Cornerstone OnDemand built Orion AI, a multi-agent system using Amazon Bedrock and Strands Agents, and reports that it reduced database-diagnosis time from 45 minutes to 10 minutes. For its Enterprise DataOps engineers, the system consolidates investigation, recommendations and action approval in one operational interface.
The figures come from an AWS-published customer implementation case study. Cornerstone says a three-person team delivered Orion AI in six months to address investigations spread across tools and system views, lifecycle workflows with more than 10 manual steps, a 15-minute SRE-to-data-team reporting lag, and overlapping alerts.
Reported operational results
Cornerstone reports a 78% reduction in database diagnosis time. Previously, engineers connected to affected SQL Server instances, examined blocking chains and wait types, cross-referenced logs for long-running queries, and formed a root-cause hypothesis manually. Orion AI divides that work among three specialist agents and can carry an issue from diagnosis through a recommended fix and a populated Jira ticket for the appropriate on-call engineer.
The company also reports reducing lifecycle work from more than 10 steps to one natural-language interaction, which it describes as a 70% reduction. The system selects tools and data sources, runs cross-system queries, validates results and returns a unified response; engineers are still expected to validate its findings.
Cornerstone says continuous cross-system visibility replaced the prior 15-minute reporting lag. It reports a median 65% reduction in redundant alerts through deduplication, threshold filtering and cross-signal correlation, leaving three or four alerts reaching engineers for every 10 previously generated.
Hub-and-spoke agent design
Orion AI is organized around a Strands-based meta-orchestrator called TaskExecutor. The hub holds routing and control-flow tools rather than domain tools, then invokes independent specialist agents that conduct their own tool-calling loops and return synthesized results. Cornerstone says the implementation has 13 domain-specific agents.
Its SQL Server agents separate distinct operational questions: a database diagnostics agent identifies blocking chains, wait types and long-running queries; a session-blocking agent traces a chain to its root blocker; and a real-time diagnostics agent reads current blocking and high-CPU session data through Cornerstone’s DATAOPS API. Other agents cover areas including infrastructure monitoring, lifecycle management, operational analytics, knowledge retrieval and notification routing.
The architectural choice is to split work by operational domain rather than apparent task complexity, keeping each agent’s tools and prompt limited to its own area. The company presents that boundary as a way to focus model context and tool selection.
Routing and knowledge retrieval
Requests use keyword-first routing, with semantic search used when keywords do not establish intent. Cornerstone says roughly 80% of queries take its in-memory keyword path in under a millisecond; ambiguous requests fall back to semantic routing using Amazon Titan Text Embeddings V2.
When a direct tool call is not suitable, Amazon Bedrock Knowledge Bases retrieves approved operational documentation. That retrieval path is intended to ground responses in documented procedures rather than have the system answer without operational context.
Connections and memory boundaries
The containerized application runs on Amazon ECS. Shared tools, including real-time SQL diagnostics, are reached through a Portal-Tools MCP server using Model Context Protocol. Sources that do not need the shared interface, such as metrics, dashboards and on-call schedules, use direct SDK or REST API calls. Cornerstone says these connections use TLS and that MCP and REST credentials are supplied per request instead of being embedded in agent code.
The system’s memory manager reads three tiers in parallel: DynamoDB for same-session context, Amazon Bedrock AgentCore memory for cross-session recall, and an ephemeral scratchpad for findings exchanged among sub-agents. Retrieval operates with a 500-millisecond hard timeout and a 4,000-token budget. Crucially, current-state questions bypass stored memory and require live data, an explicit measure against stale context entering real-time diagnostics.
Safety controls and observability
Cornerstone says generic content filtering was insufficient for database operations, so it added domain-specific controls. These include prompt-level restrictions on dangerous recommendations, input validation intended to block prompt and SQL injection, output redaction for secrets and personally identifiable information, rate limits, role-based access controls and per-request cost tracking.
Destructive operations pause at a human confirmation gate. A user must confirm within five minutes or the request is denied. A routing-level control also prevents operational questions about current system state from being answered from memory. Amazon CloudWatch records routing confidence, latency and agent activity, while AWS X-Ray traces calls across agent executions.
What the case study does—and does not—show
The transferable choices are narrow agent ownership, a fast routing path with a semantic fallback, and a strict distinction between conversational memory and live operational state. Cornerstone selected ECS because Amazon Bedrock AgentCore runtime was unavailable when the project began, and says it is evaluating a future migration.
The performance results are Cornerstone’s reported outcomes from a single deployment described in an AWS customer case study, not independently verified benchmarks or guarantees for other teams. The implementation also retains human review for destructive actions and depends on live tool execution for current-state answers. Source: AWS Machine Learning Blog.
Definition. Orion AI is Cornerstone OnDemand’s multi-agent Enterprise DataOps system for investigating database issues, recommending fixes and routing approved actions.
| Operational measure | Reported result |
|---|---|
| Database diagnosis time | 45 minutes to 10 minutes (78% reduction) |
| Lifecycle workflow | More than 10 steps to one natural-language interaction (70% reduction) |
| Reporting lag | 15-minute lag replaced by continuous cross-system visibility |
| Redundant alerts | Median 65% reduction; three or four alerts per 10 previously generated |
Key takeaways
- Cornerstone reports a 78% reduction in database-diagnosis time, from 45 minutes to 10 minutes.
- Orion AI uses a hub-and-spoke design with a TaskExecutor orchestrator and 13 domain-specific agents.
- Current-state operational questions bypass stored memory and require live data.
- Destructive operations require human confirmation within five minutes.
- The reported results are from one Cornerstone deployment and are not independently verified benchmarks.
FAQ
How much did Orion AI reduce database diagnosis time?
Cornerstone reports that diagnosis time fell from 45 minutes to 10 minutes, a 78% reduction.
How does Orion AI handle current database-state questions?
It requires live data for current-state questions and bypasses stored memory to limit stale context in real-time diagnostics.
Are destructive database actions automated by Orion AI?
No. Cornerstone says destructive operations pause at a human confirmation gate and are denied if confirmation does not arrive within five minutes.