SYSTEM Cited by 3 sources
Amazon Bedrock Guardrails¶
What it is¶
Amazon Bedrock Guardrails is a configurable safety layer that wraps foundation-model invocations and agent behavior, filtering both inputs and outputs against declarative policies. In agentic architectures it sits in front of every agent so that unsafe or out-of-scope behavior is blocked at the runtime boundary rather than left to prompt-level instructions.
Enforced controls¶
In the clinical-trial screening architecture, all three agents operate behind Bedrock Guardrails, which enforce (Source: sources/2026-08-19-aws-ai-powered-clinical-trial-eligibility-and-safety-using-amazon-bedrock-agentcore):
- PII/PHI filtering — protect patient health information.
- Content-safety controls — help prevent clinically inappropriate outputs.
- Grounding checks — keep responses anchored in retrieved evidence rather than model parametric knowledge (a direct mitigation for hallucination).
- Denied-topic boundaries — keep agents within their screening scope.
Grounding checks and denied-topic boundaries make the guardrail a scope-limiter, not just an output scrubber: they constrain what the agent may reason about, complementing audit and evaluation layers in the system's defense-in-depth posture.
Relation to other Bedrock safety surfaces¶
Guardrails filter content probabilistically; the neurosymbolic Bedrock Guardrails automated reasoning checks surface verifies factual claims against a formal policy. Both differ from AgentCore capability enforcement, which restricts what an agent can do rather than what it can say.
Embedding in AgentCore Policy (2026-08-21)¶
Beyond wrapping model invocations directly, Guardrails can be embedded inside AgentCore Policy so that Cedar policies invoke guardrail safeguards — prompt-attack detection, content filtering, and sensitive-information blocking — at the gateway boundary during tool execution rather than only at the model I/O boundary (Source: sources/2026-08-21-aws-how-agentflo-built-ai-sales-agents-with-amazon-bedrock-agentcore-part-2). In AgentFlo this makes Guardrails the content-safety element of a broader three-layer guardrail posture (pre-turn Fargate checks → Gateway/Policy + Guardrails during tool execution → post-turn output filters).
Seen in¶
- sources/2026-08-19-aws-ai-powered-clinical-trial-eligibility-and-safety-using-amazon-bedrock-agentcore — PII/PHI, content-safety, grounding, and denied-topic controls wrapping the three screening agents
- sources/2026-08-21-aws-how-agentflo-built-ai-sales-agents-with-amazon-bedrock-agentcore-part-2 — embedded in AgentCore Policy so Cedar rules invoke prompt-attack detection, content filtering, and sensitive-info blocking at the gateway boundary; the content-safety layer of AgentFlo's three-layer guardrails.
- sources/2026-08-26-aws-closing-the-ai-agent-trust-gap-with-graduated-autonomy — in graduated autonomy, Guardrails complements Policy for model-level content safety (harmful-content filtering, sensitive-info masking) independent of the agent's autonomy tier — the content-safety plane alongside tier-based tool authorization.
- sources/2026-09-11-aws-from-zero-shot-forecast-to-purchase-order-with-agentcore — described as a mandatory control, not an optional add-on: the Supervisor agent (which interprets natural-language requests and makes branching decisions that ultimately determine order quantities) runs behind Guardrails enforcing content filtering, denied-topic policies, and grounding validation against the structured tool outputs — preventing it from hallucinating constraint overrides or generating purchase decisions outside its authorized scope.