Related AWS services
AWS service | Role in this architecture |
|---|---|
Multi-account structure, OU hierarchy, and organizational policy management | |
Account provisioning, guardrails, and landing zone governance | |
Foundation model access and inference | |
Managed agent runtime infrastructure including tool gateway, MCP hosting, memory, and identity | |
Cross-account metrics, logs, and observability dashboards | |
Distributed tracing for agent execution paths across service boundaries | |
Unified operational dashboards aggregating data from all source accounts | |
Metrics aggregation for containerized agent workloads | |
Threat detection across all platform accounts | |
Centralized security findings and compliance posture management | |
Sensitive data discovery in conversation logs and agent outputs | |
Data lake storage, RAG knowledge base documents, and conversation logs | |
Data pipeline orchestration between raw and processed data zones | |
Fine-grained access control for data lake datasets | |
Shared Docker registry for agent container images | |
CI/CD pipeline orchestration for agent promotion | |
Build, test, and deployment execution within the pipeline | |
Secure cross-account service connectivity without public internet traversal | |
Network connectivity for landing zone integration | |
Cost monitoring and alerting at account and OU level | |
Centralized human access management across all platform accounts | |
Workload-level identity management for agent authentication | |
Encryption key management for data at rest and in transit |