AWS Training
Modules Listen Certification

← The Quick Suite AI Layer

Q9 lab — the AI layer, hands on

Before you start

Write your answers to Q1–Q10 down. The point is evidence, not vibes.

Part 1 — Spaces and the permission exception

  1. Create a space named lab-q9 (console: Spaces → Create). Q1: After creation, run aws quicksight list-spaces --aws-account-id <acct> — what is the space's ID and your permission level on it?
  2. Upload two files: any PDF and a .csv. Watch the status walk Uploading → Processing → Text ready → Ready. Q2: How long did each stage take, and could you query the PDF's text before its status hit Ready?
  3. Link one existing dashboard into the space (skip if none — note it).
  4. Share the space with a colleague (or test user) as Viewer. Have them open it. Q3: Which can they open — the uploaded files, the linked dashboard, or both? Explain the difference using the rule from lesson 2.
  5. Deliberate failure #1: As the viewer, try to delete the space. Record the exact error. Q4: What permission level is required to delete, and what happens to the files vs the linked dashboard when a delete succeeds?

Part 2 — Chat scoping and the audit trail

  1. Open chat. Ask the same question ("what were our top items last month?" or similar) three times: once in General knowledge, once in All data and apps, once in Specific data and apps pinned to lab-q9. Q5: For each mode, note what sources (if any) the citations point at, and which answers carry an Explanations panel.
  2. If you have a SPICE dataset: pin chat to it, ask a numeric question, open Explanations → Generated SQL. Q6: Paste the SQL. Does it match what you'd have written?

Part 3 — Build a custom agent

  1. Chat agents → Create chat agent → natural-language flow: "An agent that answers questions about the files in the lab-q9 space, in a formal tone, and refuses questions outside that scope." Review what Generate produced in the builder.
  2. Move the "refuses questions outside scope" instruction into Persona instructions (if the generator didn't), link lab-q9 under Knowledge sources, and add one suggested prompt. Launch it, then share it to your test user as Viewer.
  3. Q7: Ask the agent something answerable only from your uploaded PDF, and something clearly out of scope. Record both behaviors. Then run aws quicksight describe-agent --aws-account-id <acct> --agent-id <id> (get the ID from list-agents) — what AgentLifecycle state is it in?
  4. Deliberate failure #2: Try to attach an 11th resource (or in the API, an 11th space) to the agent. Record the error. Q8: Which documented limit did you hit, and is it adjustable?

Part 4 — A flow with a real limit

  1. Flows → create from natural language: "Ask the user for a topic, search the web for it, summarize the top findings in three bullets." Run it in run mode.
  2. Open the visual editor and count the steps; note the step types against lesson 5's list.
  3. Q9: Try to add a schedule. Does your home Region allow it? Relate what you see to the documented Region list (us-east-1, us-west-2, eu-west-1).

Part 5 — Research (optional, burns ~0.5 agent hour)

  1. Start a Research run on a topic you know well, sources = web + the lab-q9 space. Note the progress display while it runs (20–40 min — go do Part 6).
  2. When it lands: click two citations, then use Understand the statement on one claim. Q10: Did the evidence actually support the claim? Export the report to PDF.

Part 6 — Where the logs are

  1. In CloudTrail (home Region), find the events for your CreateSpace / CreateAgent / DescribeAgent calls from this lab. Record one event ID.
  2. Look for your chat questions from Part 2 in CloudTrail. You won't find them. Then check whether CloudWatch vended logs (CHAT_LOGS) are enabled in your account — if not, enable them now if you're authorized; that's the day-one governance task from lesson 6.

Teardown

Done when you can

Facilitator notes