Add guardrail to seahaven-alex agent #38
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#38
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/bedrock-guardrail"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Audit finding M-19 — Alex had no Bedrock guardrail despite returning QBO/payment/WO/PO/HR data. Adds prompt-attack + content filters and PII masking scoped to credential/financial identifiers only (vendor names/contacts intentionally unmasked — that's the bot's job).
Validation
zjlcfq5vjic5v1 attached, agent re-prepared,livealias → agent version 10.bedrock-agent-runtimeon the live alias: SA8000 misconduct-reporting question answers normally (MISCONDUCT output=MEDIUM regression check); prompt-injection attempt returns the guardrail block message.Tests
Live invocation smoke tests as above;
tsc --noEmit+ synth clean.Notes
guardrail/*version ARNs), explicit CFN dependencies added, ASCII apostrophe + version labels cleaned up.kmsKeyArn(config-at-rest CMK) — follow-up, consistent with account encryption posture work.