<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Shadab Hussain</title>
    <description>The latest articles on DEV Community by Shadab Hussain (@techwithshadab).</description>
    <link>https://dev.to/techwithshadab</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F738392%2F646fb90e-a268-4b26-bbf3-3fb11b8b46f3.jpg</url>
      <title>DEV Community: Shadab Hussain</title>
      <link>https://dev.to/techwithshadab</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/techwithshadab"/>
    <language>en</language>
    <item>
      <title>When A Ship Goes Dark: Building A Maritime Watch Floor With AI Agents On AWS</title>
      <dc:creator>Shadab Hussain</dc:creator>
      <pubDate>Tue, 08 Sep 2026 18:18:17 +0000</pubDate>
      <link>https://dev.to/techwithshadab/-2lee</link>
      <guid>https://dev.to/techwithshadab/-2lee</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/aws-builders/when-a-ship-goes-dark-building-a-maritime-watch-floor-with-ai-agents-on-aws-2nj5" class="crayons-story__hidden-navigation-link"&gt;When A Ship Goes Dark: Building A Maritime Watch Floor With AI Agents On AWS&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;
          &lt;a class="crayons-logo crayons-logo--l" href="/aws-builders"&gt;
            &lt;img alt="AWS Community Builders  logo" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F2794%2F88da75b6-aadd-4ea1-8083-ae2dfca8be94.png" class="crayons-logo__image" width="350" height="350"&gt;
          &lt;/a&gt;

          &lt;a href="/techwithshadab" class="crayons-avatar  crayons-avatar--s absolute -right-2 -bottom-2 border-solid border-2 border-base-inverted  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F738392%2F646fb90e-a268-4b26-bbf3-3fb11b8b46f3.jpg" alt="techwithshadab profile" class="crayons-avatar__image" width="800" height="800"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/techwithshadab" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Shadab Hussain
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Shadab Hussain
                
                
              
              &lt;div id="story-author-preview-content-4608635" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/techwithshadab" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F738392%2F646fb90e-a268-4b26-bbf3-3fb11b8b46f3.jpg" class="crayons-avatar__image" alt="" width="800" height="800"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Shadab Hussain&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

            &lt;span&gt;
              &lt;span class="crayons-story__tertiary fw-normal"&gt; for &lt;/span&gt;&lt;a href="/aws-builders" class="crayons-story__secondary fw-medium"&gt;AWS Community Builders &lt;/a&gt;
            &lt;/span&gt;
          &lt;/div&gt;
          &lt;a href="https://dev.to/aws-builders/when-a-ship-goes-dark-building-a-maritime-watch-floor-with-ai-agents-on-aws-2nj5" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Sep 8&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/aws-builders/when-a-ship-goes-dark-building-a-maritime-watch-floor-with-ai-agents-on-aws-2nj5" id="article-link-4608635"&gt;
          When A Ship Goes Dark: Building A Maritime Watch Floor With AI Agents On AWS
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/aws"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;aws&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/agenticai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;agenticai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/systemdesign"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;systemdesign&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
            &lt;a href="https://dev.to/aws-builders/when-a-ship-goes-dark-building-a-maritime-watch-floor-with-ai-agents-on-aws-2nj5#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            20 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>agents</category>
      <category>ai</category>
      <category>aws</category>
    </item>
    <item>
      <title>When A Ship Goes Dark: Building A Maritime Watch Floor With AI Agents On AWS</title>
      <dc:creator>Shadab Hussain</dc:creator>
      <pubDate>Tue, 08 Sep 2026 18:13:57 +0000</pubDate>
      <link>https://dev.to/aws-builders/when-a-ship-goes-dark-building-a-maritime-watch-floor-with-ai-agents-on-aws-2nj5</link>
      <guid>https://dev.to/aws-builders/when-a-ship-goes-dark-building-a-maritime-watch-floor-with-ai-agents-on-aws-2nj5</guid>
      <description>&lt;p&gt;&lt;em&gt;How a watch floor turns a stream of AIS position reports into reviewed alerts, evidence backed investigations and collection tasking, with Amazon Bedrock AgentCore, Amazon Nova, Strands Agents, LangGraph and the Model Context Protocol.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Problem: Vessels That Go Dark
&lt;/h2&gt;

&lt;p&gt;Every commercial vessel above 300 gross tons broadcasts its identity, position, course and speed through the Automatic Identification System (AIS). Maritime domain awareness leans on that stream. The vessels worth watching are the ones that bend it: a tanker that switches its transponder off for an hour inside a subsea cable corridor, two ships that drift together at sea for a ship to ship transfer nobody declared, a hull that reports the same MMSI from two places at once, a bulk carrier that loiters at the edge of a naval exercise area. Each of these is a small signal inside millions of routine reports, and each one needs context before it means anything: who owns the ship, where has it been flagged, is the operator on a sanctions list, has it done this before.&lt;/p&gt;

&lt;p&gt;A watch floor does this work by hand today. An analyst notices a gap on the plot, opens a registry lookup, checks a sanctions screen, pulls the track history, writes a vessel of interest note and decides whether to ask for satellite imagery. The bottleneck is not detection, a rule can find a gap. The bottleneck is the investigation that follows, the judgement about which of the forty gaps this morning deserve an hour of attention, and the record that shows why a decision was made.&lt;/p&gt;

&lt;p&gt;Argus is a working system built for that gap. It watches an area, raises alerts, investigates each one across identity, ownership, sanctions and behaviour, writes a Vessel of Interest report with every claim cited to the tool that produced it, and proposes collection tasking. Officers keep every decision: alerts are accepted or rejected, reports are reviewed, tasking is approved or declined. Nothing is tasked and nothing is closed by a model on its own.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhojtojvvrmcv953qk6wz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhojtojvvrmcv953qk6wz.png" alt="How Argus works, from AIS feeds through detection, investigation and reporting to the officer's decisions." width="800" height="249"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 1. How Argus works, from AIS feeds through detection, investigation and reporting to the officer's decisions.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What A Shift Looks Like With Argus
&lt;/h2&gt;

&lt;p&gt;The system runs as a loop with a person at the end of it. A sweep runs every thirty minutes on a schedule, or when an officer presses the sweep button. Detectors scan the last twelve hours of positions for five anomaly kinds and hand fixed candidates to the Watch agent, which decides what to raise and how to describe it. Each alert lands on the watch floor with its evidence attached.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Sweep: the detectors and the Watch agent turn twelve hours of positions into a short list of alerts, each with a kind, a time window, a severity and the evidence behind it.&lt;/li&gt;
&lt;li&gt;Review: the officer reads the alert, opens the track, and accepts or rejects it. High severity alerts open an investigation automatically; any alert can be investigated on demand.&lt;/li&gt;
&lt;li&gt;Investigation: the Orchestrator runs two Investigator branches in parallel (identity, ownership and sanctions on one side, behaviour on the other), asks the Tasking agent whether imagery is worth collecting, and drafts the report.&lt;/li&gt;
&lt;li&gt;Report: the Vessel of Interest report carries a headline, a timeline, indicators and counter indicators, information gaps, recommended actions and a collection plan. Every evidence line names the tool that produced it.&lt;/li&gt;
&lt;li&gt;Tasking: collection requests arrive as proposals. An officer approves or rejects each one; approval is the only path to a tasked request.&lt;/li&gt;
&lt;li&gt;Record: every state change is an append only audit event that names the actor, human or agent, so a reviewer can reconstruct who did what and when.
The scenario used through this article is a scripted eastern Mediterranean baseline with eight fictional vessels and planted anomalies, played on a loop at sixty times real speed. The same stack runs on live AIS from AISStream across six watched regions, and later sections show both.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Design Principles
&lt;/h2&gt;

&lt;p&gt;Five decisions shape everything else in the system. They are recorded as architecture decision records in the repository, eighteen of them at the time of writing, and they explain most of what follows.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Agents propose, officers decide.&lt;/strong&gt; Agents can raise alerts, write findings and propose tasking. They cannot approve tasking, close an alert or finalise a report. Human in the loop is enforced in the API, not in a prompt.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The investigation is a code owned graph.&lt;/strong&gt; The Orchestrator is a LangGraph state machine whose sequence is fixed in code. The only model call it makes itself is the report draft. No model chooses which agent runs next, so a run is reproducible and its cost is bounded.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Every claim cites a tool.&lt;/strong&gt; Findings and reports carry evidence lines in the form server.tool (for example ais.get_vessel_track). A report that cites nothing, or recommends an action outside the allowed set, is rejected by a policy check and redrafted once with the corrections listed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Production is Bedrock only, with Amazon Nova.&lt;/strong&gt; Three model tiers map to Nova Lite, Nova 2 Lite and Nova Pro. Other providers exist for development and evaluation, but the deployed runtimes can only reach first party Bedrock models through a VPC endpoint, and the IAM allowlist enforces that.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Agents live in an isolated network.&lt;/strong&gt; The AgentCore runtimes sit in subnets with no route to the internet. Everything they need, Bedrock, the tool gateway, the registry, Secrets Manager, SSM, is an interface endpoint. If an agent is compromised, there is nowhere for it to send data.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Architecture On AWS
&lt;/h2&gt;

&lt;p&gt;The deployment is four CDK stacks (network, data, platform, agents) and nothing is created outside infrastructure as code. The figure below is the complete picture. Reading it left to right: the watch floor and the operators arrive through an edge that signs them in, the platform stack holds the API, the job workers, the scheduler and the databases, the agents plane runs on Amazon Bedrock AgentCore behind two gateways, and the external feeds enter through the ingest task alone.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1fk6o5ekrmnwy30p3gn7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1fk6o5ekrmnwy30p3gn7.png" alt="Argus on AWS" width="800" height="354"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 2. Argus on AWS: edge, platform, agents plane, tool plane, data and observability, with the trust boundaries drawn.&lt;/em&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  The Edge
&lt;/h3&gt;

&lt;p&gt;An Application Load Balancer terminates TLS and runs the Cognito sign in itself: every listener for the UI and for Grafana carries an authenticate action, so the browser never reaches an application page without a session. The balancer forwards the signed id token on every request and the API verifies it against the balancer's regional key, checks that the signer is this deployment's balancer and that the issuer is its user pool, and records the officer's email on every decision. AWS WAF sits in front with a per IP rate limit and the managed rule groups for IP reputation, common attacks and known bad inputs. Tooling and evaluation runs bypass the browser sign in on /api/* with a bearer token that the API verifies against IAM, admitting only named roles.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkrxod11kwje8g729lg7j.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkrxod11kwje8g729lg7j.jpg" alt="hosted sign in page" width="439" height="358"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 3. The hosted sign in page. Officers are created by an operator; there is no self sign up, and MFA can be made mandatory with one deployment flag.&lt;/em&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  The Platform
&lt;/h3&gt;

&lt;p&gt;A FastAPI service is the system of record's front door. It owns alerts, investigations, findings, tasking, review states and the audit log, and it is the only component that writes those tables. Long running work never runs inside a request: the API writes a job row and publishes its id to one of two SQS queues, one for sweeps and one for investigations, and a worker service per queue picks it up. The queues carry ids only. A worker heartbeats the message visibility while the job runs, reclaims a job that a crashed worker left behind, and dead letters the ones that fail for good. EventBridge Scheduler drops the periodic sweep onto the same queue, so a scheduled sweep and a button press take the identical path.&lt;/p&gt;

&lt;p&gt;Aurora Serverless v2 with PostGIS holds everything: positions partitioned by day, vessels and the registry, the ownership network, zones, alerts, investigations, evidence snapshots and the audit trail. The ingest task subscribes to AISStream for every watched region in live mode, or replays the scenario, and writes positions straight into the partitions while publishing them on a stream for the map.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Agents Plane
&lt;/h3&gt;

&lt;p&gt;The four agents and the four MCP tool servers run as Amazon Bedrock AgentCore Runtime endpoints (ARM64 containers, one IAM role per runtime). Two AgentCore Gateways front them. The tools gateway exposes the twenty four tools of the four servers with semantic search and an AgentCore Policy engine in enforce mode: Cedar policies generated from the tool inventory allow each agent exactly the tools it is meant to call and block everything else. The agents gateway carries the agent to agent calls (A2A) from the orchestrator and the workers to the specialists. Agents discover each other through the AWS Agent Registry rather than through environment variables, AgentCore Identity holds the OpenSanctions credential as an API key provider, AgentCore Memory keeps what the system learned about a vessel across investigations, and AgentCore Evaluations scores live sessions online.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;AgentCore capability&lt;/th&gt;
&lt;th&gt;How Argus uses it&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Runtime&lt;/td&gt;
&lt;td&gt;Nine endpoints: Watch, Investigator, Tasking, Orchestrator, the four tool servers and the tasking harness pilot&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gateway (tools)&lt;/td&gt;
&lt;td&gt;One MCP gateway over the four servers, IAM inbound, semantic tool search, Cedar policy in enforce mode&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gateway (agents)&lt;/td&gt;
&lt;td&gt;Runtime targets for A2A; callers hit //invocations and never a runtime URL&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Policy&lt;/td&gt;
&lt;td&gt;Cedar allow rules per agent generated from mcp-servers/tools.json; a tool added without regenerating is blocked&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Agent Registry&lt;/td&gt;
&lt;td&gt;MCP server records and A2A agent cards, approved on deploy; agents resolve each other by name&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Identity&lt;/td&gt;
&lt;td&gt;API key credential provider for OpenSanctions; the runtime injects the workload token per request&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory&lt;/td&gt;
&lt;td&gt;Per vessel long term memory plus raw recent events, so a repeat investigation sees the previous run at once&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Evaluations&lt;/td&gt;
&lt;td&gt;Online evaluators on each agent: built in helpfulness, correctness, tool selection, goal success, harmfulness, plus a report rubric&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Guardrails&lt;/td&gt;
&lt;td&gt;One Bedrock Guardrail on every model call, calibrated so it does not block legitimate investigation prompts&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  The Tool Plane
&lt;/h3&gt;

&lt;p&gt;Tools are Model Context Protocol servers, one per data domain. They are the only way an agent touches data, and each carries its own database role and reads personal data only where a specific tool needs it.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Server&lt;/th&gt;
&lt;th&gt;Tools&lt;/th&gt;
&lt;th&gt;What it answers&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;ais&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;Tracks, latest positions, gaps, MMSI conflicts, loitering, rendezvous, zone incursions, vessels near a point, open alerts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;registry&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Vessel lookup, flag history, fleet associations, the ownership network, sanctions screening (OpenSanctions or the local list)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;geo&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Zones, point in zone tests, nearest ports, reverse geocoding&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;imagery&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;Sentinel scene search, next pass estimate, tasking requests (create and list)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Any free text a server receives from an external source passes through an untrusted content wrapper before a model sees it, and the servers verify who is calling: each request carries a token signed by AWS STS that proves the caller's IAM role, and the servers admit an allowlist of role names and nothing else.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Investigation Graph
&lt;/h2&gt;

&lt;p&gt;The figure shows one investigation from trigger to watch floor. An alert review, a policy rule or an officer's request opens the job; the worker claims it and invokes the Orchestrator through the agents gateway with the vessel, the trigger and the alert. The Orchestrator fans out to two Investigator branches that run in parallel, merges their findings in pure code, asks the Tasking agent for a collection decision, drafts the report, runs the policy check, and persists the result to Aurora and then to AgentCore Memory.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fejvfdygmulozgueasb81.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fejvfdygmulozgueasb81.png" alt="investigation graph" width="800" height="244"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 4. The investigation graph: triggers, the durable job, parallel Investigator branches, the pure merge, Tasking, report plus policy, persistence, then the watch floor.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The branches split the work by the questions an analyst asks, so each carries a focused prompt and a focused tool set:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Identity, ownership and sanctions:&lt;/strong&gt; who is this ship, who owns and operates it, how has its flag changed, what does the ownership network connect it to, does anything screen against a sanctions list.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Behaviour:&lt;/strong&gt; what did the track do, where and for how long was it silent, who did it meet, which zones did it enter, what does the vessel's recent history in memory say.
A branch that fails does not fail the investigation. It is marked degraded and the report says so. A branch that hits a provider availability error is retried once on the next model tier. If both branches fail, the job fails and the audit trail records it, which is exactly what the earlier screenshot of failed runs shows from a misconfigured local environment.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The report node is the one place the Orchestrator calls a model. Its output must pass a policy module before it is stored: a headline and summary, a timeline, indicators and counter indicators, information gaps, recommended actions from an allowed list, a collection plan, and evidence lines in the server.tool form. On the run captured for this article the first draft was rejected for an action outside the allowed set and for an empty counter indicator list, and the second draft, written with the correction list in the prompt, passed.&lt;/p&gt;

&lt;h2&gt;
  
  
  Agents, Frameworks And Models
&lt;/h2&gt;

&lt;p&gt;Two agent frameworks share the plane on purpose. Strands Agents runs the tool heavy loops where a model reasons over many tool results (Watch, Tasking). LangGraph runs the graphs whose structure must be fixed (the Investigator's own branch graph and the Orchestrator). Both frameworks build their models through one factory, so a tier, a guardrail or a provider change lands everywhere at once.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Agent&lt;/th&gt;
&lt;th&gt;Framework&lt;/th&gt;
&lt;th&gt;Tier and model&lt;/th&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Watch&lt;/td&gt;
&lt;td&gt;Strands&lt;/td&gt;
&lt;td&gt;fast: Amazon Nova Lite&lt;/td&gt;
&lt;td&gt;Reviews detector candidates from a sweep and raises or dismisses each with a written reason&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Investigator&lt;/td&gt;
&lt;td&gt;LangGraph&lt;/td&gt;
&lt;td&gt;standard: Amazon Nova 2 Lite, escalates to strong&lt;/td&gt;
&lt;td&gt;Two branches: identity, ownership and sanctions; behaviour. Emits findings with evidence&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tasking&lt;/td&gt;
&lt;td&gt;Strands&lt;/td&gt;
&lt;td&gt;standard: Amazon Nova 2 Lite&lt;/td&gt;
&lt;td&gt;Decides whether imagery is worth collecting and proposes a request with a sensor, a window and a priority&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Orchestrator&lt;/td&gt;
&lt;td&gt;LangGraph (code graph)&lt;/td&gt;
&lt;td&gt;strong: Amazon Nova Pro for the report&lt;/td&gt;
&lt;td&gt;Owns the sequence, merges findings, drafts and checks the report, persists&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The Watch sweep deserves a closer look because it is where a small model does the most damage if left alone. Early runs let the model name the vessel and the time window of each alert, and a smaller model would copy one vessel's gap window onto another; evaluation recall swung between 0.4 and 0.8 from run to run. The sweep is now a deterministic pre pass followed by judgement. The detectors run first and build candidates with a fixed MMSI, kind, window and evidence. The model only chooses to raise or dismiss a candidate by id and writes the explanation. Two kinds are not dismissible at all, an MMSI reporting from two places and a rendezvous outside any declared anchorage, because they are anomalies by definition. Candidates are ranked and capped at twenty five per sweep so a busy hour cannot exhaust the model's context.&lt;/p&gt;

&lt;p&gt;Prompts are published to Amazon Bedrock Prompt Management at deploy time and the runtimes fetch them by version, falling back to the file in the image. The manifest of every investigation records the prompt version, the model and the tier that produced each node, so a reviewer can tell which prompt wrote which report.&lt;/p&gt;

&lt;h2&gt;
  
  
  Data Model And Provenance
&lt;/h2&gt;

&lt;p&gt;The data model separates what the feeds gave, what Argus produced, and the record. Positions are range partitioned by day and deliberately have no primary key, because spoofed MMSIs and duplicate AIS reports legitimately share a vessel and a timestamp. Evidence snapshots freeze the tool output an investigation used, so a report can be re read months later against the data it actually saw, not against the table as it is today. Each investigation carries a manifest naming the prompt versions, models, tools and tiers that ran.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzimdmd6i1phw8nti62ra.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzimdmd6i1phw8nti62ra.png" alt="PostGIS data model" width="800" height="227"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 5. The PostGIS data model grouped by concern: the picture the feeds gave, the findings and work Argus produced, and the append only record.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Review state is not approval.&lt;/strong&gt; Findings and reports carry a review state (draft, accepted, rejected). Actions such as tasking carry an approval status. The two are separate columns with separate endpoints, because reviewing a claim and authorising an action are different acts.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The audit log is append only.&lt;/strong&gt; A database trigger rejects updates and deletes. Every API state change writes an event naming the actor, and agents appear as actors under their own names.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Personal data is encrypted at the column.&lt;/strong&gt; Beneficial owner names and person entities exist only as pgp encrypted values with a data key from Secrets Manager. The registry tool decrypts for the one lookup that needs it; the API and the UI stay pseudonymous. Re keying rewrites every row in one transaction from an operator command.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The database password rotates monthly.&lt;/strong&gt; Connection pools notice a failed authentication, re read the secret and rebuild, with no restart and no lost job.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The Watch Floor
&lt;/h2&gt;

&lt;p&gt;The user interface is a single page over the API: a map with vessels, zones and watched areas on the left, and four tabs on the right for alerts, investigations, tasking and the audit trail. It is built for a shift, not a demo: keyboard shortcuts move through the alert queue, review actions need a modifier key so stray typing cannot accept an alert, and the officer's identity comes from the sign in and is locked in the header on AWS.&lt;/p&gt;

&lt;h3&gt;
  
  
  Live Watching Across Regions
&lt;/h3&gt;

&lt;p&gt;In live mode the ingest subscribes to every watched region in one AISStream session. The header's watching selector lists all regions and lets the officer fit the map to one of them and filter the vessels shown to that box; alerts stay global. The catalogue of regions is a small YAML file and a single environment variable picks which are watched.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F56utdd1mrsqio2tskaph.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F56utdd1mrsqio2tskaph.jpg" alt="Live mode with six watched regions" width="800" height="624"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 6. Live mode with six watched regions: the dashed boxes are the subscribed areas, each vessel dot is a live AIS report, and the scale bar reads five hundred nautical miles.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7pop2sx9voh8lpdx0shp.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7pop2sx9voh8lpdx0shp.jpg" alt="Eastern Mediterranean box on live AIS" width="800" height="624"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 7. The eastern Mediterranean box on live AIS: the cable corridor and the naval exercise area from the scenario, with real traffic around them and two alerted vessels in amber.&lt;/em&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  One Case From Alert To Audit
&lt;/h3&gt;

&lt;p&gt;The walkthrough below was recorded on the deployed system against live AIS traffic. It opens on the map with every watched region drawn; choosing the eastern Mediterranean from the watching selector fits the map to that box and filters the vessels to the ninety or so reporting there. The alert queue is global: the half hourly sweeps had raised over a hundred alerts that day, each marked as an AI draft, which every agent written record stays until an officer reviews it. The newest is a 171 minute AIS gap on a container ship near Singapore. Expanding the evidence shows the three tool results the Watch agent used, each cited as server.tool with the detector's numbers. Track draws another alerted vessel's last twenty four hours with its two silent periods. Investigate opens a job, and the progress card follows it from the queue through the orchestrator, the two Investigator branches and tasking to the report.&lt;/p&gt;

&lt;p&gt;The report comes back in about a minute and is a useful example of restraint: priority low, confidence low, one indicator (the gap) against one counter indicator (the vessel was in no declared zone and its positions before and after the gap suggest it anchored), an information gap (no registry record for this hull), and a collection plan. Accept report and Reject report are the officer's two verbs. On the tasking tab the agent's SAR proposal for the gap waits for Approve or Reject, and the approval is stamped with the officer's email and the time. The audit tab, filtered on the vessel, shows the chain: the alert raised by the Watch agent, the investigation opened by the officer, the tasking proposed by the Tasking agent, each linked to its record.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpwyvgi235ln4ayk8xw56.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpwyvgi235ln4ayk8xw56.gif" alt="ARGUS UI" width="599" height="309"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 8. The live walkthrough: every region on one map, the region selected, the evidence behind one alert, a track with two silent periods, the investigation in progress, the report, the approved tasking and the audit trail.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fg4ku8rwndy6da371o4pe.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fg4ku8rwndy6da371o4pe.jpg" alt="finished Vessel of Interest report" width="800" height="413"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 9. The finished Vessel of Interest report on live data: headline, priority and confidence, summary, timeline and recommended actions, with the trace id into the trace store and the AI draft badge until review.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The report from that run, as stored, reads as follows.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Field&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Headline&lt;/td&gt;
&lt;td&gt;The vessel OOCL PANAMA exhibited a 171-minute AIS gap, which may indicate an attempt to avoid tracking, but its behavior before and after the gap suggests it may have anchored, a benign activity.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Priority, confidence&lt;/td&gt;
&lt;td&gt;low, low&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Indicators&lt;/td&gt;
&lt;td&gt;171-minute AIS gap detected (source: ais.find_ais_gaps)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Counter indicators&lt;/td&gt;
&lt;td&gt;The vessel was not inside any declared zones during the AIS gap (source: geo.point_in_zones)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Information gaps&lt;/td&gt;
&lt;td&gt;Registry identity (name, IMO, flag, type) is not available.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Evidence sources&lt;/td&gt;
&lt;td&gt;ais.find_ais_gaps, geo.point_in_zones, registry.lookup_vessel&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Collection plan&lt;/td&gt;
&lt;td&gt;Propose sentinel-1-sar imagery collection with AOI center at [-73.935242, 40.689247] and radius 10.0 NM, window start 2026-09-11T10:00:00+00:00, window end 2026-09-11T11:00:00+00:00.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost of the run&lt;/td&gt;
&lt;td&gt;$0.089&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Observability
&lt;/h2&gt;

&lt;p&gt;Everything emits OpenTelemetry. The platform services and the runtimes send spans, metrics and logs to a collector; the collector fans out to a self hosted Grafana, Tempo, Loki and Prometheus task and to CloudWatch and X-Ray. AgentCore's own unified telemetry lands in CloudWatch with Transaction Search on, which is what AgentCore Evaluations and the GenAI observability views read. One Grafana board, generated from a Python panel library, is the operator view; it is organised by the question someone is asking rather than by service.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fygdl7dkrv4nqoljwz8m1.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fygdl7dkrv4nqoljwz8m1.gif" alt="ARGUS Dashboard" width="800" height="401"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 10. A scroll through the Argus board after a day of live sweeps: the watch floor strip, pipeline health against the service levels, tool and model calls, tokens and cost per investigation, the AgentCore section, and the infrastructure row.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The alarms that must page regardless of the board live in CloudWatch: thirty one of them, covering the queues and dead letter queues, both load balancers and their targets, every service's running task count, Aurora CPU, capacity and local storage, NAT gateways, the web ACL's blocked requests, degraded investigator branches and the evaluation gate per suite. Alarm and recovery both notify one SNS topic, and every alarm name has a runbook entry.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quality Gates: Evaluations And Tests
&lt;/h2&gt;

&lt;p&gt;A prompt or model change is not done until the evaluation gate passes against a running stack. Each agent has a suite with regression floors, scored by deterministic checks where possible and by a model judge where a rubric is needed. The Watch suite scores alerts against the scenario's ground truth by time overlap, so an alert without a window scores nothing.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Suite&lt;/th&gt;
&lt;th&gt;Floors&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;watch&lt;/td&gt;
&lt;td&gt;recall 0.8, precision 0.6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;investigator&lt;/td&gt;
&lt;td&gt;schema valid 1.0, evidence traceability 0.9, expected hits 0.7&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;tasking&lt;/td&gt;
&lt;td&gt;schema valid 1.0, decision match 0.5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;report&lt;/td&gt;
&lt;td&gt;completion 1.0, policy clean 1.0, rubric average 3.5 of 5, expected hits 0.6&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Below the evaluation gate, the repository carries a unit suite that runs with no database, no Docker and no AWS (one hundred and sixty three tests across twenty three files at the time of writing), integration tests for the detectors against PostGIS, ruff for lint and format, a compose configuration check, and cdk-nag on every synth with every suppression justified in code. Several of the unit tests exist because a deploy found the bug: a self recursive connection wrapper, an SNS topic policy that dropped the CloudWatch allow, a JWT verifier that re encoded the balancer's padded token. Each is pinned so it cannot return.&lt;/p&gt;

&lt;h2&gt;
  
  
  Security Posture
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Identity at the edge:&lt;/strong&gt; Cognito user pool with operator created users, optional or mandatory TOTP, eight hour sessions, sign in enforced by the balancer on every listener.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity between services:&lt;/strong&gt; STS signed caller tokens verified by the tool servers and the API; allowlists of IAM role names; agent only API routes that stay IAM only even for signed in officers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Least privilege:&lt;/strong&gt; one IAM role per runtime and per task, a Bedrock allowlist limited to first party models, a deploy role that requires MFA, an operator role for tooling, and a refusal to run scripts as root.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; agents in subnets with no NAT route and interface endpoints for every AWS service they use; the tool servers reachable only through the gateway; HTTPS on the internal balancer with a certificate the agents trust through SSM.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data:&lt;/strong&gt; encrypted personal data columns, monthly password rotation, an operator run re key, an append only audit log, and no demo or synthetic disclaimers in agent output so a report reads as a report.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Model safety:&lt;/strong&gt; one guardrail on every model call, prompt attack and misconduct filters calibrated against real investigation prompts, and a policy check on every report.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Running It
&lt;/h2&gt;

&lt;p&gt;The same compose file and the same CDK application serve local development and AWS. Locally, one command starts the twenty containers and the scenario replays on a loop:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight make"&gt;&lt;code&gt;&lt;span class="err"&gt;cp&lt;/span&gt; &lt;span class="err"&gt;.env.example&lt;/span&gt; &lt;span class="err"&gt;.env&lt;/span&gt;    &lt;span class="c"&gt;# set MODEL_PROVIDER and its credential
&lt;/span&gt;&lt;span class="nl"&gt;make up                 # UI on &lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nf"&gt;8088&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nf"&gt; API on :8000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nf"&gt; Grafana on :3000&lt;/span&gt;
&lt;span class="err"&gt;make&lt;/span&gt; &lt;span class="err"&gt;sweep&lt;/span&gt;              &lt;span class="c"&gt;# or press Sweep 12 h on the watch floor
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;On AWS the lifecycle is CDK only. The deploy script reads the feed keys and the officer's email from the environment, builds the images, deploys the four stacks, stores the keys in Secrets Manager and restarts the reader that needs them:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight make"&gt;&lt;code&gt;&lt;span class="err"&gt;make&lt;/span&gt; &lt;span class="err"&gt;deploy&lt;/span&gt;      &lt;span class="c"&gt;# create or update everything
&lt;/span&gt;&lt;span class="err"&gt;make&lt;/span&gt; &lt;span class="err"&gt;stop-aws&lt;/span&gt;    &lt;span class="c"&gt;# ECS to zero, Aurora pauses; volumes and data kept
&lt;/span&gt;&lt;span class="err"&gt;make&lt;/span&gt; &lt;span class="err"&gt;start-aws&lt;/span&gt;
&lt;span class="err"&gt;make&lt;/span&gt; &lt;span class="err"&gt;destroy&lt;/span&gt;     &lt;span class="c"&gt;# destroy plus asset garbage collection
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Cost is a design input. An idle deployment with the observability task and two NAT gateways runs at roughly four hundred dollars a month, a paused one at roughly one hundred and forty, and a destroyed one at under two dollars for the retained buckets. An investigation costs a few cents in Nova tokens; the run captured above cost just under nine cents.&lt;/p&gt;

&lt;h2&gt;
  
  
  Lessons From Building It
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Small models need rails, not longer prompts.&lt;/strong&gt; Handing the model fixed candidates and asking only for a decision took Watch recall from a coin flip to a stable floor.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reproducibility comes from code, not from a planner.&lt;/strong&gt; A code owned graph with a single model node for the report made cost, latency and failure modes predictable.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Every new managed service type was validated by a failed deploy.&lt;/strong&gt; Evaluator placeholders, registry descriptor limits, gateway role permissions, resource policy shapes: read the service's own documentation page before guessing, and pin the answer in a unit test.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Observability pays for itself in the first incident.&lt;/strong&gt; The three bugs found on the final deploy were all diagnosed from logs and metrics in minutes: a task that could not connect, an alarm action that could not publish, a token that failed verification.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Keep humans in the API.&lt;/strong&gt; Enforcing review and approval in the service, with separate endpoints and separate columns, made the human in the loop guarantee something a test can check.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What Comes Next
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Move the Tasking agent onto the AgentCore harness path by default once its evaluation suite matches the direct path.&lt;/li&gt;
&lt;li&gt;Add more detector kinds (course reversals near boundaries, speed profiles inconsistent with the declared ship type) and their ground truth to the scenarios.&lt;/li&gt;
&lt;li&gt;Run the agents across two availability zones once AgentCore VPC mode supports the remaining zones in the region.&lt;/li&gt;
&lt;li&gt;Extend the region catalogue and give each region its own zone set and its own sweep cadence.
Argus is a complete system rather than a demonstration of one technique: a feed, detectors, four agents on two frameworks, twenty four tools behind a policy enforcing gateway, a durable job system, a reviewed data model, a watch floor, and the observability and evaluation harness to run it. The AWS generative AI stack, AgentCore in particular, supplied the runtime, the gateway, the policy, the identity, the memory and the evaluation pieces so that the engineering effort could go into the domain: what an analyst needs to know about a ship that went dark, and how to show the evidence.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What It Costs To Run
&lt;/h2&gt;

&lt;p&gt;The figures below are the on demand list prices in us-east-1 at the time of writing, rounded, for the deployment as shipped: two availability zones, one NAT gateway per zone, the self hosted observability task on, Aurora at its half ACU floor. Model usage is metered separately and is small next to the fixed floor: an investigation costs a few cents in Amazon Nova tokens, and the day of live sweeps behind the screenshots came to under a dollar. Your bill will differ with region, traffic, retention and the free tier.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Running, approximate per month&lt;/th&gt;
&lt;th&gt;Paused (make stop-aws)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;NAT gateways (two zones)&lt;/td&gt;
&lt;td&gt;about $66 plus data&lt;/td&gt;
&lt;td&gt;about $66&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Application load balancers (public and internal)&lt;/td&gt;
&lt;td&gt;about $35&lt;/td&gt;
&lt;td&gt;about $35&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aurora Serverless v2 (0.5 ACU floor, storage, backups)&lt;/td&gt;
&lt;td&gt;about $50&lt;/td&gt;
&lt;td&gt;about $5 (auto pause, storage only)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECS Fargate: API, UI, two workers, ingest, collector, observability task&lt;/td&gt;
&lt;td&gt;about $150&lt;/td&gt;
&lt;td&gt;$0 (services at zero)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ElastiCache Serverless, WAF, Secrets Manager, S3, VPC endpoints&lt;/td&gt;
&lt;td&gt;about $60&lt;/td&gt;
&lt;td&gt;about $30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CloudWatch, X-Ray Transaction Search, logs&lt;/td&gt;
&lt;td&gt;about $15 to $30&lt;/td&gt;
&lt;td&gt;under $5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Bedrock AgentCore runtimes, gateways, memory (metered per use)&lt;/td&gt;
&lt;td&gt;usage: a few dollars at demo load&lt;/td&gt;
&lt;td&gt;$0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Amazon Nova tokens&lt;/td&gt;
&lt;td&gt;about $0.04 to $0.09 per investigation, cents per sweep&lt;/td&gt;
&lt;td&gt;$0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total&lt;/td&gt;
&lt;td&gt;about $400 idle plus usage&lt;/td&gt;
&lt;td&gt;about $140&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Destroyed (make destroy) the account keeps only the retained buckets, under two dollars a month. The runbook lists the two switches that move the floor most: a single NAT gateway (about $33 less) and the Aurora reader (about $43 more when on).&lt;/p&gt;

&lt;h2&gt;
  
  
  Source Code
&lt;/h2&gt;

&lt;p&gt;The complete system, infrastructure as code, tests, evaluation harness and documentation set are in the repository below. The README covers the local stack in one command and the AWS deployment in one more.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/techwithshadab/argus" rel="noopener noreferrer"&gt;Argus - https://github.com/techwithshadab/argus&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;p&gt;AWS services and the documentation pages this article leans on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aws.amazon.com/bedrock/agentcore/" rel="noopener noreferrer"&gt;Amazon Bedrock AgentCore&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/" rel="noopener noreferrer"&gt;Amazon Bedrock AgentCore developer guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://aws.amazon.com/bedrock/" rel="noopener noreferrer"&gt;Amazon Bedrock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://aws.amazon.com/ai/generative-ai/nova/" rel="noopener noreferrer"&gt;Amazon Nova models&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails.html" rel="noopener noreferrer"&gt;Amazon Bedrock Guardrails&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-management.html" rel="noopener noreferrer"&gt;Amazon Bedrock Prompt Management&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/elasticloadbalancing/latest/application/listener-authenticate-users.html" rel="noopener noreferrer"&gt;Application Load Balancer user authentication with Amazon Cognito&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://aws.amazon.com/waf/" rel="noopener noreferrer"&gt;AWS WAF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-serverless-v2.html" rel="noopener noreferrer"&gt;Amazon Aurora Serverless v2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/cdk/v2/guide/" rel="noopener noreferrer"&gt;AWS CDK v2 developer guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cdklabs/cdk-nag" rel="noopener noreferrer"&gt;cdk-nag&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Agent frameworks and protocols:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://strandsagents.com/" rel="noopener noreferrer"&gt;Strands Agents SDK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://langchain-ai.github.io/langgraph/" rel="noopener noreferrer"&gt;LangGraph&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://modelcontextprotocol.io/" rel="noopener noreferrer"&gt;Model Context Protocol&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://a2a-protocol.org/" rel="noopener noreferrer"&gt;Agent2Agent protocol&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Data, mapping and observability:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aisstream.io/" rel="noopener noreferrer"&gt;AISStream, live AIS over WebSocket&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.opensanctions.org/" rel="noopener noreferrer"&gt;OpenSanctions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.imo.org/en/OurWork/Safety/Pages/AIS.aspx" rel="noopener noreferrer"&gt;Automatic Identification System, IMO overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://postgis.net/" rel="noopener noreferrer"&gt;PostGIS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://maplibre.org/" rel="noopener noreferrer"&gt;MapLibre GL JS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://carto.com/basemaps/" rel="noopener noreferrer"&gt;CARTO basemaps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://opentelemetry.io/" rel="noopener noreferrer"&gt;OpenTelemetry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://grafana.com/" rel="noopener noreferrer"&gt;Grafana&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>ai</category>
      <category>aws</category>
      <category>agenticai</category>
      <category>systemdesign</category>
    </item>
    <item>
      <title>Unveiling the Quantum Frontier: A Dive into AWS Braket</title>
      <dc:creator>Shadab Hussain</dc:creator>
      <pubDate>Thu, 18 Jan 2024 05:57:24 +0000</pubDate>
      <link>https://dev.to/aws-builders/unveiling-the-quantum-frontier-a-dive-into-aws-braket-3a32</link>
      <guid>https://dev.to/aws-builders/unveiling-the-quantum-frontier-a-dive-into-aws-braket-3a32</guid>
      <description>&lt;p&gt;The world of quantum computing is no longer the domain of science fiction. With platforms like &lt;a href="https://aws.amazon.com/braket/" rel="noopener noreferrer"&gt;AWS Braket&lt;/a&gt;, even non-experts can explore the mind-bending potential of qubits and tackle challenges once deemed impossible. In this blog, we'll take a deep dive into Braket, uncovering its features, benefits, and how it can propel your business into the quantum future.&lt;/p&gt;

&lt;h2&gt;
  
  
  Breaking Free from Classical Constraints:
&lt;/h2&gt;

&lt;p&gt;Imagine tackling problems that would take classical computers millennia to solve – that's the power of quantum. Braket provides a playground for researchers, developers, and curious minds to experiment with this transformative technology. It does this by offering:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Access to diverse quantum hardware:&lt;/strong&gt; Run your algorithms on real quantum machines from leading vendors like IonQ, D-Wave, and Rigetti. This allows you to compare performance and choose the best fit for your specific needs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Powerful quantum circuit simulators:&lt;/strong&gt; Test and refine your quantum circuits before taking them to real hardware. Braket's high-performance simulators let you iterate quickly and optimize your code without expensive real-time tests.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hybrid quantum-classical workflows:&lt;/strong&gt; Seamlessly integrate your classical code with quantum algorithms. This hybrid approach lets you leverage the strengths of both worlds, tackling complex problems with unprecedented efficiency.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Jupyter Notebook development environment:&lt;/strong&gt; Work in a familiar and interactive environment, built for scientific computing. Access pre-built Braket libraries and tools to accelerate your quantum explorations.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Unlocking Opportunities Across Industries:
&lt;/h2&gt;

&lt;p&gt;The applications of quantum computing are vast, spanning materials science, finance, drug discovery, and beyond. With Braket, you can:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Optimize logistics and supply chains:&lt;/strong&gt; Develop quantum algorithms to find the most efficient routes for your deliveries, saving time and resources.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Speed up drug discovery:&lt;/strong&gt; Simulate complex molecules to design new life-saving medications with greater accuracy and efficiency.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Break encryption codes:&lt;/strong&gt; Explore post-quantum cryptography solutions to stay ahead of potential security threats in the quantum age.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Optimize financial portfolio management:&lt;/strong&gt; Develop novel risk assessment and investment strategies using the power of quantum algorithms.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Getting Started with Braket:
&lt;/h2&gt;

&lt;p&gt;Embarking on your quantum journey with Braket is simple. Start with the Free Tier to access simulators and explore basic quantum concepts. As you progress, you can upgrade to paid plans for access to real hardware and tailored resources. With the Braket developer community and comprehensive &lt;a href="https://docs.aws.amazon.com/braket/latest/developerguide/braket-using.html" rel="noopener noreferrer"&gt;documentation&lt;/a&gt; at your side, you'll have all the support you need to navigate the quantum landscape.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F0wgvs486okycci6fq6zq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F0wgvs486okycci6fq6zq.png" alt="AWS Braket Workflow" width="800" height="230"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Future is Quantum:
&lt;/h2&gt;

&lt;p&gt;AWS Braket is your gateway to unlocking the next wave of computational power. Whether you're a seasoned developer or a curious beginner, Braket empowers you to explore the possibilities, paving the way for innovation, and secure your place at the forefront of the quantum revolution.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;So, what are you waiting for? Dive into the exciting world of AWS Braket and unleash the power of quantum computing for your business and beyond!&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This blog provides a concise overview of AWS Braket and its key features. Feel free to expand on specific functionalities or use cases relevant to your audience. Have fun exploring the frontiers of quantum computing!&lt;/p&gt;

</description>
      <category>aws</category>
      <category>awsbraket</category>
      <category>quantum</category>
      <category>quantumcomputing</category>
    </item>
  </channel>
</rss>
