End-to-end workflow
Follow feedback from sign-in and file upload to analysis and notification.
The architecture combines managed services around one feedback processing flow.
Components and responsibilities
| Component | Service | Responsibility |
|---|---|---|
| Authentication | Cognito | Sign-up, sign-in, and authentication tokens |
| API interface | API Gateway | Expose routes and validate authenticated requests |
| File storage | S3 | Store uploaded documents and recordings |
| Compute | Lambda | Handle API, upload, and processing events |
| Job queue | SQS | Buffer and decouple analysis work |
| Notifications | SNS | Distribute completion events |
| Result storage | DynamoDB | Store processing metadata and feedback insights |
| AI pipeline | Textract, Transcribe, Bedrock | Extract content and analyze it |
Processing sequence
- The user signs in through Cognito and obtains a token.
- An authorized API request obtains permission to upload, and the user sends the file to S3.
- The upload event invokes a Lambda handler, which enqueues a processing job in SQS.
- A consumer Lambda receives the job and starts the appropriate extraction or transcription process.
- Once the source content is ready, Bedrock analyzes it into structured insights.
- The worker stores the result and processing metadata in DynamoDB.
- A completion event is published to SNS for users or organizers who need a notification.
- The user or organizer retrieves the result through an API that checks access to that feedback.
Boundaries to preserve
The upload response should not wait for the AI analysis. Queue messages identify files rather than carrying their contents. Authentication happens before user-facing operations, and authorization is enforced when accessing a specific file or result.
Track asynchronous service jobs across their completion events. Store enough processing state to retry failures without producing duplicate insights or completion alerts.