An AI-powered platform that ingests architecture artifacts and acts like a board of specialists — Solution, Security, FinOps, Compliance, and Executive advisors — to identify risks, assess compliance, estimate cloud cost, and produce executive-ready recommendations, every answer grounded in cited evidence.
Upload your architecture. Ask a question. Get a board-level review with evidence.
Architecture review depends on scarce senior experts and tribal knowledge. Reviews are slow, inconsistent, and rarely produce an audit trail.
An always-available AI review board that delivers consistent, explainable, governance-grade assessments in under a minute.
Faster decisions, lower review cost, documented compliance evidence, and a one-page CIO summary for every engagement.
One orchestrator coordinates five specialist perspectives — the way a real review board works.
System design, patterns, scalability.
IAM, network, encryption, threat modeling.
Cost estimation and optimization.
PIPEDA, GDPR, HIPAA, EU AI Act, governance.
Business language, ROI, risk summaries.
A supervisor agent that interprets the request, delegates to the right specialists in parallel, and synthesizes the final verdict — it holds no tools of its own, so it can't fabricate numbers.
Actual output from a live board run on the seeded retail-csp demo (Claude Sonnet 4.5, ca-central-1): “Can this architecture support an autonomous AI support agent handling Canadian customer PII?”
No formal PII handling / data-classification standard for the AI assistant (Schedule 1 Principles 4.3 / 4.4 / 4.7).
Same PII-governance gaps; data-residency for model inference unverified.
No NIST AI RMF / ISO 42001 / EU AI Act classification, guardrails, or human-in-the-loop.
Solid serverless foundation, but 5 critical blockers: PIPEDA gap, over-permissive IAM + no MFA, unverified data residency, no AI governance, single-region (no DR).
Adopt a PII standard, decompose IAM to least-privilege + enforce MFA, add Bedrock Guardrails + HITL, design multi-region DR, right-size compute.
$1,016.68/mo now → $455–$673/mo optimized (34–55% savings). ~$68K one-time remediation; CIO/CISO go/no-go at the Week-10 gate.
Every figure above came from the deterministic Action Group tools + RAG retrieval with source citations (NFR-004) — not free-form model output. Full transcript: docs/demo-output.md.
Regulated data plane runs in ca-central-1, directly supporting the PIPEDA / data-residency story.
Recommendations cite source documents with a reasoning summary and confidence score — governance-grade, not a black box.
Prompt, response, sources, tools invoked, user, and timestamp are logged for every action.
Serverless throughout; the demo design drops idle cost to near zero while keeping a production scale-up path.
As built across four CDK stacks (Foundation · Data · Agent · Api). React SPA → API Gateway → Lambda → a Bedrock supervisor agent that delegates to five collaborator agents, each calling its own deterministic Action Groups — all on a KMS-encrypted, audited, ca-central-1 data plane.
ADR-0013, as built: a SUPERVISOR orchestrator that owns no tools — it plans, delegates, and synthesises — with five separate collaborator agents, each granted only the Action Groups it needs (least privilege per specialist). All specialists share retrieveContext for grounding.
A full board run takes ~30–60s, past API Gateway's hard 29s timeout — so POST /review returns 202 { reviewId } immediately and a worker Lambda runs the agent off the request (ADR-0012).
review.invoke audit record (NFR-003).
Every significant decision is captured as an immutable, Nygard-style ADR in docs/adr/.
| ADR | Decision | Rationale (short) | Status |
|---|---|---|---|
| 0001 | Record architecture decisions | Model the governance discipline the product enforces. | Accepted |
| 0002 | Bedrock Agents for orchestration | Managed, AWS-native multi-agent coordination. | Accepted |
| 0003 | Bedrock KB + OpenSearch Serverless (RAG) | Managed retrieval with citations — production target. | Accepted* |
| 0004 | Claude Sonnet as foundation model | Strong long-doc reasoning + reliable tool calling. | Accepted |
| 0005 | Lambda Action Groups for tools | Deterministic, testable, auditable capabilities. | Accepted |
| 0006 | Cognito + RBAC + KMS | Managed identity, persona RBAC, CMK encryption. | Accepted |
| 0007 | S3 for documents & artifacts | Durable object store + event-driven ingestion. | Accepted |
| 0008 | React SPA behind API Gateway | Clean FE/BE split; central auth & throttling. | Accepted |
| 0009 | IaC tooling — AWS CDK (TypeScript) | One language across FE + infra; built as 4 stacks. | Accepted |
| 0010 | ca-central-1 region | Canadian data residency for PIPEDA. | Accepted |
| 0011 | Lightweight vector store (demo) | Near-zero idle cost; RAG as an Action Group. | Accepted |
| 0012 | Async review via job + poll | Survives ~30–60s board runs past API Gateway's 29s limit. | Accepted |
| 0013 | Supervisor + collaborator topology | Separate agents, least-privilege tools per specialist. | Accepted† |
| 0014 | EventBridge ingestion trigger | Auto-ingest on upload with no cross-stack cycle. | Accepted |
* ADR-0003 remains the production target; ADR-0011 amends it to scope OpenSearch Serverless to production and introduce the demo retrieval path. † ADR-0013 refines ADR-0002 with the as-built supervisor/collaborator wiring (requires aws-cdk-lib ≥ 2.260).
Demo and production differ only behind the retrieveContext interface — the agent and UI are retrieval-backend agnostic.
Upload → S3 → EventBridge → ingest extracts/chunks/embeds (Titan) → vectors + citations in a DynamoDB table → retrieveContext Lambda runs similarity search and returns top-k chunks + citations.
Bedrock Knowledge Base backed by OpenSearch Serverless (built as OpenSearchKnowledgeBase, switched on by retrievalMode: 'prod'): managed chunking/embedding/sync and native Agent↔KB integration with horizontal scale.
Cognito SRP authN, RBAC by persona (enforced, #45), KMS CMKs at rest, TLS in transit, least-privilege IAM.
Append-only DynamoDB audit table — writers hold PutItem only; prompt, response, sources, actions, user, timestamp.
Evidence, source docs, reasoning summary, confidence on every recommendation.
CloudWatch dashboard + alarms (API 5xx, worker errors), X-Ray tracing, Budgets→SNS cost alerts (#11/#16/#19).
As built in infra/: four stacks — Foundation (KMS, S3, Cognito, Budgets), Data (DynamoDB, ingest, EventBridge), Agent (supervisor + 5 collaborators + Action Groups), Api (API Gateway + handlers + observability).
Typed JSON request/response per tool. Business logic lives in Lambda (unit-testable), not in prompts.
| Action Group | Function | Output shape |
|---|---|---|
| AG-001 Scoring | scoreArchitecture() | { security, reliability, cost, compliance } (0–100) |
| AG-002 Cost | estimateCost() | Monthly estimate across EC2/ECS/Lambda/OpenSearch/Bedrock/S3/RDS |
| AG-003 Compliance | assessCompliance() | pass / warning / fail per PIPEDA · GDPR · HIPAA · SOC2 · ISO27001 |
| AG-004 Diagram | generateDiagram() | Mermaid or PlantUML source → S3 artifacts bucket |
| AG-005 Threat model | generateThreatModel() | STRIDE analysis · risk matrix · mitigations → S3 artifacts |
| RAG Retrieval | retrieveContext() | top-k chunks + source citations (query, projectId, topK) |
request {"architectureId":"123"} →
response {"security":87,"reliability":91,"cost":73,"compliance":80}
| Collaborator agent | Granted Action Groups |
|---|---|
| Solution Architect | retrieveContext · scoreArchitecture · generateDiagram |
| Security Architect | retrieveContext · scoreArchitecture · generateThreatModel |
| FinOps | retrieveContext · estimateCost |
| Compliance | retrieveContext · assessCompliance |
| Executive Advisor | retrieveContext · scoreArchitecture · estimateCost |
| Supervisor / Orchestrator | none — plans, delegates, synthesises only |
Event-driven: an S3 upload triggers chunking, embedding, and indexing.
Upload — SPA gets a pre-signed URL and PUTs the file (PDF/DOCX/TXT/MD/PNG/JPG/SVG/PPTX) directly to the KMS-encrypted uploads bucket.
Trigger — the bucket emits an Object Created event to EventBridge; a rule in the Data stack (matched by bucket name, so no cross-stack cycle — ADR-0014) targets the ingest Lambda.
Extract — txt/md read directly; PDF/DOCX/PPTX go through the extractor (#22).
Chunk + embed — text is chunked and embedded with amazon.titan-embed-text.
Index — demo: write vectors + source citations to the DynamoDB Vectors table. Prod (retrievalMode: 'prod'): sync into OpenSearch Serverless via the Bedrock KB.
Retrieve — at query time retrieveContext embeds the query, runs similarity search, returns top-k chunks + citations.
React SPA (Tailwind), Cognito SRP auth, REST via API Gateway, direct-to-S3 pre-signed uploads. Local mock mode + Playwright e2e (#71/#73).
NodejsFunction Lambdas: project, upload, retrieve, review + review-worker (async). Job + poll for the <60s budget (ADR-0012).
Bedrock supervisor + 5 collaborator agents, Claude Sonnet via cross-region inference profile; Titan embeddings for RAG.
3 S3 buckets (uploads / reports / artifacts) + 3 DynamoDB tables (Projects / Vectors / Audit), all KMS-CMK encrypted, PITR on.
Cognito + persona RBAC (enforced), KMS CMKs, append-only audit (PutItem-only), least-privilege IAM per Lambda & per agent.
AWS CDK (TypeScript), 4 stacks, Jest construct tests; CloudWatch dashboard + alarms, X-Ray, Budgets→SNS; pinned to ca-central-1.
estimateCost needs a maintained AWS pricing source (AG-002).retrieveContext contract.foundation-stack.ts / api-stack.ts, ADR-0008).CfnAgent wiring (needs aws-cdk-lib ≥ 2.260); L2 aws-bedrock-alpha is the eventual target (ADR-0009/0013).Jump straight to the code on GitHub — bdot-real/arch-review.
The 4 CDK stacks, Lambdas, and construct tests.
Supervisor + 5 collaborators + Action Group wiring.
Per-specialist agent definitions (instructions + tools).
Deterministic tools: score · cost · compliance · diagram · threat.
Production RAG: OpenSearch Serverless + Bedrock KB (#18).
RAG retrieval Action Group (Titan + similarity).
React + Tailwind SPA · mock mode · Playwright e2e.
14 architecture decision records (0001–0014).
Full transcript of a live board run.
Canonical report layout + data source per section.
Product + functional/non-functional requirements.
~52 of 61 closed; the rest deploy/quota-gated.