# hncb-fusion-deid-demo Demo of the HNCB use case: a **reversible PII de-identification round trip** through **Axway Amplify AI Gateway (Fusion)**, with the reasoning done by an **Amazon Bedrock AgentCore** agent. The advisor types a query containing a real name; the cloud only ever sees a token; the real identity is restored before the answer is shown. > **Working with Claude Code? Read `CLAUDE.md` first** — it has the context, > commands, and task backlog. > **Status: unrun scaffold.** Authored, not executed. Review everything, pin > dependency versions, and adjust AgentCore specifics to the current CLI. > Demo-grade, not production-grade. ## Fusion is shared SaaS Fusion is **not deployed by this repo** — it's a shared Amplify AI Gateway SaaS instance, configured in its console (`fusion/POLICY_SETUP.md`). Because it's SaaS, anything it calls must be a **public HTTPS endpoint with auth**. So the AWS side's job is to expose two endpoints Fusion calls — **`/tokenize`** (ingress) and **`/restore`** (egress) — plus host the detector, vault, RAG tool, and agent. Those two endpoints are the main remaining build (tasks T1/T2 in `CLAUDE.md`). ## What it demonstrates Raw PII (a Chinese name + a Taiwan ROC ID) is detected on ingress, replaced with a **random, format-safe token**, and only the tokenized prompt goes to the cloud agent. The agent tool-calls back "on-prem" with the token, gets a de-identified evidence package, and writes talking points. Fusion restores the identity on the way out. **The money shot:** show the Bedrock request / AgentCore trace live — the cloud only ever saw `CUST_000123`, never `王小明`. ## Trust zones are logical Everything is one AWS account. The "on-prem" zone is tag-labelled resources (`Zone = on-prem-VPC-A`) standing in for HNCB's branch data centre. Proves data-flow behaviour, not physical residency — say so on camera. ## Component → service map (their 8 steps) | Step | Component | Service in this repo | |---|---|---| | 1, 8 | Advisor UI | `ui/index.html` on S3+CloudFront (or local) | | 2, 3-route, 8 | **Fusion AI Gateway** (the product) | **shared SaaS** — configured via `fusion/POLICY_SETUP.md` (not deployed) | | 2 (ingress), 8 (egress) | `/tokenize` + `/restore` endpoints Fusion calls | **TODO** `gateway_api/` (tasks T1/T2) | | 2 | PII **detector** (typed findings, not redaction) | Presidio on Fargate — `presidio/` | | 2, 4, 8 | Token **vault** (reversible map) | DynamoDB — `terraform/main.tf` | | 3, 7 | Cloud **agent** + model | AgentCore Runtime + Bedrock — `agent/` | | 4 | Tool bridge (Lambda → MCP tool) | AgentCore Gateway — `scripts/agentcore_setup.sh` | | 4-6 | On-prem **RAG tool** + data | Lambda + DynamoDB — `lambda_rag/`, `seed/` | | all | Observability | AgentCore Observability + CloudWatch | ## Repo layout ``` CLAUDE.md start here if using Claude Code (context + task backlog) terraform/ DynamoDB (vault + customers), RAG Lambda, IAM, Presidio hosting lambda_rag/ RAG tool: token resolve -> de-identified evidence package gateway_api/ TODO: /tokenize + /restore endpoints Fusion SaaS calls (T1/T2) agent/ Strands agent for AgentCore Runtime + tool schema presidio/ PII detector service (typed findings) + Dockerfile seed/ fake customer (Wang Xiaoming) + seed script ui/ advisor UI (restored-vs-tokenized split view) scripts/ deploy.sh, agentcore_setup.sh, teardown.sh fusion/ POLICY_SETUP.md (SaaS console config — the manual part) ``` ## Prerequisites `aws-cli` configured (creds + region), `terraform >= 1.5`, `docker`, `python3`, the AgentCore CLI (`npm i -g @aws/agentcore`), Bedrock model access enabled for `bedrock_model_id`, and access to the shared **Fusion SaaS** instance. ## Deploy ```bash bash scripts/deploy.sh # infra -> presidio image -> ECS -> seed -> AgentCore # then: build /tokenize + /restore (gateway_api/, tasks T1/T2) # then: configure the shared Fusion SaaS instance (fusion/POLICY_SETUP.md) # then: point ui/index.html GATEWAY_URL at the Fusion SaaS entrypoint and open it ``` ## Demo script (maps to the 8 steps) 1. Advisor UI: submit *"請幫我整理王小明最近三個月的理財往來,並給我下次拜訪話術。"* 2. Fusion (via `/tokenize`) detects `王小明` + `A123456789`, tokenizes, logs tokens only. 3. Show the Bedrock/AgentCore trace — the prompt the cloud saw contains `CUST_000123`. 4-6. Agent tool-calls back on-prem; RAG resolves the token, returns a summary. 7. Agent writes talking points (no PII). 8. Fusion (via `/restore`) restores `王小明`; the UI shows restored beside tokenized. ## Teardown ```bash bash scripts/teardown.sh # stop paying for Fargate / AgentCore ``` ## Honest caveats - **zh-TW detection is demo-narrow** — tuned to the scripted entities, not production recall. That remains the real-engagement risk. - **Per-request randomization** lives in the `/tokenize` mint step; confirm it satisfies HNCB's "different each time" requirement. - **The agentic token-resolution loop** (agent tool call → on-prem RAG resolves the token) is custom orchestration by design — where Fusion's depth is the argument.