Start

Which project fits?

One table for the whole decision across the four samples for agentic AI on Amazon Bedrock and Amazon Bedrock AgentCore: stage, audience, validated regions, topology, tooling, time, cost, teardown and status. Every value links to the repository line it comes from, and gaps say so.

Compare the four projects

Columns are the projects and rows are the facts. On a narrow screen, scroll the table sideways; the fact labels stay in view.

Comparison of the four projects. Each fact links to its source in the repository.
FactBuilding an Enterprise Agentic AI Platform1. LearnAgentCore Visual Workflow Platform2. BuildEnterprise MCP Governance Gateway3. GovernEnterprise Agentic AI Platform Blueprint4. Scale
Stage1. Learn2. Build3. Govern4. Scale
Best forPlatform and ML engineers who want to understand and build the foundation.Engineers who want to build and ship agents fast on top of AgentCore.Platform and security engineers who need per-tool-call authorization and audit.Platform and security engineers building enterprise-scale infrastructure.
Validated regionsAWS-run events: us-west-2. Self-paced: us-west-2 (default), us-east-1, or eu-west-1. Other regions are not supported. source for validated regions, Workshop (opens in new tab)The contentspec.yaml deployableRegions list is us-west-2, us-east-1 and eu-west-1. Workshop Studio events provision the account in us-west-2 (content/introduction/getting-started/aws-event.en.md).Any AWS region; us-east-1 is the default source for validated regions, Self-Service (opens in new tab)Outside us-east-1 the WAF web ACL is REGIONAL on the Cognito user pool and the CloudFront distribution runs without an edge ACL. APAC regions may need the model ID set explicitly.us-west-2 by default; configurable; no tested-regions list is published source for validated regions, MCP Gateway (opens in new tab)Validated in eu-west-1; SCP allow-list us-west-2, us-east-1, eu-west-1 source for validated regions, Blueprint (opens in new tab)The SCP region allow-list comes from PLATFORM_APPROVED_REGIONS in packages/platform-baselines/src/approved-regions.ts. A different Region is a new validation target, not a configuration-only substitution.
Account topologySingle AWS account; a dedicated, disposable account is recommended source for account topology, Workshop (opens in new tab)Single account and single region per deployment; several deployments can coexist in one account (dev and prod, or two regions) source for account topology, Self-Service (opens in new tab)Multi-region and multi-account deploy is opt-in and off by default (docs/ENTERPRISE_CAPABILITIES.md); a cross-account role template ships as docs/cross-account-deploy-role.json.Single account; one gateway stack plus two optional connector stacks source for account topology, MCP Gateway (opens in new tab)Multi-account: Management, Platform, and Workstream account roles (nonproduction and production may be separate accounts) source for account topology, Blueprint (opens in new tab)
Infrastructure as codeCloudFormation, run by the self-paced deploy script; Module 4 deploys the FAST agent with the AWS CDK from inside the IDE source for infrastructure as code, Workshop (opens in new tab)AWS CDK (Python) run through npx; serverless stack of API Gateway, Lambda, Step Functions, DynamoDB, S3 and CloudFront source for infrastructure as code, Self-Service (opens in new tab)AWS CDK (Python) with AWS::BedrockAgentCore L1 constructs; CDK CLI pinned to 2.1129.0 source for infrastructure as code, MCP Gateway (opens in new tab)AWS CDK (TypeScript) with CDK Pipelines; 12 service control policies; Python and shell utilities source for infrastructure as code, Blueprint (opens in new tab)
What it deploysFive CloudFormation stacks: LLM Gateway, MCP Registry, Tools Gateway, AgentCore, Code Editor IDE source for what it deploys, Workshop (opens in new tab)Serverless stack: API Gateway, Lambda, Step Functions, DynamoDB, S3 and CloudFront, plus a Cognito user pool and a WAF web ACL source for what it deploys, Self-Service (opens in new tab)AgentCore Gateway and Cedar policy engine, four Lambdas (two interceptors, two targets), a Cognito user pool, a Secrets Manager secret, a customer-managed KMS key, SSM parameters and a Bedrock Guardrail source for what it deploys, MCP Gateway (opens in new tab)A multi-account reference: AgentCore Runtime, Gateway, Identity, Memory, Policy, Registry and Evaluations; Bedrock with Guardrails and application inference profiles; Cognito, IAM Identity Center and Cedar; Organizations SCPs; CodePipeline, CodeBuild and CodeConnections; VPC with endpoints; Lambda; KMS, S3, DynamoDB, Secrets Manager and ECR; CloudWatch, OAM and X-Ray; CloudTrail, Config, Security Hub, GuardDuty and Inspector; Budgets and CUR source for what it deploys, Blueprint (opens in new tab)README section 4 calls this the deployable and live-tested reference implementation, not a universal mandatory product list. Not every optional construct is inside the Ireland support envelope.
First deployAbout 30 to 45 minutes for the self-paced deploy script (five CloudFormation stacks) source for first deploy, Workshop (opens in new tab)The self-paced guide (content/introduction/getting-started/self-service.en.md) notes that the Registry stack alone takes 20 to 30 minutes. At an AWS event the account arrives pre-provisioned, so there is nothing to deploy.Roughly 15 to 20 minutes for a first-time deploy source for first deploy, Self-Service (opens in new tab)About 5 minutes for the five quickstart steps; the gateway stack itself takes about 2 minutes source for first deploy, MCP Gateway (opens in new tab)not documentedThe README documents the deployment sequence (sections 6.1 to 6.6: one-time setup, configuration, scoped bootstrap, Platform pipeline, Workstream onboarding, validation) but no duration.
Hands-on time1.5 to 4 hours depending on the track source for hands-on time, Workshop (opens in new tab)not documentedThe README documents the deploy time only and publishes no hands-on figure.About 5 minutes for the quickstart; the governance walkthrough has no stated duration source for hands-on time, MCP Gateway (opens in new tab)not documentedThe README lists organizational prerequisites (a Platform product owner, an account-vending process, governance and approval policies) but gives no time figure.
CostAbout $15 to $30 for a one-day run in us-west-2 (workshop estimate) source for cost, Workshop (opens in new tab)At an AWS-run event the account is provided and the cost is covered. Cost accrues per hour whether or not the environment is in use.About $0.02 to $0.39 per month for the platform infrastructure at low to moderate usage (docs/COSTS.md estimate, us-east-1 list prices) source for cost, Self-Service (opens in new tab)Excludes the WAF web ACL that infra/stacks/platform_stack.py always creates, which is billed separately and for which the repository publishes no figure, and all agent inference, AgentCore and vector-store usage.not documentedThe README lists what the stack creates (AgentCore Gateway and policy engine, four Lambdas, a Cognito user pool, a Secrets Manager secret, a customer-managed KMS key, SSM parameters, and a Bedrock Guardrail) but publishes no cost figure.not documentedREADME section 8 describes a two-layer cost model (shared Platform cost and Workstream cost) and recommended controls such as allocation tags, budgets and CUR reconciliation, but publishes no figure.
TeardownFollow the workshop Cleanup module for Module 4 and Module 3a resources, then run ./deploy-cfn.sh destroy from the workshop folder. At an AWS event Workshop Studio cleans up the account automatically. source for teardown, Workshop (opens in new tab)Run ./scripts/cleanup.sh (prompts for confirmation). It deletes every AgentCore resource the platform created, empties the S3 buckets and runs cdk destroy. source for teardown, Self-Service (opens in new tab)Disconnect the MCP client first, then cdk destroy EnterpriseMcpGatewayStack (destroy the two connector stacks first if you deployed them). CloudWatch log groups are not removed. source for teardown, MCP Gateway (opens in new tab)Run python3 scripts/final_teardown.py per account role (workstream, then platform, then management), first as a dry run and then with --apply; verify with scripts/residue_inventory.py source for teardown, Blueprint (opens in new tab)
StatusPublished on AWS Builder Center (Workshop Studio); last published 2026-08-18 source for status, Workshop (opens in new tab)Publication state and date come from the Workshop Studio catalog entry, not from the repository, which holds no publish record to quote.Version 0.1.0 released 2026-07-17, with unreleased changes recorded in CHANGELOG.md source for status, Self-Service (opens in new tab)Sample and demonstration stack; not hardened for production source for status, MCP Gateway (opens in new tab)Version 1.0.0 (README badge); two open advisories (issues #29 and #30) source for status, Blueprint (opens in new tab)

Prerequisites per project are on the Prerequisites page; cost notes and teardown procedures are under Costs and cleanup.

Four paths through the repository

Each path starts on one project and says who it is for, what you have at the end, and how long the first result takes.

By role

  • AI/ML engineer who wants a running agent today: Build an agent visually. The Self-Service platform deploys in one command and ships six templates to start from.
  • Platform engineer learning the foundation: Learn and stand up the platform. The workshop builds the LLM Gateway, registries, and Tools Gateway module by module.
  • Security engineer implementing tool governance: Govern every tool call. The MCP Gateway shows Cedar ENFORCE, interceptors, and a Bedrock Guardrail on a live endpoint with tests.
  • Solutions architect comparing the pieces: Learn and stand up the platform. The workshop's longest track covers every module end to end, including the agent.
  • Platform team planning a multi-account rollout: Evaluate the enterprise blueprint. The Blueprint documents account roles, SCPs, pipelines, evidence gates, and a bounded support envelope.

By time available