Files
hncb-fusion-deid-demo/README.md

5.1 KiB

hncb-fusion-deid-demo

Demo of the HNCB use case: a reversible PII de-identification round trip through Axway Amplify AI Gateway (Fusion), with the reasoning done by an Amazon Bedrock AgentCore agent. The advisor types a query containing a real name; the cloud only ever sees a token; the real identity is restored before the answer is shown.

Working with Claude Code? Read CLAUDE.md first — it has the context, commands, and task backlog.

Status: unrun scaffold. Authored, not executed. Review everything, pin dependency versions, and adjust AgentCore specifics to the current CLI. Demo-grade, not production-grade.

Fusion is shared SaaS

Fusion is not deployed by this repo — it's a shared Amplify AI Gateway SaaS instance, configured in its console (fusion/POLICY_SETUP.md). Because it's SaaS, anything it calls must be a public HTTPS endpoint with auth. So the AWS side's job is to expose two endpoints Fusion calls — /tokenize (ingress) and /restore (egress) — plus host the detector, vault, RAG tool, and agent. Those two endpoints are the main remaining build (tasks T1/T2 in CLAUDE.md).

What it demonstrates

Raw PII (a Chinese name + a Taiwan ROC ID) is detected on ingress, replaced with a random, format-safe token, and only the tokenized prompt goes to the cloud agent. The agent tool-calls back "on-prem" with the token, gets a de-identified evidence package, and writes talking points. Fusion restores the identity on the way out. The money shot: show the Bedrock request / AgentCore trace live — the cloud only ever saw CUST_000123, never 王小明.

Trust zones are logical

Everything is one AWS account. The "on-prem" zone is tag-labelled resources (Zone = on-prem-VPC-A) standing in for HNCB's branch data centre. Proves data-flow behaviour, not physical residency — say so on camera.

Component → service map (their 8 steps)

Step Component Service in this repo
1, 8 Advisor UI ui/index.html on S3+CloudFront (or local)
2, 3-route, 8 Fusion AI Gateway (the product) shared SaaS — configured via fusion/POLICY_SETUP.md (not deployed)
2 (ingress), 8 (egress) /tokenize + /restore endpoints Fusion calls TODO gateway_api/ (tasks T1/T2)
2 PII detector (typed findings, not redaction) Presidio on Fargate — presidio/
2, 4, 8 Token vault (reversible map) DynamoDB — terraform/main.tf
3, 7 Cloud agent + model AgentCore Runtime + Bedrock — agent/
4 Tool bridge (Lambda → MCP tool) AgentCore Gateway — scripts/agentcore_setup.sh
4-6 On-prem RAG tool + data Lambda + DynamoDB — lambda_rag/, seed/
all Observability AgentCore Observability + CloudWatch

Repo layout

CLAUDE.md            start here if using Claude Code (context + task backlog)
terraform/           DynamoDB (vault + customers), RAG Lambda, IAM, Presidio hosting
lambda_rag/          RAG tool: token resolve -> de-identified evidence package
gateway_api/         TODO: /tokenize + /restore endpoints Fusion SaaS calls (T1/T2)
agent/               Strands agent for AgentCore Runtime + tool schema
presidio/            PII detector service (typed findings) + Dockerfile
seed/                fake customer (Wang Xiaoming) + seed script
ui/                  advisor UI (restored-vs-tokenized split view)
scripts/             deploy.sh, agentcore_setup.sh, teardown.sh
fusion/              POLICY_SETUP.md (SaaS console config — the manual part)

Prerequisites

aws-cli configured (creds + region), terraform >= 1.5, docker, python3, the AgentCore CLI (npm i -g @aws/agentcore), Bedrock model access enabled for bedrock_model_id, and access to the shared Fusion SaaS instance.

Deploy

bash scripts/deploy.sh          # infra -> presidio image -> ECS -> seed -> AgentCore
# then: build /tokenize + /restore (gateway_api/, tasks T1/T2)
# then: configure the shared Fusion SaaS instance (fusion/POLICY_SETUP.md)
# then: point ui/index.html GATEWAY_URL at the Fusion SaaS entrypoint and open it

Demo script (maps to the 8 steps)

  1. Advisor UI: submit "請幫我整理王小明最近三個月的理財往來,並給我下次拜訪話術。"
  2. Fusion (via /tokenize) detects 王小明 + A123456789, tokenizes, logs tokens only.
  3. Show the Bedrock/AgentCore trace — the prompt the cloud saw contains CUST_000123. 4-6. Agent tool-calls back on-prem; RAG resolves the token, returns a summary.
  4. Agent writes talking points (no PII).
  5. Fusion (via /restore) restores 王小明; the UI shows restored beside tokenized.

Teardown

bash scripts/teardown.sh        # stop paying for Fargate / AgentCore

Honest caveats

  • zh-TW detection is demo-narrow — tuned to the scripted entities, not production recall. That remains the real-engagement risk.
  • Per-request randomization lives in the /tokenize mint step; confirm it satisfies HNCB's "different each time" requirement.
  • The agentic token-resolution loop (agent tool call → on-prem RAG resolves the token) is custom orchestration by design — where Fusion's depth is the argument.