Amazon Bedrock
Educational simulation No cloud connection
0 of 8 objectives complete Score: 0 / 100
RCW guided build

Secure generative AI support assistant

Design, build, test, and approve a grounded assistant with governance controls from the first decision through operations.

Intermediate · 60–90 min
This is an interactive console simulation.

No AWS account, credentials, network calls, or real cloud charges are used. Product names appear only to teach the workflow; no vendor logo is used.

Scenario

Build the RCW IT policy assistant

Employees need reliable answers from approved IT policies. Your assistant must cite its source, resist prompt injection, protect personal data, and require a person to approve ticket creation.

  • Select a cost-aware foundation model
  • Apply Guardrails to input and output
  • Create a Knowledge Base with synthetic policy documents
  • Prepare an Agent with a gated action group
  • Evaluate grounding, safety, authorization, and cost controls
Reference architecture

Governed retrieval and action flow

Simulated
Amazon Bedrock lab architecture A user connects to a protected application. Guardrails protect an Agent that uses a foundation model, a Knowledge Base with S3 and a vector store, and a human-approved Lambda action. CloudTrail and CloudWatch provide audit evidence. USEREmployee SAFEGuardrails AGENTBedrock Agent MODELNova Lite RAGKnowledge Base APPROVETicket action S3 + vector store + KMSLambda + human gate
Objective 1 · Govern and map

Record the use case and data boundary

Complete this intake before opening model access. This creates the scope and accountability evidence for the lab.

10 points
Approved purpose
Required attestations
Framework intent: NIST AI RMF Govern/Map and ISO/IEC 42001 Plan.
RCW IT Training

Amazon Bedrock lab guide

Goal

Build a secure, source-grounded IT policy assistant and produce governance, safety, evaluation, and operations evidence.

  1. Govern and mapOn Overview, record your name, accountable owner, approved purpose, data class, and attestations.
  2. Select the modelChoose Amazon Nova Lite with single-Region on-demand inference for this cost-aware, data-locality-conscious use case.
  3. Publish a GuardrailSet content filters to High, prompt attack detection to High, denied topics, sensitive-information controls, and grounding threshold 0.75.
  4. Create and sync the Knowledge BaseUse the least-privilege role, approved S3 source, fixed chunking, Titan Text Embeddings V2, OpenSearch Serverless, KMS, public-access blocking, and private path review.
  5. Prepare the AgentAttach the Knowledge Base and Guardrail. Use a ticket-only role and require confirmation.
  6. Configure evidenceEnable CloudTrail, selected data events, encrypted invocation logs for synthetic content, 30-day retention, alarms, and budget alerts.
  7. Test and evaluateRun all four playground chips, then create the versioned RAG and safety evaluation job.
  8. Approve a limited pilotDocument residual risk, rollback, incident handling, and the next review date.
Never enter a real secret

The simulator is local, but safe habits matter. Use only the supplied synthetic content and prompts.

Open complete guide, troubleshooting, and cleanup
Human approval required

Create P1 support ticket?

The Agent proposes calling createTicket with the following validated parameters:

Severity
P1
Title
Critical policy incident
Tool identity
TicketCreateOnlyRole
!
This action changes another system.

Review the scope and approve only the single requested operation.

Lab complete

Secure Bedrock workflow approved

100/ 100
All objectives passed

Amazon Bedrock End-to-End Lab Champion

You completed the complete governed workflow.

  • Model and architecture decision
  • Guardrails, RAG, and Agent controls
  • Adversarial testing and human approval
  • Evaluation, logs, retention, and release evidence

Issued by RCW IT Training · Signed by Pradeep Raju · Educational achievement certificate

Saved