An agent in an evening, a platform in months

Build an agent in a day, then spend months hardening it for production with AWS architecture lessons on scaling and access control.

  • The Prototype and the Engineering Bill
  • A Demo and a Product Are Different Systems
  • Agent Access Is a Perimeter, Not a Checkbox
  • Why a Simple Result Costs So Much

The Prototype and the Engineering Bill

AWS Analyzed the Architecture Wood Mackenzie's platform on Amazon Bedrock AgentCore: a team builds a working agent prototype in one day, but takes months to bring it to production. The gap between these figures is the engineering bill a company receives when the prototype fails with its second concurrent user.

A Demo and a Product Are Different Systems

A demo agent answers one person in one session.

A working agent serves many users simultaneously, knows who is who, keeps their states separate, and stays within bounds when the context goes beyond the developer's scenario.

A separate engineering layer is built around the model; the model itself is not the issue here. ### What Breaks at Scale

Six things break a prototype when it moves to real users: concurrent access, session isolation, identity, persistent state, horizontal scaling, and guardrails that prevent the agent from doing what is not allowed. AWS's Wood Mackenzie analysis states the problem directly: teams repeatedly rebuild each layer for every new agent instead of putting them in a shared platform and reusing them.

Standardization saves money: the layer is built once, not N times for N agents.

The second part of the equation is observability.

Without it, no one knows under real traffic whether the agent is doing what it should once there are many users and their scenarios diverge from what the developer tested.

Agent Access Is a Perimeter, Not a Checkbox

A separate AWS analysis of MCP tool authorization on Amazon Quick highlights what businesses usually miss: every MCP tool call is a data-access event, and a valid token alone is not enough.

Checks are needed at the call-parameter level, not only to confirm that the user is logged in.

The analysis presents a chain of claims checks from an OIDC JWT token, with role-based and attribute-based controls applied separately to each tool call. The cost of an error is concrete: one incorrectly configured permission entry bypasses access requirements mandatory for compliance, and the issue surfaces during the first audit.

Assess where AI can deliver impact in your process

Why a Simple Result Costs So Much

  1. An agent that answers a question about a report in a demo and an agent that safely serves hundreds of employees with different access levels to the same data look identical in a screenshot.

  2. The first is production-ready; the second is a legal risk with an attractive interface.

  3. The difference lies in layers users do not see: sessions, identity, parameter-based authorization, and scaling.

  4. The business pays for this work: for moving the metric and keeping it from regressing under load, not for a polished demonstration.

Where This Work Is Handled Technically

This is where the LLM & Security Gateway is built: a single point through which agents and MCP tools are authorized, instead of N implementations of the same check across N agents. The same applies to the RAG layer: choosing a vector store—Amazon OpenSearch, Aurora PostgreSQL with pgvector, or S3 Vectors—determines query cost and response latency at thousands of requests per day, while different RAG scenarios in a project may require different stores simultaneously.

Here, AI-native integration means an API call isolated by session, authorized by parameters, and resilient when concurrent users increase from one to a thousand.

Conclusion

It is fair to call an agent a demo if it cannot handle a second concurrent user and does not check permissions at the call-parameter level, no matter how many tasks it solves in a developer's solo session. Companies paying for AI today are paying for months of engineering work that turns a one-day prototype into a result rather than a risk.

Discuss the article: An Agent in an Evening, a Platform in Months

Enter your email or phone number so we can get back to you.

Send via: