AWS has published the Adjudicated Query pattern and a deployable CDK sample that connects Amazon Quick to a bounded MCP server and deterministic rules engine for lease-compliance sweeps. The design gives compliance teams a chat interface without allowing the model to set the population, write SQL or make a pass/fail determination.
The approach is aimed at work where a missed record can create liability and a result may need to withstand later audit, litigation or regulatory review. AWS uses an operator managing 50,000 leases across states as its example, noting that a claim to have checked all 22,910 leases in a jurisdiction must be demonstrable, rather than inferred from a retrieval sample.
A receipt for the whole population
The central mechanism is a computed completeness receipt. Before a sweep can persist, the implementation asserts that compliant, in-breach, ambiguous and unreadable records together equal the scanned population. A run that cannot reconcile those counts does not finish, and unreadable documents are assigned a visible bucket rather than omitted.
AWS contrasts that method with RAG and text-to-SQL. In its framing, semantic retrieval returns a ranked sample and therefore cannot establish population-wide completeness. Generated SQL can provide an apparently exact total while a hallucinated predicate quietly excludes records. The pattern instead keeps population logic in reviewed, fixed operations and represents legal changes as edits to versioned rulebook data rather than jurisdiction-specific application code.
Six tools, with official and exploratory work separated
The MCP server exposes six operations: sweep_compliance, simulate_rule_change, explore_clauses, get_finding, list_rules and check_connection. Only the sweep is an official exhaustive determination that writes findings. Rule-change simulation produces directional counts without recording results, while clause exploration returns a top-K semantic sample and cannot answer a population-wide “how many” question.
Amazon Quick translates a natural-language request into one of those typed operations and narrates its response. The rules engine supplies generic comparisons such as gte, lte, equals and exists; no natural-language input reaches the SQL layer, and rule values are bound as parameters. AWS says findings are append-only, with no UPDATE or DELETE path in the sample.
One data store, two ways to inspect results
The reference architecture puts the MCP server and rules engine in Lambda behind an API Gateway HTTP API with a Cognito-backed JWT authorizer. Aurora Serverless v2 stores leases, rules, extraction status, sweeps and determinations. Amazon Quick’s chat surface and an Amazon Quick Sight dashboard read that same store, so the receipt and detailed record view use a single source of truth.
Chat is deliberately the summary layer: it presents counts, a labeled sample and a dashboard link. The dashboard holds the full table, with one row per lease-rule pair and fields needed to inspect a finding. AWS notes that 10,800 rows are not practical to render in a chat response. In the supplied synthetic Texas example, the response reports 10,111 violations, 689 ambiguous records and 20 unreadable records; the compliant count completes the receipt’s total scanned population.
A detailed finding can pair verbatim clause text with the applied rule version, citation and compared values. AWS’s example shows a 7% late fee assessed against a 5% cap under a rule effective 2026-01-01. These are sample data and placeholder rule content, not real customer lease findings.
Bedrock remains outside official determinations
Amazon Bedrock is used only for the exploratory clause-search route, according to AWS. The sample uses Titan Text Embeddings V2 for similarity ranking and Claude Sonnet 5 for qualitative clause assessment; AWS says neither is consulted during an official compliance sweep. Model availability varies by Region, and the documented deployment prerequisites specify model access in us-east-1.
AWS also treats the model that narrates tool output as an untrusted renderer. The company says it observed a model remove an illustrative-citation caveat and, from 20 preview rows, infer a population-wide range unsupported by the data. Its mitigations include repeating bracketed caveats and mode labels in several payload fields, and supplying real full-population aggregates so the model need not extrapolate from samples.
Sample deployment and operational caveats
The GitHub implementation ships with synthetic data, deterministic corpus generation and acceptance tests. AWS documents Python 3.12, Node.js 24 and AWS CLI v2 as prerequisites. Its migration stage includes 7 checks, and its live acceptance suite contains 28 checks; Aurora provisioning typically takes around 11 minutes, though AWS says timing varies by account and Region.
Quick snapshots its tool list when an MCP integration is registered, AWS says, so adding or renaming a tool requires deleting and recreating the integration. The sample uses machine-to-machine OAuth client credentials, meaning the token identifies the Quick application rather than the person asking in chat. AWS says end-user attribution must therefore be correlated in the Quick audit layer, or an end-user ID must be passed into and stored by the tool path.
Where the pattern does—and does not—fit
AWS recommends the design for enumerable record sets governed by changing external rules, where results can be challenged later. It identifies sanctions screening, insurance claims adjudication and export control as potential applications. If a dashboard is sufficient, AWS says a rules engine plus BI can retain the core guarantee at lower cost than adding chat.
The company cautions against applying the pattern to genuinely subjective decisions, such as whether a clause is unconscionable, because forcing judgment into deterministic rules can make a subjective result appear exact. It also is not suited to questions where completeness is unnecessary or where the definition of the population is itself disputed: the receipt proves coverage of the selected denominator, not that the denominator was correct. Organizations adapting the sample to real records must perform their own data classification, access review and legal validation of rule content.
Source: AWS Machine Learning Blog
Definition. The Adjudicated Query pattern is an AWS reference design for population-wide compliance sweeps in which fixed operations and versioned rules produce auditable determinations.
| Operation | Purpose and determination status |
|---|---|
| sweep_compliance | Runs the official exhaustive determination and writes findings. |
| simulate_rule_change | Produces directional counts without recording results. |
| explore_clauses | Returns a top-K semantic sample and cannot answer population-wide count questions. |
| get_finding | Retrieves a detailed finding for inspection. |
| list_rules | Lists rules available to the workflow. |
| check_connection | Checks the MCP connection. |
Key takeaways
- A computed completeness receipt reconciles all result buckets to the scanned population.
- Amazon Quick routes typed MCP operations and summarizes results, but does not set the population, write SQL or decide pass/fail outcomes.
- Only sweep_compliance creates official exhaustive findings; exploration and simulations are not official determinations.
- Population logic remains in reviewed fixed operations, while changing legal rules are stored as versioned rulebook data.
- Findings are append-only in the sample, and official sweeps do not consult Amazon Bedrock.
- The receipt proves coverage of the selected denominator, not that the denominator itself is correct.
FAQ
What makes an Adjudicated Query sweep auditable?
The design computes a completeness receipt that requires compliant, in-breach, ambiguous and unreadable records to equal the scanned population; unreconciled runs do not finish.
Can Amazon Quick make a compliance determination?
No. In this pattern, Amazon Quick translates requests into typed operations and narrates responses, while the deterministic rules engine performs official determinations.
How does the pattern differ from RAG or text-to-SQL?
AWS describes retrieval as a ranked sample that cannot prove full-population coverage, and keeps population logic in reviewed fixed operations rather than generated SQL.
Which MCP operation produces official findings?
sweep_compliance is the official exhaustive operation that writes findings. Rule-change simulation and clause exploration do not record official results.
Is Amazon Bedrock used during official compliance sweeps?
No. AWS states that Bedrock is used only for exploratory clause search, not for official compliance determinations.
When is this pattern not a good fit?
AWS cautions against subjective decisions, cases where completeness is unnecessary, and questions where the population definition is disputed.