Skip to main content
In this lesson you’ll implement a hands-on final project: an internal support assistant — a chatbot-style web application backed by Amazon Bedrock. The assistant will provide employees with access to corporate knowledge (for example, HR and VPN policies) assembled into a knowledge base. It must offer a natural-language interface, filter unsafe content both before calling the model and after model responses, and return source attributions for facts it cites. The supplied web UI is intentionally simple so you can concentrate on application logic, Bedrock integration, and safety enforcement.
A slide titled "Internal Support Assistant provides..." showing four blue circular icons. The icons list features: access to corporate knowledge, natural language interaction, filtering unsafe content, and a simple web interface.
This lesson focuses on implementing the application logic, the connection to Bedrock, and the safety and formatting requirements. The supplied web UI is intentionally simple so you can concentrate on functionality.

Project summary

  • Goal: Build an internal support assistant that answers employee questions using a curated knowledge base and Amazon Bedrock, while enforcing safety and predictable formatting.
  • Deliverables:
    • A Flask-based web frontend to accept questions and show answers.
    • Backend logic to validate inputs, retrieve supporting documents, call Bedrock securely, post-process outputs, and return answers with source attributions.
    • Safety filters both pre- and post-model invocation.

Technology stack

  • Python 3.x
  • Flask (lightweight web framework)
  • AWS Bedrock (for LLM runtime)
  • Vector store or keyword-based retrieval for knowledge base
  • VM-based compute instance with an IAM role (no hard-coded credentials)

Minimal Flask skeleton

Place a simple Flask app in app.py. This example highlights the main request flow: validate input, retrieve sources, invoke Bedrock, post-process, and return JSON.

Non-functional requirements

Your project must satisfy the following operational and safety constraints. The table below maps each requirement to an implementation note.
A presentation slide titled "Non-Functional Requirements" with four colored panels. Each panel lists a requirement—"Use a Stateful VM Architecture," "Invoke Bedrock securely using IAM," "Control response length using model parameters," and "Produce consistent formatting"—accompanied by simple icons.
Implementation notes to meet these requirements:
  • Ensure the VM runs with an IAM role that grants Bedrock permissions — never hard-code AWS credentials.
  • Use model parameters (max_tokens, temperature, top_p, stop) to control output length, randomness, and formatting.
  • Enforce predictable structure in responses (for example, returning structured JSON with answer, steps, and sources).

Architecture overview

The end-to-end flow of the assistant:
  1. End user submits a question via the web UI.
  2. Flask app validates and sanitizes the input.
  3. The app queries the knowledge base (local files, vector store, or document store) to find relevant passages.
  4. The app composes a prompt that includes context and sources, then calls the Bedrock runtime via the AWS SDK for Python.
  5. Bedrock returns a generated response; the app post-processes and filters that response.
  6. The app returns the final answer plus source attributions to the UI.
Key responsibilities for the Flask app:
  • Input validation and safety filtering
  • Retrieval and ranking of supporting documents
  • Prompt composition and model parameter tuning
  • Post-processing, output filtering, and formatting
  • Logging and auditable source attribution
A slide titled "Non-Functional Requirements" showing a simple architecture: users on the left connect to a Python Flask app (app.py) hosted on a VM in the center, which in turn communicates with AWS Bedrock on the right.

Safety and filtering

Safeguarding both inputs and outputs is essential. Pre-model (user input) filtering should include:
  • Remove or block disallowed tokens/patterns and illegal or abusive requests.
  • Enforce length limits and sanitize HTML or script content.
  • Normalize whitespace and strip control characters.
Post-model (model output) filtering should include:
  • Redact or remove unsafe content (profanity, PII, disallowed instructions).
  • Verify that factual claims are supported by at least one retrieved source before presenting them as facts.
  • Ensure the response matches required formatting and length constraints.
Always validate that your application does not leak sensitive data and that it enforces organizational safety policies both pre- and post-model invocation.
Practical filtering tips:
  • Keep a deny-list of patterns and a separate allow-list for permitted content types.
  • When in doubt about a model claim, return a conservative answer with a disclaimer and link to the source documents.
  • Log both inputs and model outputs (with access controls) for audit and debugging.

User interface and example output

The supplied UI is intentionally minimal: a text input for the question, an Ask button, and an area that displays the answer with sources. The backend should return structured data so the UI can render the sections consistently. Example JSON response structure your API can return:
Example textual UI output: Your question How do I request VPN access? Answer
  1. To request VPN access, submit a request through ServiceHub. Approval is required from your line manager and the IT Access Approvers group.
  2. Steps:
    • Log in to ServiceHub
    • Navigate to Access Requests
    • Select VPN Access
    • Fill out the request form
    • Submit the request for approval
  3. Escalation: Contact the IT Service Desk for assistance.
Sources included in prompt: acceptable_use.txt, onboarding.txt, password_reset.txt, vpn_access.txt

Implementation guidance and expectations

  • Knowledge base:
    • Build or reuse a knowledge base from the supplied text documents.
    • Retrieval options: simple keyword search, embeddings + vector store, or a document store. Ensure relevance and include correct attributions.
  • Bedrock integration:
    • Use the AWS SDK for Python to call the Bedrock runtime from your Flask app.
    • Make sure the VM’s IAM role has the necessary Bedrock permissions.
  • Model control:
    • Configure max_tokens, temperature, top_p, and stop sequences to produce concise, consistent answers.
    • Test and iterate on prompts to ensure clear, source-backed responses.
  • Formatting and auditability:
    • Return a JSON structure with answer, steps (optional), and sources.
    • Provide clear source attributions so users can verify claims.
  • Frontend:
    • Keep it simple — the UI should render the structured JSON response. Focus engineering effort on backend correctness, safety, and Bedrock integration.

Next steps

With this specification:
  1. Implement the retrieval pipeline for your knowledge base.
  2. Wire up the Flask endpoints to call Bedrock securely (use IAM role auth).
  3. Add pre- and post-filters to handle unsafe content and sensitive data.
  4. Iterate on prompts and model parameters until responses are consistent and well-attributed.
  5. Add logging and monitoring for auditability.
The goal is a working internal support assistant that safely and reliably answers questions with source attributions using Amazon Bedrock.

Watch Video

Practice Lab