mech.app

The mech.app newsletter

Agentic AI, minus the noise.

Get practical field notes on AI agents, automation, developer tools and security delivered to your inbox.

No spam. Unsubscribe anytime.

AI Agents

Contract Intelligence on AWS: Multi-Agent Extraction and Verification with AgentCore

How AWS AgentCore orchestrates field extraction, cross-validation, and aggregate analytics for vendor contracts without manual RAG tuning.

Source: aws.amazon.com
Contract Intelligence on AWS: Multi-Agent Extraction and Verification with AgentCore

Manual contract review does not scale when you manage hundreds of vendor agreements. RAG chat tools answer single-document questions but fail on portfolio-wide queries like “What is our total annual spend across all SaaS contracts?” AWS published a detailed implementation guide showing how AgentCore orchestrates extraction agents, verification workflows, and analytics integration to turn unstructured contracts into queryable data.

This is not a chatbot. It is a multi-agent pipeline that extracts fields, verifies values, and feeds structured data into Amazon Quick for aggregate analytics.

The Scaling Problem

Legal and procurement teams face a coordination bottleneck:

  • Hundreds of vendor contracts in PDF or scanned image format
  • Manual extraction of renewal dates, payment terms, and liability caps
  • No single source of truth for portfolio-wide questions
  • RAG chat tools retrieve snippets but cannot aggregate across documents

The AWS implementation replaces manual extraction with agent-driven workflows. Extraction agents parse each contract, verification agents cross-check field values, and Amazon Quick provides a query layer for both single-contract lookups and portfolio analytics.

Architecture: Extract, Verify, Query

The platform runs three distinct agent roles:

Extraction Agents
Each agent processes one contract at a time. It uses Amazon Bedrock foundation models to identify structured fields: vendor name, contract value, renewal date, termination clauses, liability limits. The agent writes extracted data to a staging table in Amazon S3.

Verification Agents
A second agent layer reads the staging table and applies validation rules. It checks for missing fields, flags ambiguous values, and compares extracted data against known vendor records. Verification agents can invoke human-in-the-loop workflows when confidence scores fall below a threshold.

Query Layer (Amazon Quick)
Amazon Quick connects to the verified contract data. Users ask natural language questions. Quick translates queries into SQL, runs them against the structured dataset, and returns answers with source citations.

The orchestration flow looks like this:

  1. Upload contract PDFs to S3
  2. AgentCore triggers extraction agents in parallel
  3. Extraction agents write structured fields to staging table
  4. Verification agents validate and flag anomalies
  5. Approved data moves to production table
  6. Amazon Quick queries production table for analytics

State Management and Parallelization

AgentCore handles state isolation so extraction agents do not collide. Each agent receives a unique contract ID and writes to a namespaced partition in S3. The orchestrator tracks agent status in DynamoDB:

# Simplified orchestration pseudocode
def orchestrate_extraction(contract_ids):
    for contract_id in contract_ids:
        agent_task = {
            "contract_id": contract_id,
            "s3_input": f"s3://contracts/raw/{contract_id}.pdf",
            "s3_output": f"s3://contracts/staging/{contract_id}/",
            "status": "pending"
        }
        dynamodb.put_item(TableName="AgentTasks", Item=agent_task)
        invoke_extraction_agent(agent_task)

The orchestrator polls DynamoDB for task completion. When all extraction tasks finish, it triggers the verification layer. This design avoids race conditions and allows horizontal scaling: you can process 500 contracts in parallel by provisioning more Lambda functions or ECS tasks.

Verification Layer: Handling Disagreement

Extraction agents sometimes produce conflicting values. For example, one agent might extract a contract value of “$1.2M annually” while another reads “$1,200,000 per year” from a different clause. The verification layer resolves conflicts using:

  • Confidence scores: Bedrock models return confidence metadata. The verification agent picks the highest-confidence extraction.
  • Cross-reference checks: It compares extracted vendor names against a known vendor database.
  • Human escalation: If confidence scores are close or values conflict, the agent flags the contract for manual review.

The verification agent writes a decision log to S3. This log becomes an audit trail for compliance teams.

Portfolio-Wide Queries vs. Single-Contract Lookups

Amazon Quick handles two query patterns:

Single-contract lookups
”What is the renewal date for the Acme Corp contract?” Quick retrieves one row from the production table and returns the answer with a citation link to the source PDF.

Aggregate analytics
”What is our total annual spend on cloud infrastructure contracts?” Quick runs a SQL aggregation across all contracts tagged with “cloud infrastructure” and returns a sum.

The key difference is memory architecture. Single-contract queries do not require agent memory. Aggregate queries rely on structured data in the production table, which agents populated during extraction. This separation means you can scale analytics independently from extraction workloads.

Failure Modes and Observability

The platform exposes several failure points:

Failure ModeDetectionMitigation
Extraction agent timeoutCloudWatch timeout alarmRetry with longer timeout or split PDF into pages
Low confidence extractionVerification agent flagsHuman-in-the-loop review queue
Verification agent disagreementConflict log in S3Escalate to manual review with side-by-side comparison
Quick query timeoutQuery execution time metricAdd indexes to production table or cache frequent queries
Stale data in production tableData freshness timestampScheduled re-extraction jobs for updated contracts

AWS recommends enabling X-Ray tracing for the full pipeline. Each agent emits trace segments, so you can visualize the end-to-end flow from PDF upload to Quick query response.

Deployment Shape

The reference architecture uses:

  • Amazon Bedrock for foundation model inference (Claude or Titan models)
  • AWS Lambda for lightweight extraction agents
  • Amazon ECS for long-running verification agents
  • Amazon S3 for contract storage and staging tables
  • Amazon DynamoDB for orchestration state
  • Amazon Quick for natural language query interface
  • AWS Step Functions for orchestration (optional, if you need complex branching logic)

You can deploy the entire stack with CloudFormation or CDK. The AWS blog post includes a CDK sample that provisions IAM roles, S3 buckets, and Lambda functions.

Security Boundaries

Contract data is sensitive. The platform enforces:

  • Encryption at rest: S3 buckets use KMS encryption
  • Encryption in transit: All API calls use TLS
  • IAM role separation: Extraction agents cannot write to production table, only staging
  • VPC isolation: ECS tasks run in private subnets with no internet access
  • Audit logging: CloudTrail logs all S3 and DynamoDB access

Verification agents run in a separate IAM role with write access to the production table. This prevents a compromised extraction agent from poisoning the verified dataset.

Trade-Offs: Agents vs. RAG Chat

ApproachStrengthsWeaknesses
RAG chatFast to prototype, no schema designCannot aggregate across documents, no structured output
Agent extractionStructured data, portfolio analytics, audit trailHigher upfront orchestration complexity, slower initial setup

RAG chat works for exploratory questions on a small number of contracts. Agent extraction makes sense when you need repeatable workflows, compliance reporting, and aggregate analytics.

Technical Verdict

Use this pattern when:

  • You manage 50+ contracts and need portfolio-wide analytics
  • Compliance or audit teams require structured data with provenance
  • You already run AWS infrastructure and want native integration with Bedrock and Quick
  • You can invest in orchestration setup and verification workflows

Avoid this pattern when:

  • You have fewer than 20 contracts (manual extraction is faster)
  • Your contracts are highly unstructured with no consistent fields
  • You need real-time extraction (this pipeline is batch-oriented)
  • You lack AWS expertise or prefer vendor-agnostic tooling

The platform shines when you treat contract data as a structured asset, not a document archive. If your goal is ad-hoc chat over PDFs, stick with RAG. If your goal is repeatable extraction and analytics, the agent pipeline delivers.