Design, build, test, and approve a grounded assistant with governance controls from the first decision through operations.
Intermediate · 60–90 min
i
This is an interactive console simulation.
No AWS account, credentials, network calls, or real cloud charges are used. Product names appear only to teach the workflow; no vendor logo is used.
Scenario
Build the RCW IT policy assistant
Employees need reliable answers from approved IT policies. Your assistant must cite its source, resist prompt injection, protect personal data, and require a person to approve ticket creation.
✓ Select a cost-aware foundation model
✓ Apply Guardrails to input and output
✓ Create a Knowledge Base with synthetic policy documents
✓ Prepare an Agent with a gated action group
✓ Evaluate grounding, safety, authorization, and cost controls
Reference architecture
Governed retrieval and action flow
Simulated
Objective 1 · Govern and map
Record the use case and data boundary
Complete this intake before opening model access. This creates the scope and accountability evidence for the lab.
10 points
Amazon Bedrock/Model catalog
Foundation models
Model catalog
Compare available models against quality, latency, cost, licensing, and data-residency needs.
Not selected
!
Model governance checkpoint
Production teams should review model cards, acceptable-use requirements, provider terms, Region availability, EULAs, and cross-Region routing before enabling access.
3 models in training catalog
A
Recommended for this lab
Amazon Nova Lite
Amazon
TextConverseOn-demand
Use case
Fast, cost-aware support Q&A
Relative latency
Low
Relative cost
$
A
Amazon Nova Pro
Amazon
TextMultimodalOn-demand
Use case
Complex reasoning and analysis
Relative latency
Medium
Relative cost
$$$
A
Amazon Titan Text Premier
Amazon
TextLegacy comparison
Use case
General text generation
Relative latency
Medium
Relative cost
$$
✓
Model decision recorded
Amazon Nova Lite · Single-Region on-demand · Model card and terms reviewed for training.
Amazon Bedrock/Guardrails/Create
Build
Create guardrail
Apply consistent safety, privacy, and policy controls to prompts and model responses.
No draft
1 Configure2 Review3 Create and publish
Amazon Bedrock/Knowledge bases/Create
Build
Create knowledge base with vector store
Ingest approved documents, transform them into embeddings, and retrieve source-grounded context.
Orchestrate the selected model, trusted knowledge, and a tightly scoped action with human oversight.
DRAFT
Amazon Bedrock/Playgrounds/Agent test
Test
Agent playground
Verify grounded answers, injection resistance, PII protection, and approval-gated actions.
0 / 4 tests
Test rcw-it-helpdesk-agentAlias: lab-v1 · synthetic session
AI
Lab assistant
Prepare the model, guardrail, Knowledge Base, and Agent, then run all four required tests above.
Objective 6
Required test evidence
10 points
○
Grounded answerAnswer includes a source citation.
○
Prompt injectionRetrieved or direct hostile instructions are blocked.
○
PII disclosureSensitive data request is denied or masked.
○
Excessive agencyTicket executes only after human approval.
Amazon Bedrock/Settings/Logging and monitoring
Operate
Logging, monitoring, and cost controls
Create traceable evidence without retaining sensitive content longer than required.
Not configured
!
Invocation logs can contain full prompts and responses.
Payload logging is enabled here only because every prompt and document is synthetic. Production use requires privacy review, least-privilege access, encryption, destination controls, and documented retention.
Evidence preview
Recent simulated events
Time
Event
Identity
Resource
Result
Amazon Bedrock/Model evaluation/Create job
Measure
Create RAG and safety evaluation
Use a versioned benchmark to measure usefulness and safety before release.
No job
Job completed
rcw-it-policy-eval-v1 results
PASS
0.94Retrieval relevance
0.97Groundedness
100%Safety tests
0Unauthorized actions
✓
All configured thresholds passed.
This result supports the release decision but does not prove legal compliance, eliminate model risk, or replace continuous monitoring.
Amazon Bedrock/Compliance review
Manage and approve
Production-readiness review
Inspect the evidence, document residual risk, and make a human release decision.
Not ready
Control evidence
Automated readiness checks
0 / 8 ready
○
Governance and data scopeOwner, purpose, classification, and impact attestations recorded.
Pending
○
Model decisionCost-aware model and single-Region inference selected.