Agent with enforced write control architecture

The pattern for letting an agent touch production: every write passes an approval gate, every action lands in a hash-chained evidence log.

AWSguardrailsevidenceauditgovernance
Task queuedInternal APIPlan the changeDecides what to write andwhyApproval gateguardraildb_writeApplies the approvedchangeBudget capguardrailArcFoundry runtimeruntimeProduction databasedb.t4g.large ·multi-AZ · 100 GBEvidence pack stora…100 GB standardApproval notificati…1M notifications
9 nodes — 3 infrastructure and 6 agent, on one graph. Drawn by the same layout the product uses.
What is in it

Every resource, and what it costs.

Projections from August 2026 list prices for always-on resources. Connect an account and these become the figures your provider actually bills.

Resources in the Agent with enforced write control template with projected monthly cost.
NodeTypeWhat it isProjected
Production databaseDatabasedb.t4g.large · multi-AZ · 100 GB$215/mo
Evidence pack storageStorage100 GB standard$3.00/mo
Approval notificationsMessaging1M notifications$1.00/mo
Task queuedTriggerInternal API
Plan the changeAgent stepDecides what to write and whybilled per token
Approval gateGuardrailEvery production write pauses hereenforced at runtime
db_writeToolApplies the approved change
Budget capGuardrailHalts runs over $80/moenforced at runtime
ArcFoundry runtimeRuntime

Agent steps are priced from provider-reported token usage once the agent runs, not estimated. Guardrails cost nothing and are the reason a runaway agent cannot.

Open Agent with enforced write control on the canvas.

It loads as an editable graph. Connect an account or instrument an agent and the projected figures above become measured ones.