Skip to main content

AI Hub Enablement
on Amazon Bedrock

Governed, identity-aware access to Claude and multi-model AI — deployed as AWS's packaged reference architecture, inside your existing AWS account. Per-group model entitlements, spend caps, and an account-enforced guardrail.

Governed AI, Fast

Roll Out AI Access at Scale — Without Building the Plumbing

AI Hub is AWS's partner-enablement reference architecture for rolling out governed AI access at scale: per-group model entitlements, spend caps, and an account-enforced guardrail — without building a custom proxy tier from scratch.

Atayo deploys and validates the package end-to-end in your account, so your team gets a working, tested control layer rather than a stack of unassembled templates. AWS consumption is billed directly by AWS — you own the environment.

At a Glance

  • Deployed inside your existing AWS account
  • Account-enforced Bedrock guardrail
  • Identity-aware: Cognito or enterprise IdP
  • Per-group entitlements & spend caps
  • Fixed-price, fixed-scope delivery

Anthropic ClaudePowered by Amazon Bedrock

How It Flows

Governed Access, End to End

Every request travels the same governed path — from the user's client, through identity and the enforced gateway, to the models running in your own AWS account.

1

Users & Clients

Claude Desktop/Code or any Anthropic / OpenAI-protocol app

2

Identity

Cognito or enterprise IdP — Entra ID, Okta, Ping, SAML

3

AI Gateway

Entitlements, spend caps & the account-enforced guardrail

4

Amazon Bedrock

Claude & multi-model access, in your own AWS account

Governed, end to end

Every request is authenticated, entitled to the right models, metered against spend caps, and screened by an account-level Bedrock guardrail — with per-persona and per-team reporting.

Which Path Do You Need?

Two Deployment Paths

Both can run in one account, sharing a single enforced guardrail — the paths aren't mutually exclusive. Ask about the combined deployment.

Claude Apps Gateway

Claude-only governed access

Choose this if…

  • Users work exclusively in Claude Code or Claude Desktop
  • You want BI-grade, per-persona spend reporting (QuickSight)
  • A single model vendor (Claude) covers all use cases
  • You want the most operationally tested evaluation kit

Multi-Harness Edge

Multi-model, multi-protocol access

Choose this if…

  • Any client speaks the OpenAI API, not just Anthropic's
  • You need multiple model families (Nova, Llama, Mistral)
  • Per-user spend attribution matters, without a paid BI tier
  • You want a lighter footprint and to own the gateway image

What's Included

A Structured, Three-Stage Delivery

Every engagement follows the same proven arc — from account validation through deployment and team enablement.

1

Prerequisites & Account Validation

  • Validate dedicated us-east-1 account, Bedrock model access, and service quota headroom
  • Confirm identity approach: built-in Cognito vs. enterprise IdP federation (Entra ID, Okta, Ping, SAML)
  • Review guardrail scope and account-level enforcement requirements
2

Package Deployment & Guardrail Enforcement

  • Stage and deploy the account-enforced Bedrock guardrail (12 structured identifier types)
  • Deploy the gateway stack (Claude Apps Gateway) or edge stack (Multi-Harness), plus dashboards
  • Multi-Harness only: build the patched LiteLLM image and mirror to your private ECR
  • Execute the full manual validation runbook (PASS/FAIL checks, stop conditions)
3

Identity, Persona/Team Setup & Enablement

  • Configure personas and spend caps (Gateway) or teams and 30-day budgets (Multi-Harness)
  • Client configuration for Claude Desktop/Code, or Anthropic/OpenAI-protocol clients
  • Runbook handoff and knowledge transfer session with your operations team

Fixed-Scope Delivery

Choose Your Pattern

Each engagement is fixed-scope and completes in a matter of weeks. We'll scope the right fit for your environment and provide pricing during a short discovery call.

Claude Apps Gateway

Claude-only governed access

  • Cognito personas with per-group entitlements
  • Per-persona spend caps
  • 2-tier reporting dashboards (QuickSight)
  • Operationally tested evaluation kit
Get Started
Most Popular

Multi-Harness Edge

Multi-model, multi-protocol access

  • 6 model families (Claude, Nova, Llama, Mistral, +)
  • OpenAI- and Anthropic-protocol compatible
  • Team budgets with 30-day windows
  • Cognito token broker; lighter footprint
Get Started

AWS Landing Zone Integration

Add-on — stacks on either package

  • Multi-account / OU structure with dedicated AI OU
  • SCPs to lock down Bedrock access
  • Networking, inspection, and IdP federation
  • Multi-account/Region guardrail deployment
Get Started

Add-On

Landing Zone Integration

For customers with an AWS Landing Zone already in place, both base packages assume a dedicated, isolated account — not multi-account governance, org-wide SCPs, or existing network/inspection topology. This add-on layers the integration work required to deploy AI Hub inside an established landing zone, priced and scoped as shown in the table above.

  • Landing-zone readiness assessment, plus remediation for non-standard networking/account structure
  • Dedicated AI OU and accounts, including a separate AI data account for KB/vector stores if RAG is in scope
  • SCPs to lock down Bedrock access, and multi-account/Region guardrail deployment
  • Networking: separate ingress/inspection, multi-account routing to the inference account, centralized or local VPC endpoints
  • External IdP federation with Cognito, and platform-team KT with multi-account runbooks
  • CAB prep, security-team review cycles, and guardrail scope negotiation

Governed AI Access. Deployed and Validated.

Talk to an Atayo AI architect about rolling out AI Hub in your AWS account — whether you need Claude-only, multi-model, or a landing-zone integration.