Memory hook: The model proposes; tools act; policy decides whether an action is allowed.
Must remember
- An agent uses a model, instructions, state and tools to work toward a goal. A fixed workflow follows predefined steps; an agent can choose among actions dynamically. Use the simpler workflow when its decision structure is sufficient.
- A tool has an interface/schema, permissions and observable results. Validate arguments and outputs. Require human approval for consequential actions where appropriate. Retries need idempotency so a timeout does not create duplicate purchases or updates.
- MCP standardises how supported clients connect to tools and resources; it does not grant trust or make every exposed tool safe. Multi-agent designs may use a supervisor, delegation or peer interaction. More agents introduce coordination, latency and failure modes, not guaranteed quality.
- Short-term state tracks the current task; longer-term memory persists selected facts. Apply data minimisation, isolation, retention and deletion policies. Never mix one customer's retrieved data or memory with another's context.
- Bedrock Agents provides managed agent capabilities; AgentCore provides services for operating agents, including runtime and identity-related capabilities. Strands Agents is an agent-development framework. Choose components based on control and operating requirements, not similar names.
- Current AWS objectives also mention Amazon Quick for business AI experiences and Kiro for AI-assisted development. These are not substitutes for the underlying identity, model evaluation and application security controls. Product branding evolves; use the exam's current terminology.
- Evaluate whole-task completion, valid tool choice, argument accuracy, loop rate, latency and total cost. Add execution limits, safe failure paths and traces so an agent that repeats a tool indefinitely can be diagnosed and stopped.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Known approval steps and deterministic branches | Workflow orchestration. |
| A model must choose among approved business tools | An agent with scoped permissions and validation. |
| Several specialised agents share work | Explicit orchestration, state boundaries and end-to-end evaluation. |
Traps
- Tool discovery is not tool authorisation.
- Memory can preserve incorrect or sensitive information.
- Successful text generation is not the same as successful completion of an external action.
Active recall
1. Why should a payment tool use an idempotency key?
A retry after an ambiguous timeout must not charge twice.
2. Does MCP authenticate every business user automatically?
No. Authentication and authorisation remain explicit design responsibilities.
3. When is a fixed workflow preferable?
When known steps and branches meet the requirement with less operational uncertainty.
4. Which metric catches an agent that speaks well but never completes a booking?
End-to-end task completion, including verification of the tool result.
5. Why limit iterations?
To bound runaway loops, cost and repeated side effects.