Enterprise Platform Capabilities
The enterprise feature set layered on top of the core canvas — lifecycle, governance, integration, and FinOps capabilities, each wired end-to-end (UI → API → Step Functions / store → AWS).
Beyond the core canvas, the platform layers an enterprise feature set on top of raw AgentCore primitives. Each capability is wired end-to-end (UI → API → Step Functions / store → AWS) and owner-scoped for multi-tenant safety.
Agent lifecycle & quality
- Agent Versioning & Rollback -- Every deploy is an immutable, versioned snapshot. A runtime has
production/stagingslots;GET /api/runtimes/{name}/versionslists history andPOST .../rollbackpromotes the previous version back into production. Lets you ship, compare, and revert without losing prior canvases. - Cedar ENFORCE policy enforcement (fail-closed, converge-in-place) — When a Policy node runs in
ENFORCEmode, the policy step builds a schema-correct Cedar policy set against the gateway's real MCP tool manifest: onepermit(principal is AgentCore::OAuthUser, action in [AgentCore::Action::"{Target}___{tool}", …], resource == AgentCore::Gateway::"<arn>")over the allowed tools (theaction in [...]list form is mandatory even for one tool — a singletonaction == "X"is rejected as "Overly Permissive"), with forbidden tools denied by omission (AgentCore is default-deny;ENFORCEalso filterstools/listso a forbidden tool is invisible to the agent). Several guards keep enforcement honest: (1) policy names are engine-prefixed to avoid a name-collision pitfall — AgentCore policy names are account-global, not engine-scoped; (2) on a name conflict the step recovers the existing policy from this engine and validates it, or aborts if the name belongs to a foreign engine; (3) it never reports success on an engine holding 0 ACTIVE policies. A freshly-created policy engine + gateway take ~20–60 minutes (variable, AgentCore-side) to become consistent (create_policy/update_policyendCREATE_FAILED/UPDATE_FAILED "Insufficient permissions to call gateway"until then), too long to block the deploy. So the step attaches the engine fail-closed inENFORCEwith the permit recorded asenforce_pending— default-deny leaves tools temporarily unavailable rather than unprotected (a forbidden-tool value must never leak) — and a shared_maybe_promote_policy()converges the permit toACTIVEon each invoke/status touchpoint once the gateway settles. The promoter recovers a failed permit in place viaupdate_policy(stable policy id — NOT delete+recreate, which raced concurrent status-poll invocations on the account-global name and never converged), skips in-flight (CREATING/UPDATING) policies, and treatsConflictExceptionas a benign concurrent-run signal.update_policy'sdescriptionis a{"optionalValue": str}structure (not a bare string likecreate_policy). Requiresbedrock-agentcore:UpdatePolicyon the deployment Lambda role. State is surfaced viapolicy_result.{mode,enforce_validation_pending,promoted_at_first_use}. Verified live: post-convergencetools/listreturns only permitted tools, permitted tools return data, forbidden tools are denied; the policy engine is torn down children-first on delete. - Evaluation Framework -- Register AgentCore Online Evaluation (built-in goal-success / correctness / helpfulness evaluators + custom judge prompts) at deploy time.
GET /api/runtimes/{name}/evaluationsaggregates per-evaluator scores from the runtime's CloudWatch log group via Logs Insights. - Observability Dashboard -- Each deploy upserts a per-runtime CloudWatch dashboard (latency, invocations, errors, token usage, tool-call success).
GET /api/runtimes/{name}/dashboard-urlreturns the deep link. Platform Lambdas and deployed agents both emit OTLP spans (see Observability). - Cost & Usage Analytics --
GET /api/runtimes/{name}/costpricesgen_ai.usage.*token counts from the runtime's logs against a baked Bedrock price table and returns{total_cost, total_in, total_out, by_model}for the requested window.
Authoring & reuse
- NL Agent Generator (describe → canvas) --
POST /api/generate-canvasturns a natural-language description into a validated canvas spec via Bedrock tool-use (two-turn: clarify → generate). Generated tools are constrained to real built-in tool IDs (or custom tools with an input schema) so a generated agent always deploys with working gateway targets. - Agent Registry with two-persona approval -- An org-wide catalog to publish, discover, and clone agents as reusable blueprints. Role-based via Cognito groups: a
registry-developerpublishes (entry enterspending), browses approved entries, and clones approved/own entries — but cannot approve; aregistry-adminsees the pending-review queue, approves/rejects submissions, and can delete any entry. Publish from the Deploy panel; browse/clone from the canvas. See Registry Roles & Approval. - Prompt Library -- Versioned, reusable system prompts (
/api/prompts) with version history, a promotable default version, and resolve-by-reference at codegen time. A runtime'ssystemPromptcan be an inline string or a{prompt_id, version_id?}reference. - Python Code Export ("eject") --
POST /api/export-pythonreturns a standalone, runnable Python project (agent.py,requirements.txt,Dockerfile,run.sh,.env.example,README) so an agent can run independently of the platform. (Companion to the existing CloudFormation export.)
Integration & automation
- A2A (Agent-to-Agent) -- Deploy a runtime that serves a
/.well-known/agent-card.jsonand exposes an SSRF-guardedcall_a2a_peertool (https-only, host allowlist + IP denylist) so agents can discover and invoke peer agents. - Per-Agent Identity -- Opt-in
identityConfig.mode=per_agentmints a distinct least-privilege IAM execution role scoped to exactly the resources an agent is wired to (vs the shared demo role). Roles are taggedManagedBy=agentcore-flowsso cleanup is tag-scoped. - Agentic Retrieval -- Knowledge Base nodes support
retrievalStrategyofmulti_hop(LLM query decomposition + iterative retrieve),hybrid(vector + keyword, with managed-KB fallback to semantic), orreranked(wide retrieve + Claude-judge reorder) beyond simple retrieval. - Scheduled / Event Triggers -- Register
cron,eventbridge,s3, orwebhooktriggers on a runtime (/api/runtimes/{name}/triggers). Thetarget_runtime_arnis derived server-side from the owned production slot (confused-deputy guard); webhook triggers mint an owner-scoped HMAC secret in Secrets Manager. New triggers are recorded asregistered(not yet firing) until the AWS resource is provisioned — the UI never falsely shows an unwired trigger as active. - SaaS Connectors (live OpenAPI Gateway targets) -- A curated catalog (Jira/
AtlassianOauth2+ API-key Basic, Asana/PAT, Slack, GitHub, Salesforce) plus a generic OpenAPI/MCP connector, deployable as real Gateway targets. The deploy step fetches the connector's OpenAPI spec (SSRF-guarded, host-allowlisted), registers an API-key or OAuth2 client-credentials credential provider backed by an owner-scoped Secrets Manager secret, and attaches it to the gateway target. OpenAPI targets are crawled (not inline) and readiness is verified by probing the gateway's live MCPtools/list.GET /api/connectorslists the catalog for discovery. Teardown deletes the target, credential provider, and secret via the resource manifest. Live-verified: GitHub (api-key → real/userlogin) and Asana (PAT → real/users/me) end-to-end; Jira/Slack/Salesforce require live credentials to exercise. - GitOps Sync -- Store a Git PAT in an owner-scoped Secrets Manager namespace (
/api/workflows/{id}/git-token) and pull a workflow spec from a repo (/api/workflows/{id}/git-sync), preserving id/owner/ACL. SSRF-guarded. - Human-in-the-Loop (HITL) -- Inject a
human_approvaltool into an agent; pending approvals land in an owner-scoped queue (GET /api/hitl/pending,POST /api/hitl/{id}/decision) surfaced in the UI inbox. - Team Workspaces & Sharing -- Share a workflow with viewer/editor roles (
/api/workflows/{id}/share); list workspace-visible workflows (GET /api/workspaces). Owner-only mutation with escalation guards.
Enterprise governance & operations (Loom-inspired)
An enterprise governance layer modeled on awslabs/loom (opens in new tab) — scope-based access control, least-privilege automation, private networking, config-driven human oversight, and FinOps self-drive. Each item is wired end-to-end and verified against real AWS.
- Scope-based RBAC/ABAC -- Two-dimensional authz from Cognito groups: tenant role (
t-admin/t-user) × resource groups (g-admins-*/g-users-*) → a scope set;require_scopes()guards every write route. Advisory by default (RBAC_ENFORCE=false: log-would-deny), flips to fail-closed 403. Scopes never bypassowner_subtenant isolation. See RBAC Rollout. - 3rd-party OIDC IdP federation -- Context-gated Cognito identity provider federates an external IdP (e.g. Okta) and maps its group claim into the platform's internal group model, so federated users inherit RBAC scopes without a separate platform account (
-c oidc_client_id=… -c oidc_groups_claim=groups). - JIT least-privilege permission requests --
POST /api/permissions/requestsfiles a scoped IAM-widening request; a registry-admin approves it, whichPutRolePolicys aJIT-{id}inline policy scoped only to platformAgentCore*roles and validated against an action allowlist (noiam:/sts:/*escalation). Reject closes the request. - Config-driven HITL approval policies --
/api/settings/approval-policiesdefine glob-matched tool/action rules (requireblock vsnotify). On deploy, enabled policies serialize into the runtime'sLOOM_APPROVAL_POLICIESenv var so a guaranteedBeforeToolInvocationhook forces approval on matching tools — independent of whether the model chooses to callhuman_approval. Applies to both codegen and managed-harness runtimes. - OBO identity propagation & inspection --
GET /api/identity/token-infodecodes the caller JWT (issuer/scopes/claims) for the UI;POST /api/identity/test-obovalidates an RFC 8693 on-behalf-of exchange config (TOKEN_EXCHANGE/JWT_AUTHORIZATION_GRANT) without a live user token. The connectordelegationMode=obomints an AgentCore OAuth2 provider so the agent calls downstream as the end-user. - VPC-egress runtimes & named profiles --
/api/settings/vpc-profilesdefine reusable{subnet_ids, security_group_ids}bundles; a deploy referencing one by name (vpcProfile) threadsnetworkMode=VPCinto the runtime so it runs in customer private subnets. Unknown profile → 400 at deploy. Optional PrivateLink ingress IaC (NLB + VPCEndpointService + SG) ships as a downloadable add-on (privatelink-ingress.yaml(opens in new tab)). - Import existing runtime by ARN --
POST /api/runtime/importadopts an externally-built AgentCore Runtime as a caller-owned deployment (no codegen/deploy) so pre-existing runtimes join the platform's version/slot/cost/observability surfaces. - Integration gating -- When AWS Agent Registry federation is enabled, a deploy referencing an MCP/A2A integration is rejected unless each referenced integration is
APPROVEDin the registry (no-op when federation is off). - AWS Agent Registry federation -- Opt-in federation of deployed agents into the org-wide AWS-native Agent Registry (
CreateRegistryRecord→SubmitRegistryRecordForApproval→ approve →SearchDiscoverableRegistryRecords), auto-registered on deploy and removed on teardown. Targets the GA API: Agent Registry is its own AWS service (agent-registry-control/agent-registryclients,agent-registry:*IAM actions,recordType∈MCP|AGENT|CUSTOM|SKILL), so the backend requires boto3 >= 1.43.66.GET /api/registry/aws-configreportssdk_supported: falseon an older bundle rather than silently degrading. - Cost budgets + scheduled FinOps reconciliation --
/api/cost/budgetsset per owner/agent/tag monthly limits (warn + hard thresholds) evaluated against the samegen_ai.usagepipeline as the cost dashboard. A daily EventBridge sweep (cost_reconcile_step) walks every budget, sums month-to-date actual spend, and emits aBudgetBreachCloudWatch metric for any warn/over — so an idle-but-overspending agent trips an alarm even when nobody opens the dashboard. - Live model catalog --
GET /api/modelsdiscovers text models live from Bedrock (list_inference_profiles+list_foundation_models, filtered to TEXT/ACTIVE/ON_DEMAND) merged with a curated friendly-label overlay, replacing the hardcoded picker; falls back to a static list if Bedrock is unreachable. - Rich admin analytics --
GET /api/admin/audit(admin scope) rolls up audited writes intoby_action/by_actorplusdistinct_actors,distinct_sessions, and a chart-readyby_daytime-series rendered as summary tiles + a dependency-free activity chart. - End-user Chat persona + admin View-as -- Consumer personas (
t-user) get a streaming ChatPage instead of the builder canvas; admins get the builder and can preview the consumer experience. Persona derives purely from Cognito group scopes — no privilege change. - Multi-region / multi-account deploy (opt-in) -- Off by default; when enabled, a region allowlist + cross-account
sts:AssumeRoleinto a name-scopedAgentCoreFlowsDeploymentRole(with a dry-run identity check) lets a deploy land in a registered target account. - Non-Bedrock provider credentials -- Selecting any non-Bedrock provider (OpenAI/Anthropic/Gemini/LiteLLM/Mistral/Groq/DeepSeek/Together/Writer) injects the provider key from an
agentcore-provider/*-namespaced secret into the generated model init at deploy time (PROVIDER_API_KEY, optionalPROVIDER_BASE_URL).