Ordered, versioned ledger
Qualified in testsExact revisions, bounded daily pages, correction handling, and independent 400/730-day synthetic-history checks.
RELIABILITY / EVIDENCE BEFORE PROMISES
Enterprise architecture needs more than a green build. Review the ledger, package, customer lifecycle, and live AWS integration as separate boundaries.
Engineering review: 2026-10-04. This is a release-evidence summary, not a live service-status dashboard or a certification.
Exact revisions, bounded daily pages, correction handling, and independent 400/730-day synthetic-history checks.
Pinned Rust build, staged dependency validation, software bill of materials, and independent enabled-handler execution.
Epochs, cancellation fences, bounded draining, export, deletion, and restoration safety remain release gates.
The adapter constructs a request. Sending, partial-result recovery, retrieval verification, supersession, and remote deletion are not complete.
Live AWS permissions, isolation, recovery, service targets, security review, and cost limits still require qualification.
SECURITY REVIEW
Exact source and package identities, dependency inventory, a software bill of materials, structural permission tests, and independent package execution. Tests use controlled AWS transports, not a production customer environment.
Live permissions, tenant isolation under load, incident procedures, customer deletion, and backup recovery still need qualification. Kam does not currently claim a completed security review, compliance certification, or production SLA.
RETENTION IS NOT ONE NUMBER
Retaining a reference is not enough if its supporting record has expired. Each layer needs its own inspection and deletion rules.
| Data layer | Policy | What it means |
|---|---|---|
| Kam working history | 365 UTC dates | The candidate maintains today and the preceding 364 UTC dates. This is a working-window contract, not observed uptime. |
| Kam supporting evidence | May extend beyond one year | The candidate retains supporting revisions and references for up to 730 days, with direct-prior-revision extensions for corrections. Inspection ends when its evidence expires. |
| AgentCore raw events | Configurable, up to 365 days | AWS applies this retention setting to raw short-term events. It is not a universal long-term-memory retention policy. |
| AgentCore long-term records | Separate lifecycle policy | AWS describes explicit deletion workflows. Do not assume the raw-event expiry setting automatically deletes long-term records. |
Logical expiry, physical deletion, export, and backup erasure are separate operations. End-to-end customer deletion is a release gate, not a completed feature.
TAIL LATENCY
Exact keys and bounded pages limit the work of a read. They do not establish a p99 latency number. Acceptance time, local publication lag, AgentCore visibility lag, and read latency must be measured separately under a declared workload.
No production p99 is published yet. Completion latency must be paired with oldest-pending work and failures, so stuck outcomes cannot disappear from the scorecard.
THE NEXT PROOF
The next lifecycle slice must show who may process the remaining 20, through which deadline, and what is disclosed if it cannot finish. Renewal must fence old jobs; a restored backup must not silently revive deleted records. These are planned acceptance criteria.
ONE WORKLOAD. A CLEAR ACCEPTANCE TEST.
Discuss your AgentCore workload, data boundary, and the failure cases an evaluation must prove.