Protected agent runtime

Protected agent runtime An architecture diagram generated by Archify. Trusted channel · Web, messaging or API · Architecture component Trusted channel Web, messaging or API Agent runtime · Identity + request contract · AWS runtime boundary Agent runtime Identity + request contract Input boundary · ApplyGuardrail · AWS runtime boundary · fail closed Input boundary ApplyGuardrail fail closed Foundation model · Amazon Bedrock · AWS runtime boundary Foundation model Amazon Bedrock Output boundary · ApplyGuardrail · AWS runtime boundary · before persistence Output boundary ApplyGuardrail before persistence Safe response · Approved channel output · Architecture component Safe response Approved channel output Tool authorization · Schema + business rules · AWS runtime boundary · deterministic Tool authorization Schema + business rules deterministic External systems · Authorized operations only · Architecture component External systems Authorized operations only Sanitized telemetry · Input + output decisions · AWS runtime boundary · no payloads Sanitized telemetry Input + output decisions no payloads untrusted input candidate response validated operation sanitized events AWS runtime boundary Legend Backend Cloud Security External