) with CDK Pipelines; 12 service control policies; Python and shell utilitiesREADME.md (opens in new tab)
Account topologyMulti-account: Management, Platform, and Workstream account roles (nonproduction and production may be separate accounts)README.md: 5. Prerequisites (opens in new tab)
Auth and policyAWS_IAM on the Workstream Tool Gateway; Cognito M2M and AgentCore Identity for inference; AgentCore PolicyEngine plus a retained Lambda Cedar wrapper; 12 SCPsREADME.md: 10.1 Control summary (opens in new tab)
StatusVersion 1.0.0 (README badge); two open advisories (issues #29 and #30)README.md (opens in new tab)
TeardownRun python3 scripts/final_teardown.py per account role (workstream, then platform, then management), first as a dry run and then with --apply; verify with scripts/residue_inventory.pyREADME.md: 16. Cleanup (opens in new tab)
Version1.0.0README.md (opens in new tab)

Compare all four projects

Quickstart

Prerequisites and deployment sequence

Prerequisites: Blueprint prerequisites on the Start pages.

The Blueprint is a multi-account rollout, not a single command. Start with one representative Workstream cell and prove the complete lifecycle before onboarding more.

Expected time: not documented The README documents the deployment sequence (sections 6.1 to 6.6: one-time setup, configuration, scoped bootstrap, Platform pipeline, Workstream onboarding, validation) but no duration.

  1. Confirm the prerequisites (README section 5)

    Node.js 20 or later, Python 3.12 or later, AWS CLI v2 and AWS CDK v2. An AWS Organizations landing zone with Management, Platform and Workstream account roles. A GitHub organization with an AWS CodeConnections connection. Bedrock model access in the target Region. Administrator access for the initial bootstrap only.

    README section 5, Prerequisites (opens in new tab)

    Source: README.md: 5. Prerequisites (opens in new tab)

  2. 6.1 One-time setup

    git clone https://github.com/aws-samples/sample-ai-agent-factory.git
    cd sample-ai-agent-factory/enterprise-agentic-ai-platform-blueprint
    npm ci
    npm run build
    npm test
    npm run lint
    npm run scrub
    
    export AWS_REGION=eu-west-1
    export AWS_DEFAULT_REGION="$AWS_REGION"
    export CDK_DEFAULT_REGION="$AWS_REGION"

    Set all three Region variables; setting only CDK_DEFAULT_REGION is insufficient.

    README section 6.1, One-time setup (opens in new tab)

    Source: README.md: 6.1 One-time setup (opens in new tab)

  3. 6.2 Configuration

    The CDK application reads agenticai/* context values. Keep real account IDs, secret ARNs, tokens and generated Registry context outside source control, and pin agenticai/githubBranch when deploying an unmerged branch.

    README section 6.2, Configuration (opens in new tab)

    Source: README.md: 6.2 Configuration (opens in new tab)

  4. 6.3 Bootstrap with scoped policies

    Generate one CloudFormation execution policy per account and Region, validate each with IAM Access Analyzer, then run the cross-account bootstrap. Do not use AdministratorAccess as the execution policy.

    README section 6.3, Bootstrap with scoped policies (opens in new tab)

    Source: README.md: 6.3 Bootstrap with scoped policies (opens in new tab)

  5. 6.4 Deploy the Platform control plane

    Create the Platform pipeline stack with Gateway invoke permissions disabled, run it, and review Registry descriptors before approval.

    README section 6.4, Deploy the Platform control plane (opens in new tab)

    Source: README.md: 6.4 Deploy the Platform control plane (opens in new tab)

  6. 6.5 Onboard a Workstream cell

    Resolve one Registry context file per environment, deploy the Workload pipeline root, complete the two-phase Gateway permission handoff, then approve GatewayPermissionReady.

    README section 6.5, Onboard a Workstream cell (opens in new tab)

    Source: README.md: 6.5 Onboard a Workstream cell (opens in new tab)

  7. 6.6 Validation

    Run the local gates, synthesize with strict mode, and require clean cdk-nag reports. Live mode fails closed: missing credentials or expected denials are errors, not skips.

    README section 6.6, Validation (opens in new tab)

    Source: README.md: 6.6 Validation (opens in new tab)

Service control policies

The Blueprint ships 12 service control policies as TypeScript definitions. Each entry links to its source file.

  1. SCP-01 Restrict Bedrock Model Access: scp-01-model-allowlist.ts (opens in new tab)
  2. SCP-02 Enforce Bedrock Guardrail Usage: scp-02-enforce-guardrail.ts (opens in new tab)
  3. SCP-03 Enforce VPC Endpoints for AgentCore: scp-03-enforce-agentcore-vpce.ts (opens in new tab)
  4. SCP-04 Enforce VPC Endpoints for Bedrock: scp-04-enforce-bedrock-vpce.ts (opens in new tab)
  5. SCP-05 Deny Guardrail Modification in Workload Accounts: scp-05-deny-guardrail-modification.ts (opens in new tab)
  6. SCP-06 Restrict Region Usage: scp-06-restrict-regions.ts (opens in new tab)
  7. SCP-07 Deny Public AgentCore Resources: scp-07-deny-public-agentcore.ts (opens in new tab)
  8. SCP-08 Deny ECR Public Repositories: scp-08-deny-ecr-public.ts (opens in new tab)
  9. SCP-09 AgentCore Gateway Mutation Lockdown: scp-09-gateway-mutation-lockdown.ts (opens in new tab)
  10. SCP-10 Tool-Invoke Allow-list: scp-10-tool-invoke-allowlist.ts (opens in new tab)
  11. SCP-11 Agent Registry Mutation Lockdown: scp-11-registry-mutation-lockdown.ts (opens in new tab)
  12. SCP-12 Developer Permission Set and Platform-Tag Mutation Deny: scp-12-developer-platform-tag-deny.ts (opens in new tab)

Golden paths

The blueprints under blueprints/ are starting points for versioned enterprise golden paths, not disconnected demos. README.md: 7. Golden paths for engineering teams (opens in new tab)

The 5 templates under blueprints/, from README section 7
TemplateFrameworkBest fitEnterprise contract
agenticai-task-agent (opens in new tab)StrandsDeterministic business taskMax-iteration guard, baseline Guardrail, optional durable HITL
agenticai-chatbot-agent (opens in new tab)StrandsCustomer or employee conversationStreaming, conversation memory, human handoff
agenticai-multi-agent (opens in new tab)StrandsSupervisor and bounded workersSeparate identities, explicit delegation, bounded fan-out
agenticai-langgraph-agent (opens in new tab)LangGraphState-machine or graph orchestrationSame Gateway and governance boundaries through an adapter
agenticai-crewai-agent (opens in new tab)CrewAIRole-oriented crew orchestrationSame approved-tool and Guardrail contracts through an adapter

Source: README.md: 7. Golden paths for engineering teams (opens in new tab)

Repository map

The packages/ folder holds 35 packages. The groups below are a reading aid; the names are as in the repository. Browse packages/ on GitHub (opens in new tab)

Organization, accounts and access

  • landing-zone
  • organizations
  • platform-baselines
  • developer-access
  • federation
  • cost-allocation

AgentCore and application constructs

  • agentcore-gateway
  • agentcore-identity
  • agentcore-memory
  • agentcore-registry
  • agentcore-runtime
  • agent-registry
  • agentic-app
  • agentic-vpc

Model access, quotas and safety

  • platform-inference-gateway
  • litellm-gateway
  • bedrock-guardrails
  • bedrock-invocation-logging
  • bedrock-quotas
  • tenant-quota-guard
  • pii-redaction

Tools, catalogue and policy

  • platform-tool-catalogue
  • tool-cedar-wrapper
  • catalogue-drift-detector
  • agent-protocols
  • rag

Delivery, evaluation and lifecycle

  • agent-lifecycle
  • agent-resilience
  • evaluation-gates
  • online-evaluation
  • hitl
  • developer-cli

Observability and compliance

  • observability
  • otel-genai-semconv
  • eu-ai-act-compliance

Architecture and figures

Enterprise Agent Factory AWS service-level reference architecture
Figure 2 from the Blueprint README: AWS service-level reference implementation. Account IDs are documentation placeholders. README.md (opens in new tab) Download the editable .drawio source (opens in new tab)

Architecture across all four projects

Known limitations and support envelope

Each item is copied from the project README or docs without paraphrase.

Support envelope for all projects

Evidence

The README defines local gates, a strict synth for infrastructure changes, and seven conditions that a behavior-changing revision must meet before it counts as complete.

What runs against live AWS

Live mode fails closed: missing credentials, probes, resources, or expected denials are errors, not passing skips. The adversarial harness validates the evidence schema, twin ledger, sanitization, and domain catalog offline.

Source: enterprise-agentic-ai-platform-blueprint/README.md: 6.6 Validation (opens in new tab), enterprise-agentic-ai-platform-blueprint/README.md: 10.2 Threat and evidence model (opens in new tab)

Live-validated reference envelope

Each item is copied from the README without paraphrase and links its source.

Local gates

npm run build
npm test
npm run lint
npm run scrub

python3 -m pytest tests/adversarial/unit -q
python3 -m pytest scripts/test_final_teardown.py scripts/test_residue_inventory.py -q

What a pass proves: The packages build, their unit tests and lint pass, the scrub script passes, the adversarial harness unit tests pass, and the teardown and residue-inventory scripts are tested.

Source: README.md: 6.6 Validation (opens in new tab)

Strict synth and cdk-nag for infrastructure changes

npx cdk synth --strict

What a pass proves: The exact account and Region topology synthesizes, the generated templates are reviewed, and cdk-nag reports are clean.

Source: README.md: 6.6 Validation (opens in new tab)

Seven conditions for a behavior-changing revision

What a pass proves: A behavior-changing revision is complete only after all seven:

  1. reviewed pipeline deployment;
  2. an authorized positive call;
  3. an unauthorized adversarial twin with an exact denial;
  4. a mutation proving the test fails when the control is removed;
  5. rollback and re-run to green;
  6. centralized logs, metrics, and traces where claimed;
  7. dependency-ordered teardown and direct resource inventory.

Source: README.md: 6.6 Validation (opens in new tab)

Documentation on this site

  • README: Enterprise Agentic AI Platform Blueprint on AWS

Teardown

Prerequisites and deployment sequence

Retire Platform alias grants first, then run the fail-closed teardown per account role: Workstream, then Platform, then Management. Each run is a dry run until you add --apply. Finish with the residue inventory.

python3 scripts/final_teardown.py \
  --account-role workstream \
  --expected-account <WORKSTREAM_ACCOUNT> \
  --region eu-west-1

Source: README.md: 16. Cleanup (opens in new tab)

Costs and cleanup for all projects