Tag: agents
All the articles with the tag "agents".
-
Beyond Semantic Retrieval: Metadata Filtering in Agent Memory
Semantic search finds things that sound related. Sometimes you need a WHERE clause instead — filter by priority, by date, by category. I tested metadata filtering in AgentCore Memory and found a quiet gate: custom keys silently drop unless declared as indexed keys. Here's what works and what decides whether any of it works at all.
-
Bedrock Managed Knowledge Bases as a Native Gateway Tool
AgentCore Gateway now ships a native bedrock-knowledge-bases connector that replaces the Lambda wrapper entirely. Attach the KB to the Gateway and it auto-exposes Retrieve and AgenticRetrieveStream over MCP. The constraint: it only works with Managed Knowledge Bases, not customer-managed ones.
-
AgentCore Registry Is a Governed Catalog for Agent Interfaces
Hardcoded runtime ARNs are the visible pain, and Registry does fix them — but agent discovery is fundamentally a governance problem, not a routing problem.
-
An Agent That Can Pay for Its Tools
Payment is not a tool call—it is a governed financial action. An agent that pays requires user consent, credential isolation, session budgets, policy checks, and a proof path the model cannot bypass.
-
Harness vs. Runtime: When to Graduate
Harness gives you a working agent in 20 seconds with 25 lines of configuration. Runtime takes 398 lines of code. Both run on the same compute. The graduation trigger that matters is not hooks or custom loops — it's per-user outbound identity.
-
Build a Regression Suite for an Agent
I built a test suite for a support agent and found three classes of bugs that escape human review, output-quality scoring, and code review — and the regressions they taught me how to catch permanently.
-
Who May Call What: Per-User Authorization on AgentCore With Cedar
A valid token proves who is calling. AgentCore Policy is a Cedar engine on the gateway that answers who-may-call-what per user, per tool, per argument — default-deny, before the tool runs. I wired one up and watched it allow, then deny, the same call.
-
Two Ways to Authorize an Agent Tool: IAM or OAuth on Amazon Bedrock AgentCore Gateway
When you expose a tool to agents through an AgentCore Gateway, the real decision is who is allowed to call it — SigV4/IAM for callers inside your AWS boundary, or a JWT authorizer for everyone else. Here are the three patterns and when each fits.