AI Hub Enablement
on Amazon Bedrock
Governed, identity-aware access to Claude and multi-model AI — deployed as AWS's packaged reference architecture, inside your existing AWS account. Per-group model entitlements, spend caps, and an account-enforced guardrail.
Governed AI, Fast
Roll Out AI Access at Scale — Without Building the Plumbing
AI Hub is AWS's partner-enablement reference architecture for rolling out governed AI access at scale: per-group model entitlements, spend caps, and an account-enforced guardrail — without building a custom proxy tier from scratch.
Atayo deploys and validates the package end-to-end in your account, so your team gets a working, tested control layer rather than a stack of unassembled templates. AWS consumption is billed directly by AWS — you own the environment.
At a Glance
- Deployed inside your existing AWS account
- Account-enforced Bedrock guardrail
- Identity-aware: Cognito or enterprise IdP
- Per-group entitlements & spend caps
- Fixed-price, fixed-scope delivery
How It Flows
Governed Access, End to End
Every request travels the same governed path — from the user's client, through identity and the enforced gateway, to the models running in your own AWS account.
Users & Clients
Claude Desktop/Code or any Anthropic / OpenAI-protocol app
Identity
Cognito or enterprise IdP — Entra ID, Okta, Ping, SAML
AI Gateway
Entitlements, spend caps & the account-enforced guardrail
Amazon Bedrock
Claude & multi-model access, in your own AWS account
Every request is authenticated, entitled to the right models, metered against spend caps, and screened by an account-level Bedrock guardrail — with per-persona and per-team reporting.
Which Path Do You Need?
Two Deployment Paths
Both can run in one account, sharing a single enforced guardrail — the paths aren't mutually exclusive. Ask about the combined deployment.
Claude Apps Gateway
Claude-only governed access
Choose this if…
- Users work exclusively in Claude Code or Claude Desktop
- You want BI-grade, per-persona spend reporting (QuickSight)
- A single model vendor (Claude) covers all use cases
- You want the most operationally tested evaluation kit
Multi-Harness Edge
Multi-model, multi-protocol access
Choose this if…
- Any client speaks the OpenAI API, not just Anthropic's
- You need multiple model families (Nova, Llama, Mistral)
- Per-user spend attribution matters, without a paid BI tier
- You want a lighter footprint and to own the gateway image
What's Included
A Structured, Three-Stage Delivery
Every engagement follows the same proven arc — from account validation through deployment and team enablement.
Prerequisites & Account Validation
- Validate dedicated us-east-1 account, Bedrock model access, and service quota headroom
- Confirm identity approach: built-in Cognito vs. enterprise IdP federation (Entra ID, Okta, Ping, SAML)
- Review guardrail scope and account-level enforcement requirements
Package Deployment & Guardrail Enforcement
- Stage and deploy the account-enforced Bedrock guardrail (12 structured identifier types)
- Deploy the gateway stack (Claude Apps Gateway) or edge stack (Multi-Harness), plus dashboards
- Multi-Harness only: build the patched LiteLLM image and mirror to your private ECR
- Execute the full manual validation runbook (PASS/FAIL checks, stop conditions)
Identity, Persona/Team Setup & Enablement
- Configure personas and spend caps (Gateway) or teams and 30-day budgets (Multi-Harness)
- Client configuration for Claude Desktop/Code, or Anthropic/OpenAI-protocol clients
- Runbook handoff and knowledge transfer session with your operations team
Fixed-Scope Delivery
Choose Your Pattern
Each engagement is fixed-scope and completes in a matter of weeks. We'll scope the right fit for your environment and provide pricing during a short discovery call.
Claude Apps Gateway
Claude-only governed access
- Cognito personas with per-group entitlements
- Per-persona spend caps
- 2-tier reporting dashboards (QuickSight)
- Operationally tested evaluation kit
Multi-Harness Edge
Multi-model, multi-protocol access
- 6 model families (Claude, Nova, Llama, Mistral, +)
- OpenAI- and Anthropic-protocol compatible
- Team budgets with 30-day windows
- Cognito token broker; lighter footprint
AWS Landing Zone Integration
Add-on — stacks on either package
- Multi-account / OU structure with dedicated AI OU
- SCPs to lock down Bedrock access
- Networking, inspection, and IdP federation
- Multi-account/Region guardrail deployment
Add-On
Landing Zone Integration
For customers with an AWS Landing Zone already in place, both base packages assume a dedicated, isolated account — not multi-account governance, org-wide SCPs, or existing network/inspection topology. This add-on layers the integration work required to deploy AI Hub inside an established landing zone, priced and scoped as shown in the table above.
- Landing-zone readiness assessment, plus remediation for non-standard networking/account structure
- Dedicated AI OU and accounts, including a separate AI data account for KB/vector stores if RAG is in scope
- SCPs to lock down Bedrock access, and multi-account/Region guardrail deployment
- Networking: separate ingress/inspection, multi-account routing to the inference account, centralized or local VPC endpoints
- External IdP federation with Cognito, and platform-team KT with multi-account runbooks
- CAB prep, security-team review cycles, and guardrail scope negotiation
Governed AI Access. Deployed and Validated.
Talk to an Atayo AI architect about rolling out AI Hub in your AWS account — whether you need Claude-only, multi-model, or a landing-zone integration.