Skip to main content

Agent runtimes

Managed runtimes and copilots. Enforce inline where the runtime allows it, audit out of band where it does not.

Amazon Bedrock AgentCore

A Lambda subscribed to the AgentCore runtime log group. With message content capture on, ADOT writes every GenAI message as its own log record; a subscription filter forwards them, the Lambda rebuilds one evaluation unit per model call and sends the user prompt, tool arguments, tool results and model output to Alice. Verdicts land in CloudWatch and, optionally, as spans inside the agent trace. Nothing in the agent changes and nothing is blocked.

Amazon Bedrock

Turn on Bedrock model invocation logging, point it at S3 or CloudWatch, and let a Lambda forward each logged prompt and response to Alice. Findings, case management and user-level workflows such as a three-strikes rule then run in the Alice platform, next to any Amazon Bedrock Guardrails verdicts you already have. No change to the application; evaluation happens after the fact.

Microsoft Copilot Studio

Alice connects to Microsoft Copilot Studio as an Environment Security Provider (ESP), Microsoft's external threat-detection interface. Enabled once per Power Platform environment, it covers every agent in it: Copilot Studio calls Alice as an agent is about to run a tool, Alice evaluates the tool call, and a blocked tool call is suppressed live. Only tool calls are evaluated; Copilot Studio does not expose user prompts or agent responses to external security providers.

Microsoft Dynamics 365

Dynamics 365 Contact Center agents run on the same framework as custom Copilot Studio agents, so they connect the same way: Alice is registered as an Environment Security Provider (ESP) for the Power Platform environment, Dynamics 365 calls Alice as an agent is about to run a tool, Alice evaluates the tool call, and a blocked tool call is suppressed live. Only tool calls are evaluated; the security provider interface does not expose user prompts or agent responses.