Skip to main content

RELIABILITY / EVIDENCE BEFORE PROMISES

A clear line between tested and ready for production.

Enterprise architecture needs more than a green build. Review the ledger, package, customer lifecycle, and live AWS integration as separate boundaries.

Engineering review: 2026-10-04. This is a release-evidence summary, not a live service-status dashboard or a certification.

Ordered, versioned ledger

Qualified in tests

Exact revisions, bounded daily pages, correction handling, and independent 400/730-day synthetic-history checks.

Complete deployment package

Qualified in CI

Pinned Rust build, staged dependency validation, software bill of materials, and independent enabled-handler execution.

Customer lifecycle

Next implementation

Epochs, cancellation fences, bounded draining, export, deletion, and restoration safety remain release gates.

AgentCore delivery

In development

The adapter constructs a request. Sending, partial-result recovery, retrieval verification, supersession, and remote deletion are not complete.

Production assurance

Not yet qualified

Live AWS permissions, isolation, recovery, service targets, security review, and cost limits still require qualification.

SECURITY REVIEW

Inspect the evidence. Name the remaining work.

Evidence available for review

Exact source and package identities, dependency inventory, a software bill of materials, structural permission tests, and independent package execution. Tests use controlled AWS transports, not a production customer environment.

Not a compliance claim

Live permissions, tenant isolation under load, incident procedures, customer deletion, and backup recovery still need qualification. Kam does not currently claim a completed security review, compliance certification, or production SLA.

RETENTION IS NOT ONE NUMBER

Four policies. No blanket 365-day promise.

Retaining a reference is not enough if its supporting record has expired. Each layer needs its own inspection and deletion rules.

Kam and AgentCore retention responsibilities
Data layerPolicyWhat it means
Kam working history365 UTC datesThe candidate maintains today and the preceding 364 UTC dates. This is a working-window contract, not observed uptime.
Kam supporting evidenceMay extend beyond one yearThe candidate retains supporting revisions and references for up to 730 days, with direct-prior-revision extensions for corrections. Inspection ends when its evidence expires.
AgentCore raw eventsConfigurable, up to 365 daysAWS applies this retention setting to raw short-term events. It is not a universal long-term-memory retention policy.
AgentCore long-term recordsSeparate lifecycle policyAWS describes explicit deletion workflows. Do not assume the raw-event expiry setting automatically deletes long-term records.

Logical expiry, physical deletion, export, and backup erasure are separate operations. End-to-end customer deletion is a release gate, not a completed feature.

TAIL LATENCY

Bound the work. Then measure the service.

Exact keys and bounded pages limit the work of a read. They do not establish a p99 latency number. Acceptance time, local publication lag, AgentCore visibility lag, and read latency must be measured separately under a declared workload.

No production p99 is published yet. Completion latency must be paired with oldest-pending work and failures, so stuck outcomes cannot disappear from the scorecard.

THE NEXT PROOF

Accepted 300. Published 280. Then access changes.

The next lifecycle slice must show who may process the remaining 20, through which deadline, and what is disclosed if it cannot finish. Renewal must fence old jobs; a restored backup must not silently revive deleted records. These are planned acceptance criteria.

ONE WORKLOAD. A CLEAR ACCEPTANCE TEST.

Bring the history your agents depend on.

Discuss your AgentCore workload, data boundary, and the failure cases an evaluation must prove.

Discuss an evaluationSee evaluation scopePrelaunch. No production commitment implied.