Overview
Virtusa's Agentic Governance engagement establishes runtime governance and security for multi-agent systems running on AWS. The engagement covers assessment, implementation, and operation: we inventory the agents an organization already runs, measure them against a defined control baseline, deploy enforcement between those agents and everything they can reach — the model, their tools, their data, and other agents — and leave the customer with an audited control surface and the operating model to keep it.
Delivery uses the Galaxy Agentic Governance Platform as an accelerator. Its guard pipeline is framework-neutral, so agents built on LangGraph, Pydantic AI, or a provider-native tool loop are governed as they are, without re-platforming. Enforcement is installed in a governance-owned AWS environment under a separate identity, exposing LLM, data, and agent-to-agent chokepoints that agent teams call and cannot modify, so the controls hold even when the agent runtime is compromised. We implement one of two AWS paths depending on the customer's estate: Amazon Bedrock behind an API Gateway and Lambda chokepoint, or Bedrock AgentCore with a Cedar policy engine and request/response interceptor Lambdas. In neither path does agent code hold Bedrock credentials.
Implementation includes binding each agent type to its own IAM role through a Non-Human Identity registry, configuring the policy registry so an agent is denied at the chokepoint unless both identity and control policy are in place, and setting the governance floor that per-agent configuration can tighten but never weaken. We wire audit as a SHA-256 hash-chained ledger in DynamoDB and traces through OpenTelemetry to AWS X-Ray, and we install the merge-time and CI gates that keep the developer and governance boundary enforced after we leave.
Each engagement closes on evidence rather than a status report. We run a conformance matrix of 47 controls and 84 checks (49 and 90 where AgentCore is deployed), each exercised on both a pass path and an intercept path, and hand over the resulting self-describing report as audit evidence. Controls are crosswalked to the OWASP Agentic Top 10, NIST AI RMF, ISO/IEC 42001, the EU AI Act, and MITRE ATLAS, so the output maps onto the framework the customer's risk function already uses.
Highlights
- Enforcement outside the agent's trust domain. The same enforcement session runs in-process and again at a governance-owned chokepoint — API Gateway with Lambda, or AgentCore Cedar plus interceptors. Agent code never holds Bedrock credentials.
- 47 controls and 84 checks (and growing) with evidence. Each control has a pass path and an intercept path, crosswalked to OWASP Agentic Top 10, NIST AI RMF, ISO/IEC 42001, EU AI Act, and MITRE ATLAS. Audit is a hash-chained DynamoDB ledger.
- Both AWS paths, one guard pipeline. Bedrock behind an API Gateway chokepoint or Bedrock AgentCore with Cedar — identical controls and evidence on either. Framework-neutral: LangGraph, Pydantic AI, and raw tool loops reach the same pipeline. * Delivered as a professional services engagement. Virtusa runs the baseline assessment, deploys enforcement in a governance-owned account, onboards agent teams to the SDK, and hands over the conformance run as audit evidence.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
Please feel free to contact us for any further details / clarifications
Phone: +1 508 389 7300 Email: marketing@virtusa.com Contact Us URL: