> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rotascale.com/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS Bedrock

> Govern AWS Bedrock with one line: watch_bedrock wraps `converse` and `invoke_model`, and every model call, tool call and retrieval lands on the trajectory.

Bedrock runtime, for either API shape.

```python theme={"system"}
import boto3
from rotascale.middleware import watch_bedrock

client = watch_bedrock(boto3.client("bedrock-runtime", region_name="eu-central-1"))
```

That is the whole integration. From here every call the client makes is recorded
on the open trajectory.

## What is distinctive

Records the **region** the call was served from. On a deployment that declares a residency region, a call served outside it is a finding rather than something nobody notices — see [deployment](/deployment).

## In context

```python theme={"system"}
from rotascale import Rotascale

client = Rotascale()
agent = client.agent("refund-bot")

with client.witness(agent) as trajectory:
    trajectory.authorize(GRANT, {"tools": ["issue_refund"]}, amount_minor=4_500)
    # ... your AWS Bedrock calls here, already wrapped ...
```

The `witness` block opens the trajectory and closes it on exit, including when
the body raises — an episode that ended badly is exactly the one worth having a
record of.

## Recording without content

```python theme={"system"}
watch_bedrock(client, capture_content=False)
```

Shape and metadata only: model, latency, token counts, tool names. No prompt or
response text. The governed facts are unchanged.

<Tip>
  Authority is never asked for by an adapter. It stays an explicit
  `trajectory.authorize(...)` call, so importing a middleware can never become a
  spend decision. See [authorise an action](/guides/authorise-an-action).
</Tip>
