Skip to content Skip to footer

How to Build AI Operations Agents That Diagnose Faster Without Uncontrolled Automation

What Happened

Cornerstone OnDemand built Orion AI, a database operations assistant, in six months with a three-person team. It runs on Amazon ECS, uses Amazon Bedrock and the open-source Strands Agents framework, and supports operations for a platform serving 140 million users across 186 countries. Database diagnosis time fell from 45 to 10 minutes—a reduction of approximately 78%. [1]

The architecture combines a meta-orchestrator with 13 lazily loaded, domain-specific agents. An in-memory keyword routing path handles approximately 80% of queries in under a millisecond; semantic search handles the remainder. That sub-millisecond figure describes routing, not end-to-end agent response time. Amazon Bedrock Knowledge Bases supplies operational documentation when needed. [1]

Agents access operational systems through shared Model Context Protocol (MCP) tools and direct APIs, including SQL Server and Jira. Memory provides conversational context, while live sources supply current-state answers. Controls include scoped access, per-request credentials, human confirmation and restrictions on memory use. CloudWatch and AWS X-Ray provide monitoring and tracing. [1]

Why It Matters to Businesses

The business value comes from shortening operational workflows, not merely adding a chat interface. Orion AI consolidated more than 10 manual lifecycle steps into one interaction, eliminated a 15-minute reporting lag and reduced redundant alerts by a median of 65%. These are reported outcomes from one deployment, not benchmarks every organization should expect. [1]

  • Faster diagnosis: Bringing documentation, live metrics and ticket context into one workflow reduces tool switching.
  • Lower orchestration overhead: Straightforward requests can follow a fast routing path instead of requiring model-based classification at every step.
  • Controlled automation: Diagnosis can be accelerated without giving an agent unrestricted authority to change production systems.

The account does not establish model accuracy, incident-resolution improvement or total operating cost. Buyers should measure those separately before extrapolating the diagnosis-time result.

Kimbodo Engineering Perspective

Use deterministic software where the decision is predictable, and models where interpretation adds value. Orion’s keyword-first routing illustrates this separation. For stable operational categories, explicit routing can reduce latency and avoid unnecessary model calls. The trade-off is maintaining routing rules and handling ambiguous requests safely.

Specialized agents can narrow tool access and simplify instructions, but 13 agents are not inherently better than three. Each additional agent introduces routing tests, permission boundaries and coordination overhead. Start with distinct operational responsibilities and split agents only when evaluation demonstrates a benefit.

Separating memory from live operational truth is equally important. A remembered database status is not evidence of its present condition. Memory should preserve context and preferences; current-state claims should come from timestamped tool results. Orion makes this distinction explicitly. [1]

ECS and managed model access are credible deployment choices, but this case does not establish their superiority over Kubernetes or self-hosted inference. Choose based on existing operating skills, security requirements, utilization and the value of infrastructure control.

How We Would Implement It

  • Start with read-only diagnosis: Select a few frequent workflows and baseline diagnosis time, tool calls, failure rates and cost per completed task.
  • Deploy a containerized orchestration service: Use ECS where AWS is the established platform. Keep routing, authorization and tool execution separate from model-generated decisions.
  • Build tiered routing: Apply validated keyword rules first, then semantic routing for unmatched requests. Ask for clarification when routing confidence is insufficient.
  • Separate retrieval from live data: Use a knowledge base for runbooks and direct APIs or constrained MCP tools for metrics and operational records. Preserve timestamps and provenance in responses.
  • Constrain tool access: Enforce user authorization at execution time. Use short-lived, request-scoped credentials and narrowly defined database operations rather than arbitrary SQL access.
  • Gate changes: Require approval for an exact proposed action, target and parameters. Recheck authorization and relevant system state before execution.
  • Instrument and evaluate: Trace routing, retrieval, model calls and tool execution. Test stale data, incorrect routing, malicious retrieved text and tool failures before expanding access.

Risks, Costs and Security

Retrieved content and tool output must be treated as untrusted data. Runbooks, tickets and database records can contain instructions that attempt to redirect an agent. Enforce permissions outside the model, prevent retrieved text from expanding tool privileges and isolate memory by tenant and user.

Human confirmation is useful only when reviewers can see what will change. Approval should not authorize a vague intention or a different action generated later. Audit records should capture the approved operation and execution outcome without retaining credentials or unnecessary sensitive data.

Budget for inference, retrieval, container capacity, observability, evaluation and integration maintenance. Fast routing may avoid some inference costs, but multi-agent exchanges and growing memory can increase token consumption. The account provides no cost figures; measure cost per successful diagnosis rather than assuming agent orchestration is inexpensive.

The production lesson is straightforward: combine fast routing with verified live data, bounded tools and auditable approvals. Those controls turn conversational assistance into an operational system whose speed and safety can be measured.

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Infrastructure & MLOps practice, or Estimate My Infrastructure.

Sources

  1. [1] How Cornerstone OnDemand cut database diagnosis by 78% with Amazon Bedrock

Leave a comment

0.0/5