Enterprise Platform Capabilities

View source on GitHub (opens in new tab)

The enterprise feature set layered on top of the core canvas — lifecycle, governance, integration, and FinOps capabilities, each wired end-to-end (UI → API → Step Functions / store → AWS).

← Back to README

Beyond the core canvas, the platform layers an enterprise feature set on top of raw AgentCore primitives. Each capability is wired end-to-end (UI → API → Step Functions / store → AWS) and owner-scoped for multi-tenant safety.

Agent lifecycle & quality

  • Agent Versioning & Rollback -- Every deploy is an immutable, versioned snapshot. A runtime has production / staging slots; GET /api/runtimes/{name}/versions lists history and POST .../rollback promotes the previous version back into production. Lets you ship, compare, and revert without losing prior canvases.
  • Cedar ENFORCE policy enforcement (fail-closed, converge-in-place) — When a Policy node runs in ENFORCE mode, the policy step builds a schema-correct Cedar policy set against the gateway's real MCP tool manifest: one permit(principal is AgentCore::OAuthUser, action in [AgentCore::Action::"{Target}___{tool}", …], resource == AgentCore::Gateway::"<arn>") over the allowed tools (the action in [...] list form is mandatory even for one tool — a singleton action == "X" is rejected as "Overly Permissive"), with forbidden tools denied by omission (AgentCore is default-deny; ENFORCE also filters tools/list so a forbidden tool is invisible to the agent). Several guards keep enforcement honest: (1) policy names are engine-prefixed to avoid a name-collision pitfall — AgentCore policy names are account-global, not engine-scoped; (2) on a name conflict the step recovers the existing policy from this engine and validates it, or aborts if the name belongs to a foreign engine; (3) it never reports success on an engine holding 0 ACTIVE policies. A freshly-created policy engine + gateway take ~20–60 minutes (variable, AgentCore-side) to become consistent (create_policy/update_policy end CREATE_FAILED/UPDATE_FAILED "Insufficient permissions to call gateway" until then), too long to block the deploy. So the step attaches the engine fail-closed in ENFORCE with the permit recorded as enforce_pending — default-deny leaves tools temporarily unavailable rather than unprotected (a forbidden-tool value must never leak) — and a shared _maybe_promote_policy() converges the permit to ACTIVE on each invoke/status touchpoint once the gateway settles. The promoter recovers a failed permit in place via update_policy (stable policy id — NOT delete+recreate, which raced concurrent status-poll invocations on the account-global name and never converged), skips in-flight (CREATING/UPDATING) policies, and treats ConflictException as a benign concurrent-run signal. update_policy's description is a {"optionalValue": str} structure (not a bare string like create_policy). Requires bedrock-agentcore:UpdatePolicy on the deployment Lambda role. State is surfaced via policy_result.{mode,enforce_validation_pending,promoted_at_first_use}. Verified live: post-convergence tools/list returns only permitted tools, permitted tools return data, forbidden tools are denied; the policy engine is torn down children-first on delete.
  • Evaluation Framework -- Register AgentCore Online Evaluation (built-in goal-success / correctness / helpfulness evaluators + custom judge prompts) at deploy time. GET /api/runtimes/{name}/evaluations aggregates per-evaluator scores from the runtime's CloudWatch log group via Logs Insights.
  • Observability Dashboard -- Each deploy upserts a per-runtime CloudWatch dashboard (latency, invocations, errors, token usage, tool-call success). GET /api/runtimes/{name}/dashboard-url returns the deep link. Platform Lambdas and deployed agents both emit OTLP spans (see Observability).
  • Cost & Usage Analytics -- GET /api/runtimes/{name}/cost prices gen_ai.usage.* token counts from the runtime's logs against a baked Bedrock price table and returns {total_cost, total_in, total_out, by_model} for the requested window.

Authoring & reuse

  • NL Agent Generator (describe → canvas) -- POST /api/generate-canvas turns a natural-language description into a validated canvas spec via Bedrock tool-use (two-turn: clarify → generate). Generated tools are constrained to real built-in tool IDs (or custom tools with an input schema) so a generated agent always deploys with working gateway targets.
  • Agent Registry with two-persona approval -- An org-wide catalog to publish, discover, and clone agents as reusable blueprints. Role-based via Cognito groups: a registry-developer publishes (entry enters pending), browses approved entries, and clones approved/own entries — but cannot approve; a registry-admin sees the pending-review queue, approves/rejects submissions, and can delete any entry. Publish from the Deploy panel; browse/clone from the canvas. See Registry Roles & Approval.
  • Prompt Library -- Versioned, reusable system prompts (/api/prompts) with version history, a promotable default version, and resolve-by-reference at codegen time. A runtime's systemPrompt can be an inline string or a {prompt_id, version_id?} reference.
  • Python Code Export ("eject") -- POST /api/export-python returns a standalone, runnable Python project (agent.py, requirements.txt, Dockerfile, run.sh, .env.example, README) so an agent can run independently of the platform. (Companion to the existing CloudFormation export.)

Integration & automation

  • A2A (Agent-to-Agent) -- Deploy a runtime that serves a /.well-known/agent-card.json and exposes an SSRF-guarded call_a2a_peer tool (https-only, host allowlist + IP denylist) so agents can discover and invoke peer agents.
  • Per-Agent Identity -- Opt-in identityConfig.mode=per_agent mints a distinct least-privilege IAM execution role scoped to exactly the resources an agent is wired to (vs the shared demo role). Roles are tagged ManagedBy=agentcore-flows so cleanup is tag-scoped.
  • Agentic Retrieval -- Knowledge Base nodes support retrievalStrategy of multi_hop (LLM query decomposition + iterative retrieve), hybrid (vector + keyword, with managed-KB fallback to semantic), or reranked (wide retrieve + Claude-judge reorder) beyond simple retrieval.
  • Scheduled / Event Triggers -- Register cron, eventbridge, s3, or webhook triggers on a runtime (/api/runtimes/{name}/triggers). The target_runtime_arn is derived server-side from the owned production slot (confused-deputy guard); webhook triggers mint an owner-scoped HMAC secret in Secrets Manager. New triggers are recorded as registered (not yet firing) until the AWS resource is provisioned — the UI never falsely shows an unwired trigger as active.
  • SaaS Connectors (live OpenAPI Gateway targets) -- A curated catalog (Jira/AtlassianOauth2 + API-key Basic, Asana/PAT, Slack, GitHub, Salesforce) plus a generic OpenAPI/MCP connector, deployable as real Gateway targets. The deploy step fetches the connector's OpenAPI spec (SSRF-guarded, host-allowlisted), registers an API-key or OAuth2 client-credentials credential provider backed by an owner-scoped Secrets Manager secret, and attaches it to the gateway target. OpenAPI targets are crawled (not inline) and readiness is verified by probing the gateway's live MCP tools/list. GET /api/connectors lists the catalog for discovery. Teardown deletes the target, credential provider, and secret via the resource manifest. Live-verified: GitHub (api-key → real /user login) and Asana (PAT → real /users/me) end-to-end; Jira/Slack/Salesforce require live credentials to exercise.
  • GitOps Sync -- Store a Git PAT in an owner-scoped Secrets Manager namespace (/api/workflows/{id}/git-token) and pull a workflow spec from a repo (/api/workflows/{id}/git-sync), preserving id/owner/ACL. SSRF-guarded.
  • Human-in-the-Loop (HITL) -- Inject a human_approval tool into an agent; pending approvals land in an owner-scoped queue (GET /api/hitl/pending, POST /api/hitl/{id}/decision) surfaced in the UI inbox.
  • Team Workspaces & Sharing -- Share a workflow with viewer/editor roles (/api/workflows/{id}/share); list workspace-visible workflows (GET /api/workspaces). Owner-only mutation with escalation guards.

Enterprise governance & operations (Loom-inspired)

An enterprise governance layer modeled on awslabs/loom (opens in new tab) — scope-based access control, least-privilege automation, private networking, config-driven human oversight, and FinOps self-drive. Each item is wired end-to-end and verified against real AWS.

  • Scope-based RBAC/ABAC -- Two-dimensional authz from Cognito groups: tenant role (t-admin/t-user) × resource groups (g-admins-*/g-users-*) → a scope set; require_scopes() guards every write route. Advisory by default (RBAC_ENFORCE=false: log-would-deny), flips to fail-closed 403. Scopes never bypass owner_sub tenant isolation. See RBAC Rollout.
  • 3rd-party OIDC IdP federation -- Context-gated Cognito identity provider federates an external IdP (e.g. Okta) and maps its group claim into the platform's internal group model, so federated users inherit RBAC scopes without a separate platform account (-c oidc_client_id=… -c oidc_groups_claim=groups).
  • JIT least-privilege permission requests -- POST /api/permissions/requests files a scoped IAM-widening request; a registry-admin approves it, which PutRolePolicys a JIT-{id} inline policy scoped only to platform AgentCore* roles and validated against an action allowlist (no iam:/sts:/* escalation). Reject closes the request.
  • Config-driven HITL approval policies -- /api/settings/approval-policies define glob-matched tool/action rules (require block vs notify). On deploy, enabled policies serialize into the runtime's LOOM_APPROVAL_POLICIES env var so a guaranteed BeforeToolInvocation hook forces approval on matching tools — independent of whether the model chooses to call human_approval. Applies to both codegen and managed-harness runtimes.
  • OBO identity propagation & inspection -- GET /api/identity/token-info decodes the caller JWT (issuer/scopes/claims) for the UI; POST /api/identity/test-obo validates an RFC 8693 on-behalf-of exchange config (TOKEN_EXCHANGE / JWT_AUTHORIZATION_GRANT) without a live user token. The connector delegationMode=obo mints an AgentCore OAuth2 provider so the agent calls downstream as the end-user.
  • VPC-egress runtimes & named profiles -- /api/settings/vpc-profiles define reusable {subnet_ids, security_group_ids} bundles; a deploy referencing one by name (vpcProfile) threads networkMode=VPC into the runtime so it runs in customer private subnets. Unknown profile → 400 at deploy. Optional PrivateLink ingress IaC (NLB + VPCEndpointService + SG) ships as a downloadable add-on (privatelink-ingress.yaml (opens in new tab)).
  • Import existing runtime by ARN -- POST /api/runtime/import adopts an externally-built AgentCore Runtime as a caller-owned deployment (no codegen/deploy) so pre-existing runtimes join the platform's version/slot/cost/observability surfaces.
  • Integration gating -- When AWS Agent Registry federation is enabled, a deploy referencing an MCP/A2A integration is rejected unless each referenced integration is APPROVED in the registry (no-op when federation is off).
  • AWS Agent Registry federation -- Opt-in federation of deployed agents into the org-wide AWS-native Agent Registry (CreateRegistryRecord → SubmitRegistryRecordForApproval → approve → SearchDiscoverableRegistryRecords), auto-registered on deploy and removed on teardown. Targets the GA API: Agent Registry is its own AWS service (agent-registry-control / agent-registry clients, agent-registry:* IAM actions, recordType ∈ MCP|AGENT|CUSTOM|SKILL), so the backend requires boto3 >= 1.43.66. GET /api/registry/aws-config reports sdk_supported: false on an older bundle rather than silently degrading.
  • Cost budgets + scheduled FinOps reconciliation -- /api/cost/budgets set per owner/agent/tag monthly limits (warn + hard thresholds) evaluated against the same gen_ai.usage pipeline as the cost dashboard. A daily EventBridge sweep (cost_reconcile_step) walks every budget, sums month-to-date actual spend, and emits a BudgetBreach CloudWatch metric for any warn/over — so an idle-but-overspending agent trips an alarm even when nobody opens the dashboard.
  • Live model catalog -- GET /api/models discovers text models live from Bedrock (list_inference_profiles + list_foundation_models, filtered to TEXT/ACTIVE/ON_DEMAND) merged with a curated friendly-label overlay, replacing the hardcoded picker; falls back to a static list if Bedrock is unreachable.
  • Rich admin analytics -- GET /api/admin/audit (admin scope) rolls up audited writes into by_action/by_actor plus distinct_actors, distinct_sessions, and a chart-ready by_day time-series rendered as summary tiles + a dependency-free activity chart.
  • End-user Chat persona + admin View-as -- Consumer personas (t-user) get a streaming ChatPage instead of the builder canvas; admins get the builder and can preview the consumer experience. Persona derives purely from Cognito group scopes — no privilege change.
  • Multi-region / multi-account deploy (opt-in) -- Off by default; when enabled, a region allowlist + cross-account sts:AssumeRole into a name-scoped AgentCoreFlowsDeploymentRole (with a dry-run identity check) lets a deploy land in a registered target account.
  • Non-Bedrock provider credentials -- Selecting any non-Bedrock provider (OpenAI/Anthropic/Gemini/LiteLLM/Mistral/Groq/DeepSeek/Together/Writer) injects the provider key from an agentcore-provider/*-namespaced secret into the generated model init at deploy time (PROVIDER_API_KEY, optional PROVIDER_BASE_URL).