Skip to content

AI agents on AWS

AI agents on AWS: from demo to production

An agent that impresses in a demo and an agent that holds up in production are not the same object. The second one needs controlled access, scoped tools, evaluation before go-live and a measured cost. That foundation is what we build, on AWS.

01 The gap

Why an agent that works in a demo doesn't reach production.

The gap almost never comes from the model. It comes from everything around it that doesn't exist yet on demo day.

Access that's far too broad

In a demo, the agent runs with admin rights. In production it needs its own identity, bounded permissions and a trace of every action it takes.

Tools that aren't scoped

Wiring an agent to many tool servers widens the attack surface. You have to decide what is read-only, what requires confirmation, and what stays off limits.

No evaluation

Without a reference set of cases and explicit success criteria, nobody can say whether a new version of the agent is better or worse than the last one.

Unmeasured cost

An agent's cost isn't a model invoice: it depends on call volume, context length and retries. Without per-use-case measurement, the bill surprises you at scale.

02 The foundation

What we put in place on AWS.

Six building blocks, assembled to fit your context. They live in your own AWS accounts: the foundation stays yours, engagement after engagement.

Models and routing

Claude on Amazon Bedrock, with explicit routing: the most capable model where difficulty warrants it, a faster one elsewhere. Data stays in the region you choose.

Execution and hosting

Amazon Bedrock AgentCore to run agents with isolated sessions, reproducible deployment and native integration with the rest of your AWS account.

Identity and access

A dedicated IAM identity per agent, framed by a permissions boundary, with explicit cross-account access when the agent must reach beyond its home account.

Tools and connectors

MCP connectors into your existing systems (monitoring, ITSM, CMDB, business data), read-only by default, with domain separation and scoped permissions.

Evaluation

A reference set of cases and success criteria defined with your teams, replayed on every version. An agent only ships if it holds them.

Observability and FinOps

Traceability of every action, a registry of agents in service, and real cost tracking per use case along with its footprint.

03 In production

A real case: the agents in Engie's NOC.

A multi-agent platform on Claude and Amazon Bedrock, adopted by the network operations centre teams, with around fifteen connectors into the existing ecosystem.

< 30 s
to triage an alert, against 10 to 15 minutes manually
≈ 50 %
of recurring incidents resolved autonomously
~ 2.5 FTE
of recurring load absorbed, redeployed to engineering

Autonomy only covers deterministic, reversible cases validated by the team. On sensitive cases, a human stays in the loop.

Read the full case study
05 Frequently asked

What people ask us about AWS agents.

Do we need to be on AWS already to work with you?

It's our main ground and where we move fastest, because we know Bedrock, AgentCore and the IAM identity model in depth. We also work in hybrid and multi-cloud environments, but the foundation described here is the one we master best.

What's the difference between an agent and a chatbot?

A chatbot answers. An agent acts: it queries your systems, correlates information and executes actions. That is precisely what demands a frame — dedicated identity, bounded permissions, traceability and reversibility — that a chatbot never needs.

How do you guarantee an agent won't do something reckless?

By construction, not by trust. Autonomy is granted only on deterministic, reversible cases validated by your teams. Tools are read-only by default. Every action is traced. And the agent must hold a reference set of cases before it goes live.

What does an agent cost in production?

It depends on call volume, context length and the model chosen, not on a flat rate. We instrument cost per use case from deployment precisely so that the question has a measured answer rather than an estimate.

Where is the data hosted?

In the AWS region you choose, inside your own accounts. On the Engie case, data is hosted in Europe, with private access, encryption and network segregation meeting the group's requirements.

Let's talk

Want to identify the right AI use cases for your company?

In 30 minutes, we qualify your priorities, identify the first realistic use cases and define a simple path to measurable value. Describe your context in a few lines.

Or email us directly

contact@the-intelligence-partners.com

+33 6 47 52 92 31