5.1 KiB
hncb-fusion-deid-demo
Demo of the HNCB use case: a reversible PII de-identification round trip through Axway Amplify AI Gateway (Fusion), with the reasoning done by an Amazon Bedrock AgentCore agent. The advisor types a query containing a real name; the cloud only ever sees a token; the real identity is restored before the answer is shown.
Working with Claude Code? Read
CLAUDE.mdfirst — it has the context, commands, and task backlog.
Status: unrun scaffold. Authored, not executed. Review everything, pin dependency versions, and adjust AgentCore specifics to the current CLI. Demo-grade, not production-grade.
Fusion is shared SaaS
Fusion is not deployed by this repo — it's a shared Amplify AI Gateway SaaS
instance, configured in its console (fusion/POLICY_SETUP.md). Because it's SaaS,
anything it calls must be a public HTTPS endpoint with auth. So the AWS side's
job is to expose two endpoints Fusion calls — /tokenize (ingress) and
/restore (egress) — plus host the detector, vault, RAG tool, and agent.
Those two endpoints are the main remaining build (tasks T1/T2 in CLAUDE.md).
What it demonstrates
Raw PII (a Chinese name + a Taiwan ROC ID) is detected on ingress, replaced with a
random, format-safe token, and only the tokenized prompt goes to the cloud
agent. The agent tool-calls back "on-prem" with the token, gets a de-identified
evidence package, and writes talking points. Fusion restores the identity on the
way out. The money shot: show the Bedrock request / AgentCore trace live — the
cloud only ever saw CUST_000123, never 王小明.
Trust zones are logical
Everything is one AWS account. The "on-prem" zone is tag-labelled resources
(Zone = on-prem-VPC-A) standing in for HNCB's branch data centre. Proves
data-flow behaviour, not physical residency — say so on camera.
Component → service map (their 8 steps)
| Step | Component | Service in this repo |
|---|---|---|
| 1, 8 | Advisor UI | ui/index.html on S3+CloudFront (or local) |
| 2, 3-route, 8 | Fusion AI Gateway (the product) | shared SaaS — configured via fusion/POLICY_SETUP.md (not deployed) |
| 2 (ingress), 8 (egress) | /tokenize + /restore endpoints Fusion calls |
TODO gateway_api/ (tasks T1/T2) |
| 2 | PII detector (typed findings, not redaction) | Presidio on Fargate — presidio/ |
| 2, 4, 8 | Token vault (reversible map) | DynamoDB — terraform/main.tf |
| 3, 7 | Cloud agent + model | AgentCore Runtime + Bedrock — agent/ |
| 4 | Tool bridge (Lambda → MCP tool) | AgentCore Gateway — scripts/agentcore_setup.sh |
| 4-6 | On-prem RAG tool + data | Lambda + DynamoDB — lambda_rag/, seed/ |
| all | Observability | AgentCore Observability + CloudWatch |
Repo layout
CLAUDE.md start here if using Claude Code (context + task backlog)
terraform/ DynamoDB (vault + customers), RAG Lambda, IAM, Presidio hosting
lambda_rag/ RAG tool: token resolve -> de-identified evidence package
gateway_api/ TODO: /tokenize + /restore endpoints Fusion SaaS calls (T1/T2)
agent/ Strands agent for AgentCore Runtime + tool schema
presidio/ PII detector service (typed findings) + Dockerfile
seed/ fake customer (Wang Xiaoming) + seed script
ui/ advisor UI (restored-vs-tokenized split view)
scripts/ deploy.sh, agentcore_setup.sh, teardown.sh
fusion/ POLICY_SETUP.md (SaaS console config — the manual part)
Prerequisites
aws-cli configured (creds + region), terraform >= 1.5, docker, python3,
the AgentCore CLI (npm i -g @aws/agentcore), Bedrock model access enabled for
bedrock_model_id, and access to the shared Fusion SaaS instance.
Deploy
bash scripts/deploy.sh # infra -> presidio image -> ECS -> seed -> AgentCore
# then: build /tokenize + /restore (gateway_api/, tasks T1/T2)
# then: configure the shared Fusion SaaS instance (fusion/POLICY_SETUP.md)
# then: point ui/index.html GATEWAY_URL at the Fusion SaaS entrypoint and open it
Demo script (maps to the 8 steps)
- Advisor UI: submit "請幫我整理王小明最近三個月的理財往來,並給我下次拜訪話術。"
- Fusion (via
/tokenize) detects王小明+A123456789, tokenizes, logs tokens only. - Show the Bedrock/AgentCore trace — the prompt the cloud saw contains
CUST_000123. 4-6. Agent tool-calls back on-prem; RAG resolves the token, returns a summary. - Agent writes talking points (no PII).
- Fusion (via
/restore) restores王小明; the UI shows restored beside tokenized.
Teardown
bash scripts/teardown.sh # stop paying for Fargate / AgentCore
Honest caveats
- zh-TW detection is demo-narrow — tuned to the scripted entities, not production recall. That remains the real-engagement risk.
- Per-request randomization lives in the
/tokenizemint step; confirm it satisfies HNCB's "different each time" requirement. - The agentic token-resolution loop (agent tool call → on-prem RAG resolves the token) is custom orchestration by design — where Fusion's depth is the argument.