Enterprise samples for building, governing, and operating agentic AI on AWS — centered on Amazon Bedrock and Amazon Bedrock AgentCore. Open the Journey documentation — browsing requires no local setup or commands.
Four complementary projects that together show how enterprises move from learning to agent operations at scale. Each project is self-contained with its own deployment instructions and can be adopted independently.
Sample code — MIT-0 License. Not an AWS service, AppSec-reviewed product, or compliance attestation. Review architecture, security, and costs before use.
| Stage | Project | What It Does | Best For |
|---|---|---|---|
| 1. Learn | Workshop | Hands-on modules for building enterprise platform patterns | Platform engineers learning the foundation |
| 2. Build | Self-Service | Visual drag-and-drop canvas for designing and deploying agents | Engineers shipping agents fast |
| 3. Govern | MCP Gateway | Per-tool-call authorization with Cedar policies and Bedrock Guardrails | Security teams implementing tool governance |
| 4. Scale | Blueprint | Multi-account CDK reference with Organizations, SCPs, and CI/CD gates | Platform teams building enterprise infrastructure |
The projects share architectural concepts expressed as capability contracts. A capability contract defines the outcomes and controls that any chosen implementation must preserve, regardless of product. The table below shows what each capability does and one reference implementation — alternatives are valid when those contracts are preserved.
| Capability | Purpose | Reference Implementation |
|---|---|---|
| LLM Gateway | Governed model access with auth, routing, and attribution | AgentCore Gateway inference targets, LiteLLM |
| Tool Gateway | Authenticated MCP discovery/invocation with policy | AgentCore Gateway (AWS_IAM in the Blueprint; Cognito JWT authorizer in the Workshop, Self-Service and MCP Gateway) |
| Agent Runtime | Immutable deployable execution with identity and scaling | AgentCore Runtime |
| Agent Memory | Actor-scoped storage with encryption and retention | AgentCore Memory with CMK |
| Identity | Short-lived credentials with tenant binding | AgentCore Identity, Cognito M2M |
| Registry | Ownership, lifecycle, and approval for agents/tools | AWS Agent Registry |
| Policy Engine | Fail-closed authorization with versioning | AgentCore PolicyEngine, Cedar |
| Delivery | Reviewed source, build, scan, gates, and rollback | CodePipeline, CodeBuild, ECR |
| Observability | Correlated logs/metrics/traces with fleet views | CloudWatch, X-Ray, OAM |
| Cost | Attribution by app/agent/tenant with budgets | Allocation tags, Budgets, CUR |
Replacements: LiteLLM, AgentCore Gateway targets, and other components are reference choices. Substitutes must preserve the security, identity, tenancy, lifecycle, and evidence contracts. The support envelope applies only to the exact tested implementation.
git clone https://github.com/aws-samples/sample-ai-agent-factory.git
cd sample-ai-agent-factory/<chosen-project>
# Example: cd sample-ai-agent-factory/workshop-building-agentic-ai-platform
# Follow the project's README for prerequisites and deploymentChoose your project (folder names are exact and case-sensitive):
workshop-building-agentic-ai-platform/— Learn the patternsAgentic-ai-self-service/— Build agents visuallyenterprise-mcp-governance-gateway/— Govern tool accessenterprise-agentic-ai-platform-blueprint/— Enterprise-scale reference
Multi-module workshop composing AgentCore with an LLM Gateway (LiteLLM), MCP Gateway & Registry, and Strands Agents. Three tracks: Fast Path (1.5-2 hrs), Build the Platform (2-3 hrs), Full Journey (3-4 hrs).
Prerequisites: AWS CLI v2, basic AWS familiarity, Bedrock access. See README for supported regions.
Take it online: Open the workshop in the AWS workshop catalog, listed on AWS Builder Center.
→ workshop-building-agentic-ai-platform/README.md
Visual workflow builder for AgentCore: drag-and-drop canvas, template gallery, CloudFormation export, versioning/rollback, Cedar policy, and cost analytics.
Prerequisites: AWS CLI v2, Node.js 20+, Python 3.12+. See README for supported regions.
→ Agentic-ai-self-service/README.md
Deployable governance layer placing AgentCore Gateway in front of MCP tool servers. JWT authentication (Cognito), Cedar policy evaluation in ENFORCE mode, Bedrock Guardrail screening, and request/response Lambda interceptors.
Prerequisites: Node.js + AWS CDK, Python 3.12+, AWS credentials.
→ enterprise-mcp-governance-gateway/README.md
Multi-account CDK reference blueprint with AWS Organizations, SCPs, per-tenant Application Inference Profiles, a private VPC with interface endpoints, AgentCore Runtime/Gateway/Memory, Registry integration, CDK Pipelines with evaluation gates, and CloudWatch OAM observability.
This is an enterprise-scale reference blueprint with a bounded reviewed support envelope — not universal readiness for all environments. See the project README for tested configurations and known limitations.
Prerequisites: AWS Organizations, Node.js 20+, Python 3.12+, CDK experience.
→ enterprise-agentic-ai-platform-blueprint/README.md
All projects deploy real, billable AWS resources and every project invokes Amazon Bedrock models. The workshop runs ECS Fargate, Amazon DocumentDB, NAT Gateways, load balancers, CloudFront and an EC2-hosted IDE. The Self-Service platform is serverless (API Gateway, Lambda, Step Functions, DynamoDB, CloudFront, AWS WAF). The MCP Gateway uses Lambda, Cognito and AgentCore Gateway. The Blueprint spans AgentCore, VPC interface endpoints, CodePipeline and CloudWatch across several accounts. Tear down resources when finished using each project's cleanup commands.
Each project documents its security posture in its README. Before use:
- Review IAM policies and trust relationships
- Understand network configuration and egress patterns
- Verify data classification and retention requirements
- Check compliance obligations for your organization
See CONTRIBUTING.md for reporting security issues.
Each project documents its tested regions, prerequisites, and known limitations. The support envelope applies to the exact reference implementations tested — replacements require independent validation.
Open the Journey documentation — browsing requires no local setup or commands.
GitHub Pages publishes the site automatically from main after a repository maintainer selects GitHub Actions once under Settings → Pages. Contributors who want to preview changes locally can follow docs-site/README.md.
See CONTRIBUTING.md for contribution guidelines.
MIT-0 License. See LICENSE. Bundled subprojects retain their own licenses — see LICENSE/NOTICE files in each folder.