SYSTEM Cited by 8 sources
Bedrock AgentCore¶
What it is¶
AWS's agent-runtime service for deploying agentic AI systems inside mechanically-enforced capability envelopes. AgentCore mediates agent actions — tool calls, outputs, state transitions — against a customer-authored specification, and rejects anything outside the envelope.
We need to specify the envelopes in which the agents can operate, use a system like Bedrock AgentCore to restrict the agents to those envelopes, and then reason about the composition of their behavior to ensure that bad things don't happen and good things eventually do happen. — Byron Cook (Source: sources/2026-02-17-allthingsdistributed-byron-cook-automated-reasoning-trust-ai)
Why it exists¶
Pure prompt-level instructions ("don't do X") don't generalize to production at AWS scale. In regulated / high-stakes domains the agent must not be able to do X — capability restriction has to be enforced by the runtime, not guidance to the model.
The pattern AgentCore implements is envelope-and-verify:
- Specify the envelope (often concepts/lightweight-formal-verification).
- AgentCore mechanically restricts the agent to the envelope.
- automated-reasoning over the composition of envelopes proves global invariants.
Where it sits in the AWS AI-trust stack¶
| Layer | Responsibility | AWS product |
|---|---|---|
| Spec authoring | Write the envelope / correctness spec | systems/kiro |
| Agent capability enforcement | Restrict what the agent can do | AgentCore (this page) |
| Output correctness verification | Restrict what the agent can say | systems/bedrock-guardrails-automated-reasoning-checks |
| Composition reasoning | Prove global invariants across agents | automated-reasoning over envelopes |
Together these form the full neurosymbolic production stack Cook describes for agentic banking, healthcare, and regulatory domains.
Envelope examples¶
From the interview:
- The bank's agentic system will not share information between its consumer and investment wings. (Information-flow invariant.)
- A refund may only follow a verified authentication in the same session. (Temporal / ordering invariant.)
- The trading agent may never execute an order without knowing the user's current risk envelope. (Epistemic invariant.)
Envelopes are the spec. AgentCore is where the spec becomes enforceable runtime behavior.
Relation to post-inference verification¶
post-inference-verification (via systems/bedrock-guardrails-automated-reasoning-checks) filters outputs. AgentCore filters actions. Most production systems want both:
- An output-filter alone lets the agent take bad actions and only catches the downstream statement of them.
- A capability-filter alone still permits outputs inside the envelope that are factually wrong.
Stacked, they cover both sides.
Caveats¶
- Architecture-level description only. Cook's interview does not disclose AgentCore's internal design: mediation mechanism, policy language, throughput/latency numbers, or how it integrates with other Bedrock surfaces. Treat this page as a conceptual stub that will thicken as a dedicated product/architecture post lands.
- The "compose and reason" promise is research-adjacent. Multi-agent composition reasoning at production scale is still a live research frontier; Cook's framing is aspirational as well as shipping.
Named sub-surfaces (2026-04-23)¶
The IBM + AWS KYC architecture post (2026-04-23) is the first wiki source to name four distinct AgentCore sub-surfaces in one place, moving AgentCore from one product to a platform of four cooperating services:
- AgentCore Runtime — native orchestration, session management, automatic context preservation across asynchronous processing workflows. Hosts the Supervisor + sub-agents.
- systems/agentcore-memory — built-in feature managing session state and shared memory across sub-agents; the scratchpad substrate for multi-agent KYC case execution.
- systems/agentcore-gateway — OpenAPI-schema-driven tool invocation + auth + request/response validation + retry manager. Declarative bridge from agent action to external API without per-tool glue code. Implements openapi-schema-as-agent-tool-contract.
- systems/agentcore-identity — per-agent authentication + authorization of tool invocations and Knowledge Base access. Prevents sub-agents from invoking tools outside their declared scope, even under prompt injection.
The KYC post frames AgentCore as the runtime for "asynchronous invocation patterns where MSK consumers trigger AgentCore processing without blocking, enabling sub-5-minute processing times while handling thousands of concurrent KYC requests." See async-agent-invocation-over-kafka for the MSK → Lambda → AgentCore async loop.
(Source: sources/2026-04-23-aws-modernizing-kyc-with-aws-serverless-solutions-and-agentic-ai.)
AG-UI handler for adaptive interfaces (2026-09-29)¶
The adaptive-interfaces reference architecture
adds a new AgentCore sub-component to the wiki: the AG-UI handler — "a
specialized component within AgentCore that manages AG-UI
protocol events, formatting agent responses as standardized events for dynamic
UI rendering." It sits between the swarm and the frontend and converts
agent output into the AG-UI typed-event stream (TEXT_MESSAGE_CONTENT,
STATE_DELTA, TOOL_CALL_*, UI_COMPONENT_SPEC) delivered over SSE.
In this architecture AgentCore plays its familiar roles in a new (adaptive-UI) context:
- AgentCore Gateway is the orchestration layer — routing agent requests, managing sessions, coordinating the multi-agent workflow, and load-balancing across runtime instances. The Lambda AG-UI handler invokes agents through the Gateway.
- AgentCore Runtime provides the execution environment, running the Strands Swarm with an isolated runtime instance per agent type (Image Analysis / Clinical Reasoning / Reporting).
- The whole thing is deployed on AgentCore for its managed runtime: up to 8-hour long-running tasks, asynchronous tool execution, and native CloudWatch integration, positioned as ideal for production with minimal operational overhead.
This is the wiki's first instance of AgentCore driving an adaptive frontend (via the AG-UI handler) rather than only back-end tool orchestration.
Seen in¶
- sources/2026-10-01-aws-accelerating-airline-retailing-innovation-datalex-modernization — agentic AI layered onto a modernized system via AgentCore + MCP Gateway. Datalex's proof-of-concept conversational booking interface uses a Bedrock AgentCore orchestrator coordinating three specialized agents (authentication, data retrieval, reporting); each reaches existing Datalex REST APIs through the AgentCore Gateway, with an MCP Gateway (MCP as integration proxy) translating the agent's natural-language interface to REST, secured by Cognito.
- sources/2026-02-17-allthingsdistributed-byron-cook-automated-reasoning-trust-ai — named as the capability-restriction substrate for agentic AI in high-stakes domains; the "envelope enforcer" half of Cook's three-part envelope-and-verify architecture.
- sources/2026-04-23-aws-modernizing-kyc-with-aws-serverless-solutions-and-agentic-ai — thickest on-wiki disclosure of AgentCore as a named platform with four sub-surfaces (Runtime + Memory + Gateway + Identity); hosts a Supervisor + five KYC sub-agents with MSK-backed async invocation and OpenAPI-declared tool contracts.
- sources/2026-08-19-aws-ai-powered-clinical-trial-eligibility-and-safety-using-amazon-bedrock-agentcore — Runtime hosts three phase-scoped clinical-trial screening agents (pre-screening, detailed screening, site/enrollment) with MCP Gateway tools, session memory, identity-based least-privilege access, a built-in code interpreter (eGFR/BMI), and an AgentCore Evaluations LLM-as-judge layer gating human review.
- sources/2026-08-20-aws-how-agentflo-built-ai-sales-agents-with-amazon-bedrock-agentcore —
Runtime hosts AgentFlo's Strands sales agents in
per-session microVMs (concepts/micro-vm-isolation, stateful up to 8
hours); Gateway brokers MCP tool calls; Policy
(Cedar) enforces deterministic tool authorization; Observability + Data
Firehose capture interactions. Two CLI commands (
agentcore configure/agentcore launch) take a local agent to a production/invocationsendpoint. - sources/2026-08-21-aws-how-agentflo-built-ai-sales-agents-with-amazon-bedrock-agentcore-part-2 — AgentFlo Part 2 exercises more AgentCore surfaces for Trust & Reliability: Runtime microVM session isolation as the multi-tenant substrate; AgentCore Observability emitting per-turn traces (model latency, tool sequences, token usage, error rates) into CloudWatch with per-merchant/agent/conversation cost attribution; Runtime as the reasoning stage of a decoupled STT→reason→TTS voice pipeline; and a roadmap for server-side tool execution (single Bedrock Responses API call passing an AgentCore Gateway ARN as an MCP connector, ~30% lower latency — server-side-tool-execution) plus BidiAgent real-time voice on AgentCore WebRTC + Kinesis Video Streams.
- sources/2026-08-26-aws-closing-the-ai-agent-trust-gap-with-graduated-autonomy — AgentCore is the substrate for graduated autonomy: Runtime hosts the agent, Gateway + Policy (Cedar, forbid-wins) enforce tier→permission mapping out of band, Evaluations power the delivery gate, and DynamoDB stores trust state + TPAOS audit records. Concrete instantiation of Cook's "specify the envelope, use AgentCore to restrict the agents to those envelopes" thesis, with the envelope now earned via a rolling trust score.
- sources/2026-09-11-aws-from-zero-shot-forecast-to-purchase-order-with-agentcore —
the one-boundary-per-service framing: each of AgentCore's six sub-services maps
to a single production concern rather than being adopted wholesale. Runtime = where
agents run (per-session microVM, up to 8-hour sessions, scale-to-zero between runs);
Gateway + Policy = what
writes reach external systems (Cognito JWT + Cedar);
Memory = what the agent carries across sessions (semantic + user-preference
strategies; summary strategy deliberately unused);
Observability = why a decision was made (auto-traced to
CloudWatch); Evaluations = whether
the agent still behaves after deployment. Hosts a four-agent inventory-replenishment
pipeline (Supervisor + Preprocessing + Forecasting + Reporting) on the
Strands SDK;
agentcore deploywraps each invocation in an isolated microVM and streams traces automatically. Canonical wiki instance of patterns/deterministic-tool-vs-llm-judgment — only one of eight tools crosses the Gateway boundary. - sources/2026-09-17-aws-how-dhi-group-accelerates-generative-ai-workloads-from-idea —
AgentCore as the orchestration layer for a cross-account MCP integration (DHI Group
case study). The winning hackathon architecture uses Agent Runtime for session
management + reasoning loops, Gateway as an MCP gateway
with IAM authentication and semantic search for tool
discovery/routing,
McpBearerTokenfor authenticating to downstream MCP servers, and memory (CJRecruiterAgent) to persist recruiter preferences across turns. The agent (Claude 3.5 Haiku on Bedrock) lives in the AgileATS account and reaches an MCP Server Lambda in the ClearanceJobs account over MCP-over-HTTPS with bearer auth + tenant-ID headers — a concrete instance of patterns/mcp-as-centralized-integration-proxy. - sources/2026-09-29-aws-build-adaptive-ai-interfaces-with-the-ag-ui-protocol-agent-s-ff0dbca9 — AgentCore as the substrate for an adaptive AI interface. Introduces the AG-UI handler sub-component (formats agent responses as AG-UI events for dynamic UI rendering); Gateway orchestrates/routes/load-balances; Runtime hosts the Strands Swarm with an isolated instance per agent type. Deployed for AgentCore's managed runtime (up to 8-hour tasks, async tool execution, native CloudWatch). Worked HIPAA radiology assistant: React AG-UI client → SSE → orchestrator → three-agent swarm → Bedrock/Claude Sonnet, with Nova Act writing to a legacy RIS/EMR.