product updateAmazon Web Services

AWS details ambient agent pattern on Bedrock AgentCore: S3 events trigger jobs, one ask_human tool pauses for approval

TL;DR

AWS published a reference implementation for ambient agents on Amazon Bedrock AgentCore. S3 uploads or scheduled events create jobs that an agent runs, pausing for human input through a single ask_human tool. Each agent turn is capped at the 15-minute Lambda timeout.

3 min read
0

AWS has published a reference implementation for building "ambient agents" on Amazon Bedrock AgentCore. In this pattern, system events such as an S3 file upload or a scheduled trigger start an agent job, and the agent pauses for human input through a single ask_human tool. This is a sample architecture and walkthrough, not a new model or a new managed service.

How the pattern works

AWS contrasts two flows. User-initiated agents follow User → Prompt → Agent → Response. Ambient agents follow Event → Signal → Agent → [Optional human interaction] → Action. The event itself serves as the prompt, and multiple agents can run in parallel. AWS credits LangChain, among others, with articulating the ambient agent concept.

The central abstraction is the ambient signal: a configuration mapping an event source to an agent. When the event fires, the platform creates a job. One setting controls what happens next:

  • autoExecute: false (default): The job lands on the Jobs page in idle status and waits for a human to review and run it. AWS recommends this when a signal could fire on unknown input or when the agent has high-stakes tools.
  • autoExecute: true: The job is enqueued on the worker queue and runs immediately. A human is involved only if the agent calls ask_human.

What ships and what you build

The reference sample ships two event sources: Amazon S3 file uploads (by bucket and prefix) and scheduled events, which are driven by jobs carrying jobType: "scheduled" rather than by a signal. API webhooks and database changes (DynamoDB streams, Amazon RDS events) are listed as extension points. Adding one requires writing a new handler Lambda function and a corresponding form field on the Signals page.

Architecture and constraints

AgentCore Runtime hosts the agent in containers. AWS describes it as supporting long-running workloads with built-in session isolation and integration with Bedrock foundation models. The sample combines it with AWS Lambda for event processing and Amazon DynamoDB for state, which AWS calls a fully serverless platform. Deployment also involves SQS, API Gateway, CloudFront, Cognito, ECR and a React frontend.

Specific requirements from the post:

  • Turn limit: The reference implementation caps each agent turn at the Lambda 15-minute timeout. AWS says this is "more than enough headroom in practice."
  • Region: Sample defaults are wired for us-east-1.
  • Model: Access to Anthropic Claude Sonnet 4.5 in Amazon Bedrock is required. AWS says switching models is a one-line config change.
  • Tooling: AWS CDK v2 (bootstrapped), Docker, Python 3.11+ for backend Lambdas and the agent build, and Node.js 18+ for the frontend.
  • Permissions: Broad IAM, Lambda, DynamoDB, S3, SQS, API Gateway, CloudFront, Cognito, ECR and AgentCore runtime permissions. AWS suggests administrator access on a sandbox account.

The post does not disclose pricing for the sample or for AgentCore Runtime. It does not report benchmarks or latency figures, beyond saying a job can appear "within seconds" of an S3 upload. That timing is AWS's characterization, not a measured result. The excerpt available covers the signal model and the introduction of the single ask_human tool with a canonical response envelope. AWS claims this is enough to support the full range of human-in-the-loop interactions.

What this means

The pattern fills a real gap. Step Functions orchestrates deterministically but cannot reason through ambiguity, and chat agents reason but need someone to start the conversation. The sample's contribution is a concrete, deployable wiring of existing AWS event sources to an agent runtime with a pause-and-resume approval step.

Two design choices matter most for builders. First, autoExecute defaults to false, so the review-first flow is the baseline and full autonomy is opt-in. Second, collapsing all human interaction into one tool keeps the approval surface small and auditable. Teams should still test whether one envelope covers their review needs, such as multi-reviewer or time-boxed approvals.

The 15-minute turn cap is a limit of this reference implementation, not necessarily of AgentCore Runtime. Workloads that exceed it will need a different design. The dependency on Claude Sonnet 4.5 and the us-east-1 defaults also mean production use needs adaptation. Because the sample is wired to AWS services, it is not portable to other clouds.

Related Articles

product update

AWS Publishes Reference Architecture for Contract Intelligence Using Bedrock AgentCore and Dual Claude Models

AWS published a reference architecture showing how to combine structured data extraction with Bedrock AgentCore, dual Claude models, and Amazon Quick to answer portfolio-wide questions that standard RAG systems get wrong. The design uses Claude Sonnet 4.6 for extraction and Claude Haiku 4.5 for independent verification, with Amazon Textract as a deterministic tiebreaker.

model release

Amazon open-sources Strands Decider 2B, a small decision model built on a Qwen3.5-2B base

Amazon Web Services has released Strands Decider 2B, an open-source model that chooses among pre-decided options and returns a confidence score instead of generating text. It is inspired by TypeSafe's Jev and is small enough to run locally. Amazon says it briefly topped the Jevbench ranking for models of its size.

product update

uniopen lifts Amazon Nova 2 Lite moderation F1 from 0.585 to 0.855 using LoRA fine-tuning on SageMaker AI

Taiwan retail platform uniopen adapted Amazon Nova 2 Lite to its two-axis moderation policy using LoRA supervised fine-tuning in Amazon SageMaker AI, plus a prompt-format change. According to AWS, Per Behavior Macro F1 rose from 0.5852 to 0.8550 and Subject Type Macro F1 from 0.4162 to 0.8491, both above production targets.

product update

SpaceXAI launches Grok for Intune, a separate iOS app with Microsoft Intune app protection support

SpaceXAI has released Grok for Intune, a standalone enterprise iOS app that supports Microsoft Intune Mobile Application Management and honors organizational app protection policies. It signs in with work email and has no in-app purchases. Pricing and the underlying model version were not disclosed.

Comments

Loading...