{"_id":"@decionis/bedrock-guard","name":"@decionis/bedrock-guard","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@decionis/bedrock-guard","version":"0.1.0","description":"Hard-block guard for Amazon Bedrock Agent action groups — gates each agent action on a signed Decionis Decision Dossier before it touches RDS/S3.","keywords":["decionis","aws","bedrock","agent","action-group","guardrail","governance"],"homepage":"https://decionis.com/docs/integrations/bedrock","bugs":{"url":"https://github.com/decionis/Decionis/issues"},"repository":{"type":"git","url":"git+https://github.com/decionis/Decionis.git","directory":"packages/bedrock-guard"},"license":"UNLICENSED","author":{"name":"Decionis"},"type":"module","sideEffects":false,"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs","default":"./dist/index.js"}},"engines":{"node":">=20"},"dependencies":{"@decionis/sdk":"0.1.0","@decionis/aws-lambda-guard":"0.1.0"},"devDependencies":{"@types/node":"^20.11.30","tsup":"^8.5.1","typescript":"^5.6.3","vitest":"^2.1.8"},"scripts":{"build":"tsup src/index.ts --format esm,cjs --dts --sourcemap --out-dir dist","test":"vitest run","typecheck":"tsc -p tsconfig.json --noEmit","lint":"eslint .","format":"prettier --check . --ignore-path ../../.prettierignore","format:fix":"prettier --write . --ignore-path ../../.prettierignore"},"_id":"@decionis/bedrock-guard@0.1.0","_integrity":"sha512-bykzjRfAFskVtVbd6OQGXLX5TlAtlrtPO1bJNSjqTsY2hvFrc6rXnNal/bnSTTLa4LQTmhAerAgzxejibHxy2g==","_resolved":"/tmp/decionis-release.rR1zPN/decionis-bedrock-guard-0.1.0.tgz","_from":"file:/tmp/decionis-release.rR1zPN/decionis-bedrock-guard-0.1.0.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-bykzjRfAFskVtVbd6OQGXLX5TlAtlrtPO1bJNSjqTsY2hvFrc6rXnNal/bnSTTLa4LQTmhAerAgzxejibHxy2g==","shasum":"062dc5ede4446c9e615c1000f211ce454b036a33","tarball":"https://registry.npmjs.org/@decionis/bedrock-guard/-/bedrock-guard-0.1.0.tgz","fileCount":9,"unpackedSize":68150,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAIwNqcshJoRoKHFe6IPFk7TLdUbCJeaxMVeSVw2IitEAiEAsr3W46OjcflB/whu5FAhCe+fkp5imWBJeq2PLreT5yY="}]},"_npmUser":{"name":"decionis","email":"festus@binariesfort.com"},"directories":{},"maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/bedrock-guard_0.1.0_1785449179327_0.9111270905540831"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-30T22:06:19.128Z","0.1.0":"2026-07-30T22:06:19.458Z","modified":"2026-07-30T22:06:19.753Z"},"maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"description":"Hard-block guard for Amazon Bedrock Agent action groups — gates each agent action on a signed Decionis Decision Dossier before it touches RDS/S3.","homepage":"https://decionis.com/docs/integrations/bedrock","keywords":["decionis","aws","bedrock","agent","action-group","guardrail","governance"],"repository":{"type":"git","url":"git+https://github.com/decionis/Decionis.git","directory":"packages/bedrock-guard"},"author":{"name":"Decionis"},"bugs":{"url":"https://github.com/decionis/Decionis/issues"},"license":"UNLICENSED","readme":"# @decionis/bedrock-guard\n\nHard-block guard for **Amazon Bedrock Agent action groups**. It gates every agent action on a\nsigned Decionis Decision Dossier **before it runs** — the real enforcement boundary between the\nLLM orchestration and the enterprise's data (RDS/S3) is the action group's Lambda, and that is\nexactly where this wrapper sits.\n\nBuilt on [`@decionis/aws-lambda-guard`](../aws-lambda-guard) (same shadow-default safety model)\nand [`@decionis/sdk`](../sdk-node). Mirrors the semantics of\n[`@decionis/langchain`](../langchain-decionis)'s `DecionisGateTool`, adapted to the Bedrock\naction-group contract.\n\n> **Language choice.** Bedrock action-group Lambdas run on the Node.js 20 runtime, so this\n> guard is TypeScript and reuses the existing gate engine with zero duplication. A Python port\n> can later live under `sdks/python` alongside `sdks/python-langchain` for Python action-group\n> runtimes.\n\n## Usage\n\n```ts\nimport { wrapBedrockActionGroup } from \"@decionis/bedrock-guard\";\nimport { resolveGuardConfigFromEnv } from \"@decionis/aws-lambda-guard\";\n\nconst config = resolveGuardConfigFromEnv(); // DECIONIS_BASE_URL / API_KEY / ORG_ID / ...\n\nexport const handler = wrapBedrockActionGroup(\n  async (event) => {\n    // Your real action-group business logic. Only runs when the action is allowed.\n    return runAction(event);\n  },\n  { config, siteBaseUrl: \"https://decionis.com\" },\n);\n```\n\n## Behaviour\n\n- **Shadow-default.** An action's `decision_type` (default `bedrock.<actionGroup>.<action>`)\n  runs in `SHADOW` until promoted via `DECIONIS_ENFORCED_DECISION_TYPES`.\n- **Blocked / held → denial response, not an exception.** When enforced and the outcome is\n  `REJECT` (block) or `REVIEW`/`ESCALATE` (hold), the inner handler never runs and the agent\n  receives a properly-shaped denial it can surface or re-plan around:\n  - function-schema → `functionResponse.responseState = \"FAILURE\"` with the reason + dossier id.\n  - OpenAPI-schema → `httpStatusCode: 403` with an `application/json` error body.\n- **Verify URL.** Set `siteBaseUrl` to embed a public dossier verification link in the denial.\n- **Fail-open by default** (configurable) when the decision graph is unreachable.\n\n## Customizing the decision\n\n- `decisionType`: a string or `(event) => string` to key policy/dossier on your own taxonomy.\n- `buildDecisionRequest`: full control over the decision request (return `null` to skip gating).\n- `onDecision`: observability hook fired for every decision (shadow included).\n","readmeFilename":"README.md","_rev":"1-514e9845a1728fc1bd26a2e8bcc3a2d9"}