Checking tens of hundreds of residence leases towards continually altering state landlord-tenant legal guidelines, and proving you truly checked all of them, has been past the attain of most compliance groups. However with generative AI in Amazon Fast, paired with the precise backend, it’s now attainable. On this publish, we introduce a design sample referred to as Adjudicated Question. Enterprise customers can use it to ask compliance questions in a chat interface (Amazon Fast), whereas the precise move/fail selections keep in a deterministic (non-AI) guidelines engine. We stroll by means of an AWS reference structure that implements the sample, and deploy a working pattern you’ll be able to run finish to finish. The sample applies to different high-stakes compliance domains as properly (sanctions screening, insurance coverage claims adjudication, export management), however lease compliance serves as our concrete instance.
The compliance problem at scale
A portfolio operator holds 50,000 leases throughout a number of states. Every state publishes landlord-tenant statutes (late-fee caps, discover intervals, security-deposit limits) that change on the legislature’s schedule, not the operator’s. When a regulation modifications, the workforce accountable for compliance should decide which leases at the moment are out of line.
At small quantity a paralegal reads the leases. The reply is reliable as a result of a human stands behind it. Previous some threshold, that stops being attainable. The work strikes to software program, and a brand new downside seems: the reply is now a quantity on a display that no one can independently confirm.
Two properties observe from that actuality:
- Provable completeness: A declare like “we checked all 22,910 Texas leases” have to be true and demonstrable. A report by no means assessed have to be reported as unevaluated slightly than silently omitted.
- Defensibility: A discovering could also be challenged months later in litigation, an audit, or a regulatory examination. Defending it means figuring out which model of which rule was utilized, to which clause textual content, by what methodology, on what date, and by whom.
These two properties are what distinguish this downside from enterprise search. Retrieval Augmented Technology (RAG) addresses the accessibility hole however can not fulfill both property. Similarity search has no threshold meaning all of them. A ranked pattern by no means is aware of what it excluded.
Textual content-to-SQL narrows this hole, however carries a category-level threat: a hallucinated predicate can silently scale back the inhabitants, and the ensuing quantity seems precise even when the scope is improper.
How the Adjudicated Question sample solves it
The Adjudicated Question sample is a bounded conversational layer over a deterministic guidelines engine. The mannequin does precisely two issues: translate a natural-language query right into a name on a hard and fast set of typed operations, and narrate the outcome that comes again. It by no means writes a question, by no means fixes the inhabitants, and by no means performs a willpower.
Behind the boundary sits a guidelines engine. Guidelines are versioned information, not code. The engine is aware of generic comparability operators (gte, lte, equals, exists) and incorporates no department naming a jurisdiction or subject. A regulation change is a rulebook row edit, not a code deployment.
Each compliance sweep produces a completeness receipt: an asserted invariant the place compliant + in-breach + ambiguous + unreadable should equal scanned. That is computed from counts and asserted earlier than something persists. A run that may’t account for its inhabitants by no means finishes. There’s no path by which a report is silently skipped.
The conversational floor carries counts, the receipt, and a labeled pattern. The complete outcome set (doubtlessly tens of hundreds of rows) lives on a dashboard floor studying the identical information retailer, drillable per report. This separation means the mannequin by no means summarizes away the assure.
Why not RAG or text-to-SQL?
| Strategy | Inhabitants | Completeness | Defensibility |
| Semantic retrieval (RAG) | A ranked pattern | Structurally not possible | Partial |
| Generated queries (text-to-SQL) | Claimed however unprovable | Silent narrowing threat | If modeled |
| Guidelines engine + BI (no chat) | Precise and confirmed | Sure | Sure |
| Adjudicated Question | Precise and confirmed | Sure | Sure |
The Adjudicated Question sample provides natural-language entry to the principles engine plus enterprise intelligence (BI) strategy with out sacrificing the assure. It’s the precise alternative when accountable customers want conversational entry, and a missed report is a legal responsibility slightly than a gentle inconvenience.
Reference structure
The next diagram reveals how the parts match collectively finish to finish. A compliance officer interacts with two surfaces in Amazon Fast: a chat agent for asking questions and an Amazon Fast Sight dashboard for shopping the total outcome set. The chat agent first fetches an OAuth token from Amazon Cognito. It then sends Mannequin Context Protocol (MCP) requests over an Amazon API Gateway HTTP API, which validates the token earlier than forwarding to an AWS Lambda operate. The Lambda operate hosts the MCP server and the principles engine, reads and writes to Amazon Aurora Serverless v2 by means of the RDS Information API, and calls Amazon Bedrock just for the exploratory clause-search path. The Amazon Fast Sight dashboard reads the identical Aurora retailer immediately by means of a digital non-public cloud (VPC) connection. Each surfaces due to this fact learn from one retailer, which is what makes the completeness receipt a single supply of fact.
Each surfaces learn the identical retailer. The chat agent carries the completeness receipt and a hyperlink to the dashboard. The dashboard carries the amount, as a result of 10,800 rows don’t render in a chat message. Amazon Bedrock is named from AWS Lambda solely by the exploratory operation. No mannequin is concerned in compliance sweeps, and Amazon Aurora Serverless v2 doesn’t name a mannequin.
The bounded operation floor
The MCP server exposes precisely six instruments, every with a definite semantic:
| Instrument | What it does | End result means |
| sweep_compliance | Exhaustive inhabitants sweep towards guidelines in power on a said date | Official. Each lease accounted for in a computed receipt. Writes findings |
| simulate_rule_change | One rule examined at a proposed worth towards the authorised baseline | Exploratory. Directional counts solely. Information nothing |
| explore_clauses | Prime Okay by semantic similarity inside a filtered inhabitants | Interpretive. A ranked pattern. Can’t reply “what number of” |
| get_finding | One discovering’s full proof chain | Drill-down right into a single willpower |
| list_rules | The rulebook in power on a date, with variations, citations, approvers | Reference lookup |
| check_connection | Liveness examine, touches no information | Transport well being |
This bounded floor removes the trail to the silent-narrowing threat of generated queries. As a result of the mannequin can solely choose from a hard and fast set of operations whose inhabitants logic was written, reviewed, and examined by folks, it has no technique to compose a improper inhabitants.
Key structure parts
With the Amazon Fast conversational interface and agent orchestration layer, you’ll be able to ask natural-language compliance questions that the Amazon Fast chat agent interprets into calls on the bounded MCP operation floor. Amazon Fast authenticates to the MCP server through the use of OAuth 2LO by means of Amazon Cognito and handles instrument discovery and response narration. The deterministic engine handles the compliance logic.
Amazon Aurora Serverless v2 (Postgres + pgvector) shops the rulebook, lease data, extraction standing, determinations, and runs in a single relational retailer. Placing every little thing in a single database makes the completeness receipt a SQL rely, an economical technique to make the central assure inspectable.
AWS Lambda hosts the MCP server (JSON-RPC 2.0 over Streamable HTTP, utilizing Server-Despatched Occasions framing for responses, which the Amazon Fast consumer requires) and the rule engine. Bounded operations translate to set-based SQL through the use of rule values sure as parameters. No pure language reaches the question layer.
Amazon API Gateway HTTP API gives the entrance door with a JSON Internet Token (JWT) authorizer backed by Amazon Cognito. No unauthenticated route exists.
Amazon Cognito points OAuth tokens by means of a two-legged (consumer credentials) move. The consumer secret is learn from Amazon Cognito at registration time and never written to disk.
Amazon Bedrock powers the exploratory path solely, utilizing Amazon Titan Textual content Embeddings V2 (amazon.titan-embed-text-v2:0) for semantic similarity rating and Anthropic Claude Sonnet 5, invoked by means of a cross-region inference profile, for qualitative clause evaluation. It isn’t consulted for an official compliance willpower. Amazon Bedrock mannequin availability, together with Amazon Titan Textual content Embeddings V2 and Anthropic Claude Sonnet 5, varies by AWS Area, so affirm the fashions can be found in your Area earlier than deploying.
Amazon Fast Sight connects to Aurora by means of a VPC connection and renders the total findings desk, filterable by sweep and severity band, with each column wanted to defend a willpower already on the row.
Design guidelines which can be non-negotiable
- Guidelines are information. A regulation change is a rulebook row. The engine incorporates no jurisdiction-specific department.
- No pure language reaches SQL. Operators choose mounted SQL templates. Rule values bind as parameters.
- Deterministic earlier than AI. A numeric comparability solutions the sweep. No mannequin is consulted.
- Precise filtering for completeness, vectors just for rating. Similarity by no means decides membership.
- Receipts are computed, not written by hand. The invariant is asserted earlier than a sweep commits.
- Unreadable paperwork are named, not dropped. Each lease lands in precisely one bucket.
- Findings are append-only. No UPDATE or DELETE towards findings exists within the code base.
Treating the summarizing mannequin as an untrusted renderer
One design aspect deserves its personal part as a result of it’ll look unfamiliar: engineering safeguards to outlive paraphrase by the chat mannequin.
Excluding the mannequin from the choice path however placing one again within the supply path reintroduces threat on the finish of the chain. In observe, we noticed:
- A mannequin stripped a caveat prefix. An ILLUSTRATIVE quotation tag was eliminated throughout paraphrase, and the mannequin offered an invented quotation as statute.
- A mannequin extrapolated from a pattern. Given 20 preview rows, the mannequin inferred a population-wide vary that didn’t exist within the information.
Three methods handle this:
- Phrase caveats as un-strippable bracketed suffixes repeated at a number of payload ranges, not main labels that learn as detachable metadata.
- Provide the information that makes the sincere reply the simple one. Compute actual aggregates over each report and hand them to the mannequin. A mannequin that has the actual quantity doesn’t must guess from a pattern.
- Repeat mode labels at a number of structural ranges (area, string, abstract) in order that a minimum of one survives paraphrase.
The precept: a safeguard within the payload is just as sturdy as its survival by means of paraphrase.
Deploy and run the pattern
The entire reference implementation is obtainable on GitHub. It ships with artificial information (no actual buyer lease information), deterministic corpus era, and acceptance checks towards the deployed stack.
Conditions
Earlier than deploying, confirm that you’ve got:
- An AWS account with Amazon Bedrock mannequin entry enabled for Amazon Titan Textual content Embeddings V2 and Anthropic Claude Sonnet 5 within the US East (N. Virginia) Area (us-east-1).
- AWS Command Line Interface (AWS CLI) v2 with credentials configured (
aws sts get-caller-identityought to succeed). - Python 3.12.
- Node.js 24 for the AWS Cloud Improvement Equipment (AWS CDK) CLI. mise is optionally available and solely used to provision Node 24. You possibly can set up Node 24 by your alternative of methodology (Node 18 has reached finish of life for CDK).
Step 1: Clone the repository
Clone the pattern repository and arrange the Python atmosphere:
Step 2: Deploy the infrastructure
Bootstrap CDK (if not already finished) and deploy the stack. Aurora provisioning sometimes takes round 11 minutes, although timing varies by account and Area.
The CDK model is pinned to 2.261.0 to match necessities.txt. The stack deploys:
- Amazon Cognito (2LO consumer).
- Amazon API Gateway with JWT authorizer.
- AWS Lambda (MCP server + rule engine).
- Amazon Aurora Serverless v2.
- Amazon Fast Sight networking.
Step 3: Seed information and confirm
Run the migration, corpus era, ingestion, and Amazon Fast Sight setup scripts in sequence:
The corpus is deterministic, so a rebuilt stack reproduces an identical outcomes.
Step 4: Register the MCP integration in Amazon Fast
Amazon Fast snapshots the instrument record at registration time. Amazon Fast doesn’t detect new or renamed instruments till you delete and recreate the combination. Deploying the Lambda alone isn’t sufficient.
Print the registration inputs out of your deployment outputs:
Retrieve the consumer secret (learn from Amazon Cognito every time, not written to disk). Use the consumer pool ID from the Issuer URL in your outputs:
Then in Amazon Fast: Connectors > Create in your workforce > Mannequin Context Protocol. Delete any present entry first, then create a brand new one with these values (OAuth client-credentials/2LO). Copy the consumer secret into Amazon Fast immediately slightly than right into a file or shell variable.
Step 5: Confirm the combination
Confirm the deployment finish to finish, on this order:
The acceptance suite proves the server works. The following part walks by means of the Amazon Fast chat expertise to verify Amazon Fast picks the precise instrument.
Strolling by means of the expertise
With the stack deployed and verified, now you can run a compliance sweep from Amazon Fast chat and examine the outcomes.
Ask a compliance query
In Amazon Fast chat, enter: “Which Texas leases violate the late payment cap? Use guidelines efficient 01/01/2026.”
Amazon Fast identifies this as a compliance sweep and selects the sweep_compliance instrument. The instrument runs an exhaustive examine towards each Texas lease within the inhabitants, making use of guidelines in power on the said date. No mannequin is concerned within the willpower.
Amazon Fast narrates the structured outcome. Determine 2 reveals the chat response: a brief pattern of noncompliant findings in a desk, the completeness receipt rendered as counts, a synthetic-data caveat, and a hyperlink to open the total dashboard.
The response features a pattern of noncompliant findings and the completeness receipt as counts: 10,111 violations, 689 ambiguous, and 20 unreadable. It additionally features a synthetic-data caveat and a hyperlink into the Amazon Fast Sight dashboard. It intentionally doesn’t attempt to render all 10,111 rows.
Confirm the completeness receipt by checking the invariant: compliant + in-breach + ambiguous + unreadable ought to equal the entire scanned inhabitants. On this instance, the counts sum to the entire Texas lease inhabitants, confirming that each report landed in precisely one bucket.
Examine the total inhabitants on the dashboard
Observe the dashboard hyperlink within the chat response to open the Amazon Fast Sight dashboard. Determine 3 reveals the findings tab, the place each lease-rule pair from the sweep seems as its personal row with the total proof chain.
The dashboard shows each discovering from the sweep, one row per lease-rule pair. Use the severity band filter to isolate in-breach findings. Every row carries the lease ID, the rule that fired, the extracted worth, and the anticipated worth. Type by rule to group associated violations and determine patterns throughout the portfolio.
Drill right into a single discovering
Deciding on a row opens the discovering element. Determine 4 reveals a single discovering, with the verbatim lease clause on one aspect and the rule that fired on the opposite, together with its model, quotation, and the in contrast values.
That is what defensibility seems like in observe. The discovering reveals the extracted worth (7 % late payment), the required worth (5 % cap), and the rule quotation (TX Prop. Code ch. 92 subch. B, as amended eff. 2026-01-01). All of this seems alongside the clause textual content verbatim from the lease, so nothing must be reconstructed.
Check further routing paths
Verify Amazon Fast routes to the proper instrument by testing the remaining operations:
- “Discover Texas clauses that learn like legal responsibility waivers.” (ought to invoke
explore_clauses). - “What if the Texas late payment cap dropped to three%?” (ought to invoke
simulate_rule_change).
Cleanup
To keep away from ongoing prices, destroy the stack if you find yourself completed:
Aurora Serverless v2 can scale to 0 Aurora Capability Models (ACU) and robotically pause after a interval of inactivity (see Amazon Aurora pricing). This pattern units a small non-zero minimal capability as an alternative, as a deliberate alternative, as a result of a paused cluster provides resume latency to the primary query of a session. No NAT gateway is deployed.
When you plan to return to the stack later however wish to reduce value between classes, set serverless_v2_min_capacity=0 in infra/stack.py and redeploy to allow scale-to-zero with auto-pause. Count on a brief resume delay on the primary question after the cluster has paused. The corpus is deterministic, so a totally destroyed and redeployed stack reproduces an identical outcomes.
Safety issues
As a result of this sample is constructed for compliance work, safety is a part of the design slightly than an add-on. The pattern applies the next practices, and you must overview every one towards your personal necessities earlier than adapting it.
- Authenticated entry solely. Each request from Amazon Fast reaches the MCP server by means of an Amazon API Gateway HTTP API protected by a JSON Internet Token (JWT) authorizer backed by Amazon Cognito. No unauthenticated route exists, and the two-legged (consumer credentials) OAuth move points short-lived tokens slightly than long-lived keys.
- Secret dealing with. The Amazon Cognito consumer secret is learn at registration time and isn’t written to disk or dedicated to supply management. Retailer it solely within the Amazon Fast connector configuration, and rotate it in your regular schedule.
- Least-privilege mannequin entry. The AWS Lambda execution function grants Amazon Bedrock InvokeModel just for the precise Amazon Titan Textual content Embeddings V2 and Anthropic Claude Sonnet 5 mannequin ARNs the pattern makes use of, not a wildcard over all fashions. Scope AWS Id and Entry Administration (IAM) permissions the identical method in your personal construct.
- Community isolation for the information path. Amazon Fast Sight reaches Amazon Aurora Serverless v2 by means of a VPC connection slightly than a public endpoint, and the database safety group admits solely the anticipated sources. Maintain the shop off the general public web.
- No pure language within the question path. The foundations engine assembles SQL solely from a hard and fast operator-to-template desk with rule values sure as parameters, which removes the injection floor {that a} model-written question would create. This can be a safety property as a lot as a correctness one.
- Auditable, append-only findings. Findings are append-only, with no UPDATE or DELETE path within the code base, so the compliance report can’t be silently altered after the very fact. Every willpower carries its proof chain for later overview.
- Artificial information boundary. The pattern ships with artificial lease information and clearly labeled placeholder guidelines and citations. Earlier than operating towards actual data, full your group’s information classification, entry overview, and authorized validation of any rule content material.
- Human attribution of a sweep. Amazon Fast authenticates to the MCP server machine-to-machine by means of the two-legged (consumer credentials) move, so the token identifies the Amazon Fast software, not the person who requested the query in chat. The engine data what was determined, the rule model, the proof, the tactic, and the date, but it surely doesn’t obtain an end-user id to retailer alongside a discovering. For the “by whom” a part of defensibility, attribution lives within the Amazon Fast audit layer, which data which consumer ran which chat motion. A discovering ties again to an individual by correlating its sweep ID and timestamp with that report. When you want attribution recorded within the compliance retailer itself, thread an end-user ID from Amazon Fast into the instrument name and persist it on the sweep row. The “who” then travels with the discovering slightly than dwelling solely within the Amazon Fast audit layer.
When to make use of this sample
The Adjudicated Question sample applies each time:
- A missed report is a legal responsibility slightly than a gentle inconvenience.
- Solutions is perhaps challenged months later by somebody who was not within the room.
- The governing logic is externally owned and modifications by itself schedule.
- The physique of data is enumerable (you’ll be able to record each report a query covers).
That description covers a variety of domains. Examples embody lease compliance, insurance coverage claims adjudication, sanctions screening, export management, medical trial protocol monitoring, constructing code inspection, monetary reporting controls testing, and credential verification.
RAG is the easier alternative when believable solutions suffice and customers can re-ask. Textual content-to-SQL works properly for groups that may confirm generated queries and tolerate occasional incorrect outcomes. If accountable customers will settle for dashboards with no conversational layer, contemplate a guidelines engine plus BI immediately: it delivers the identical assure at decrease value.
When that is the improper alternative
The sample is heavy: a guidelines engine, a bounded instrument floor, and a completeness receipt. That equipment earns its maintain solely on the precise downside, and copying it onto the improper one provides value with out including belief. Keep away from the sample in three instances.
- The foundations aren’t actually deterministic. The sample works when compliance is a clear comparability, comparable to payment is lower than or equal to a cap, or discover is bigger than or equal to a required variety of days. When the decision is a real judgment, comparable to whether or not a clause is unconscionable or a disclosure is enough, forcing it into this sample hides the subjectivity inside rule-authoring and makes the outcome look precise when it isn’t. Maintain a human within the loop for these determinations slightly than dressing them as deterministic ones.
- Completeness doesn’t matter for the query. If the consumer solely desires a couple of consultant examples, or is exploring slightly than adjudicating, the completeness receipt is overhead for a assure they don’t want. RAG is the easier, appropriate reply for that type of query.
- The inhabitants itself is fuzzy. The receipt proves you lined each report within the inhabitants, not that the inhabitants is the precise one. If the definition of “all Texas leases” is itself contestable, the assure is exact in regards to the improper denominator. Be certain the inhabitants could be drawn by a precise, defensible predicate earlier than you depend on the receipt.
Conclusion
On this publish, we launched the Adjudicated Question sample and demonstrated the way it delivers provably full, defensible compliance solutions by means of the Amazon Fast conversational interface. The sample pairs a bounded MCP operation floor with a deterministic guidelines engine, so the mannequin interprets questions and narrates outcomes however doesn’t contact the selections that produce the assure.
By deploying the pattern stack, asking a compliance query in Amazon Fast chat, and following the outcomes by means of the Amazon Fast Sight dashboard, you walked by means of the total sample finish to finish. The completeness receipt accounts for each report, findings carry their full proof chain, and the split-surface supply retains the assure intact by means of paraphrase.
To get began, clone the sample repository, deploy the stack, register the MCP integration in Amazon Fast, and take a look at asking your first compliance query.
Sources
Concerning the creator




