![]()
๐งญ Three Horizons: Static Baseline โ Static-Enhanced โ AWS Serverless AI
๐ฏ v1.x Today ยท v2.0 Keep Static, Go Deeper ยท v3.0+ Amazon Bedrock Serverless
๐ Document Owner: CEO | ๐ Version: 3.0 | ๐
Last Updated: 2026-05-31 (UTC)
๐ Review Cycle: Quarterly | โฐ Next Review: 2026-08-31
๐ข Owner: Hack23 AB (Org.nr 5595347807) | ๐ท๏ธ Classification: Public
This document is the strategic architecture roadmap for Riksdagsmonitor, organised around three architectural horizons. It is deliberately honest about what exists today versus what is aspirational, and labels every future target as a target โ never as an achieved metric.
| Horizon | Version | Window | Thesis |
|---|---|---|---|
| ๐ข Horizon 1 | v1.x | Today (2026) | Static baseline โ pre-rendered HTML/CSS, 14 languages, AWS CloudFront + S3, autonomous AI newsroom in the build pipeline. Proven, cheap, near-zero attack surface. |
| ๐ต Horizon 2 | v2.0 | 2026โ2027 | Keep static, go deeper โ same zero-backend delivery model, but richer party-focused dashboards and advanced OSINT/INTOP analytics. AI stays in the build/newsroom pipeline; every published artifact remains a static file. |
| ๐ฃ Horizon 3 | v3.0+ | 2028โ2037 | All-in AWS serverless โ Lambda, Amazon Bedrock (+ Agents & Knowledge Bases), API Gateway, Cognito, DynamoDB, Aurora Serverless v2, Neptune Serverless, OpenSearch Serverless, Timestream, Step Functions, EventBridge. Zero infrastructure, Well-Architected, multi-region. |
"At Hack23 AB, we have made a strategic decision to build our future on AWS serverless architecture. This means zero infrastructure management, no Kubernetes, no containers to maintainโjust pure serverless compute, managed AI services, and AWS's deep expertise in security and compliance. By standardizing entirely on AWS, we eliminate operational complexity and leverage Amazon Bedrock for all AI capabilities. But we get there deliberately: we will exhaust the value of the static model first, because the cheapest, safest political-intelligence platform is one with no servers to attack. This document openly shares our staged roadmap โ static today, static-but-deeper tomorrow, serverless AI thereafter."
โ James Pether Sรถrling, CEO, Hack23 AB
| Document | Focus | Description |
|---|---|---|
| Architecture | ๐๏ธ Current | C4 models (Context, Container, Component) |
| Data Model | ๐ Current | Entities, schemas, relationships |
| Flowcharts | ๐ Current | Process flows and data pipelines |
| State Diagrams | ๐ Current | System state transitions |
| Mindmaps | ๐ง Current | Conceptual system maps |
| SWOT | ๐ผ Current | Strategic position assessment |
| Future Architecture | ๐ This Document | AWS serverless roadmap, AI enhancement |
| Future Data Model | ๐ Future | Aurora, DynamoDB, Neptune data architecture |
| Future Flowcharts | ๐ Future | Bedrock AI workflows, Step Functions orchestration |
| Future State Diagrams | ๐ Future | AI-enhanced state transitions, event-driven workflows |
| Future Mindmaps | ๐ง Future | Future capability evolution, AWS service relationships |
| Future SWOT | ๐ผ Future | Future strategic opportunities |
| Security Architecture | ๐ก๏ธ Security | Defense-in-depth controls |
| Future Security Architecture | ๐ก๏ธ Future | Planned AWS security enhancements (GuardDuty, WAF) |
| Threat Model | ๐ฏ Security | STRIDE threat analysis |
This document outlines the architectural evolution of Riksdagsmonitor across three horizons (2026โ2037). We do not jump straight to the cloud: the roadmap deliberately extracts maximum value from the current static model before committing to a serverless backend.
graph LR
H1["๐ข Horizon 1 โ v1.x<br/>Static Baseline (Today)<br/>HTML/CSS ยท 14 langs ยท CloudFront+S3<br/>AI newsroom in build pipeline"]
H2["๐ต Horizon 2 โ v2.0<br/>Static-Enhanced (2026โ2027)<br/>Party & OSINT dashboards<br/>Same zero-backend delivery"]
H3["๐ฃ Horizon 3 โ v3.0+<br/>AWS Serverless AI (2028โ2037)<br/>Bedrock ยท Lambda ยท API Gateway<br/>Public political-intelligence API"]
H1 --> H2 --> H3
style H1 fill:#4caf50,stroke:#2e7d32,color:#000000
style H2 fill:#2196f3,stroke:#1565c0,color:#000000
style H3 fill:#9c27b0,stroke:#6a1b9a,color:#ffffff
Horizon 1 โ v1.x Static Baseline (Today): A pre-rendered HTML/CSS website in 14 languages, served from AWS CloudFront + multi-region S3 with GitHub Pages disaster recovery. An autonomous AI newsroom (gh-aw agentic workflows, Claude Opus 4.8 authoring / Sonnet 4.6 translation) produces evidence-graded analysis artifacts that are aggregated and rendered to static news pages. No backend, no login, near-zero attack surface.
Horizon 2 โ v2.0 Keep Static, Go Deeper (2026โ2027): We retain the entire static delivery model and instead deepen the analysis: party-focused dashboards (cohesion, coalition dynamics, bloc alignment, party-vs-party, agenda tracking) and advanced OSINT/INTOP tradecraft (network, temporal and geospatial analysis, anomaly detection, source-graded evidence, scorecards). AI remains confined to the build/newsroom pipeline โ every published artifact is still a static file behind the CDN.
Horizon 3 โ v3.0+ AWS Serverless AI (2028โ2037): Once the static model is exhausted, we migrate to a pure AWS serverless backend with zero infrastructure management โ no Kubernetes, no containers, no EC2. Amazon Bedrock provides all runtime AI (incl. Agents and Knowledge Bases for RAG); Lambda + API Gateway expose a public political-intelligence API; data lives in Aurora Serverless v2, DynamoDB, Neptune Serverless, OpenSearch Serverless and Timestream.
AWS Serverless Strategy (Horizon 3):
AWS Serverless Foundation Stack (Horizon 3):
| Layer | AWS Services | Purpose |
|---|---|---|
| AI/ML | Amazon Bedrock, Bedrock Agents, SageMaker Serverless | Frontier Claude Opus, Llama, Nova; election forecasting |
| Compute | AWS Lambda (Python, Node.js) | Serverless functions |
| API | Amazon API Gateway, AppSync (GraphQL) | Public political-intelligence API |
| Identity | Amazon Cognito | API auth, tiered access |
| Data | Aurora Serverless v2, DynamoDB | Relational + NoSQL |
| Search | OpenSearch Serverless, Bedrock Knowledge Bases | Full-text + vector/RAG search |
| Graph | Neptune Serverless | Entity & coalition relationship networks |
| Time-Series | Timestream | Historical trends, forecasting |
| Storage | S3, CloudFront | Object storage + CDN |
| Orchestration | Step Functions, EventBridge, Kinesis | Workflow + streaming automation |
Key Milestones:
Current State (2026 Q2 โ Horizon 1, achieved):
๐ข Horizon 1 โ v1.x Static Baseline
๐ต Horizon 2 โ v2.0 Static-Enhanced (2026โ2027) 2. Horizon 2 โ v2.0 Keep Static, Go Deeper
๐ฃ Horizon 3 โ v3.0+ AWS Serverless AI (2028โ2037) 3. Future C4 Architecture Models (AWS Serverless) 4. AI Enhancement Roadmap (Amazon Bedrock) 4A. Political-Intelligence Capability Architecture (OSINT/INTOP, to 2037) 5. Scalability Improvements 6. AWS Serverless Architecture Evolution 7. Advanced Features Roadmap 8. Migration Strategy (AWS-Only) 9. Risk Assessment (AWS-Specific) 10. Success Metrics 11. Timeline & Milestones 12. Related Documentation
๐ Cross-Cutting (Horizon 3 detail) โ Well-Architected ยท Security Services ยท Multi-Region ยท Resilience Hub ยท Enterprise Integration ยท IMF Integration
Technology Stack:
IntersectionObserverscripts/imf-client.ts), World Bank (non-economic only), CIA platform exportsCurrent Capabilities:
Architecture Strengths:
Current Characteristics:
analysis/daily/$DATE/$SUB/; scripts/aggregate-analysis.ts concatenates them into a canonical article.md + SHA-256 provenance manifest; scripts/render-articles.ts + scripts/render-lib/ converts markdown to sanitised HTML (news/$DATE-$SUB-{en,sv}.html); news-translate extends to the remaining 12 languages out-of-band โ zero manual HTML editingCurrent News Pipeline (aggregate-then-render):
analysis/daily/$DATE/$SUB/*.md (AI-authored artifacts โ 9 per article)
โ produced by 10 per-type news workflows
โผ
scripts/aggregate-analysis.ts (concat + SHA-256 manifest)
โ
โผ
scripts/render-articles.ts (markdown โ sanitised HTML via rehype)
+ scripts/render-lib/ (chrome: JSON-LD NewsArticle, hreflang, CSP)
โ
โผ
news/$DATE-$SUB-{en,sv}.html (2 languages per CI run)
โ news-translate workflow
โผ
news/$DATE-$SUB-{da,nb,fi,de,fr,es,nl,ar,he,ja,ko,zh}.html (12 more)
This is the baseline that Horizon 2 deepens without changing the delivery model, and that the Horizon 3 AWS Serverless future state in ยง3โยง11 eventually migrates to a backend.
Thesis: The single biggest near-term win is not a backend โ it is better analysis. Horizon 2 keeps the entire static delivery model of Horizon 1 (pre-rendered HTML/CSS, CloudFront + S3, no login, no servers) and invests instead in party-focused dashboards and advanced OSINT/INTOP tradecraft. AI remains confined to the build/newsroom pipeline; every published artifact is still a static file behind the CDN. This is the cheapest, safest way to deepen Riksdagsmonitor's intelligence value before taking on serverless operational complexity.
| Dimension | Horizon 1 (v1.x today) | Horizon 2 (v2.0) | Horizon 3 (v3.0+) |
|---|---|---|---|
| Delivery | Static HTML/CSS on CDN | Unchanged โ static HTML/CSS on CDN | AWS serverless backend |
| Backend | None | None (deliberate) | Lambda + API Gateway |
| AI placement | Build/newsroom pipeline | Build/newsroom pipeline (deeper analytics) | Runtime via Amazon Bedrock |
| Dashboards | 11 general dashboards | + Party cohesion, coalition, bloc, party-vs-party, agenda | Interactive API-backed views |
| OSINT depth | Source-graded articles | + Network / temporal / geospatial / anomaly detection | + RAG, conversational queries |
| Attack surface | Near-zero | Near-zero (unchanged) | Managed AWS controls |
| Cost model | CDN + CI only | CDN + CI only | Pay-per-request serverless |
C4Context
title Horizon 2 โ Riksdagsmonitor Static-Enhanced Context (v2.0, 2026-2027)
Person(citizen, "Citizens & Voters", "14 languages, WCAG 2.1 AA, no login")
Person(journalist, "Journalists & Researchers", "Party dashboards, OSINT scorecards, CSV export")
Person(analyst, "Political Analysts", "Network / temporal / geospatial intelligence views")
System(riksdag, "Riksdagsmonitor (Static)", "Pre-rendered HTML/CSS + lazy-loaded TS dashboards on CloudFront + S3")
System_Ext(newsroom, "AI Newsroom (build-time)", "gh-aw agentic workflows ยท Claude Opus 4.8 / Sonnet 4.6")
System_Ext(riksdag_api, "Riksdagen API", "data.riksdagen.se open data")
System_Ext(regeringen, "Regeringen (g0v.se)", "Government documents")
System_Ext(scb, "SCB PxWeb v2", "Swedish official statistics")
System_Ext(imf, "IMF (primary economic)", "Datamapper + SDMX 3.0 ยท scripts/imf-client.ts")
System_Ext(worldbank, "World Bank (non-economic)", "Governance, social, environment")
Rel(citizen, riksdag, "HTTPS via CloudFront")
Rel(journalist, riksdag, "Dashboards + CSV download")
Rel(analyst, riksdag, "OSINT/INTOP analytic pages")
Rel(newsroom, riksdag, "Commits static artifacts (article.md โ HTML)")
Rel(newsroom, riksdag_api, "Fetch votes, MPs, documents")
Rel(newsroom, regeringen, "Fetch government docs")
Rel(newsroom, scb, "Fetch statistics")
Rel(newsroom, imf, "Fetch economic indicators (primary)")
Rel(newsroom, worldbank, "Fetch non-economic indicators")
UpdateLayoutConfig($c4ShapeInRow="3", $c4BoundaryInRow="1")
Architecture: Identical zero-backend delivery to Horizon 1. The only growth is in the build pipeline (more analysis artifacts, more dashboard bundles) and in the static assets served. There is still no runtime compute โ every box below is either a build-time job or a static file on the CDN.
C4Container
title Horizon 2 โ Riksdagsmonitor Static-Enhanced Containers (v2.0)
Person(user, "Users", "Browser only โ no login")
System_Boundary(edge, "Delivery Edge (unchanged from v1.x)") {
Container(cloudfront, "CloudFront", "Global CDN (600+ edge)", "TLS, caching, OAC to S3")
Container(s3, "S3 Static Origin", "us-east-1 primary + eu-west-1 replica", "HTML, CSS, JS bundles, CSV, JSON")
Container(pages, "GitHub Pages", "Disaster Recovery origin", "Failover static mirror")
}
System_Boundary(site, "Static Site (pre-rendered)") {
Container(html, "HTML/CSS Pages", "14 languages, cyberpunk theme", "index, dashboards, news, intelligence")
Container(dash, "Dashboard Bundles", "TypeScript + Chart.js/D3.js", "Lazy-loaded via IntersectionObserver")
Container(party, "Party Dashboards (NEW)", "TS modules", "Cohesion, coalition, bloc, party-vs-party, agenda")
Container(osint, "OSINT/INTOP Views (NEW)", "TS + D3.js", "Network, temporal, geospatial, anomaly, scorecards")
Container(data, "Data Files", "CSV / JSON", "MPs, votes, documents, indicators")
}
System_Boundary(build, "Build Pipeline (CI โ no runtime compute)") {
Container(newsroom, "AI Newsroom", "gh-aw + Node 26", "Authors evidence-graded analysis artifacts")
Container(aggregate, "aggregate-analysis.ts", "Node script", "Concat artifacts โ article.md + SHA-256 manifest")
Container(render, "render-articles.ts", "Node + rehype", "Markdown โ sanitised HTML")
Container(etl, "Data ETL", "Node scripts", "imf-client.ts, SCB, Riksdagen โ CSV/JSON")
}
System_Ext(sources, "Open Data Sources", "Riksdagen, Regeringen, SCB, IMF, World Bank")
Rel(user, cloudfront, "HTTPS")
Rel(cloudfront, s3, "Origin fetch (OAC)")
Rel(cloudfront, pages, "DR failover")
Rel(s3, html, "Serves")
Rel(s3, dash, "Serves")
Rel(s3, party, "Serves")
Rel(s3, osint, "Serves")
Rel(s3, data, "Serves")
Rel(newsroom, sources, "Fetch (build-time)")
Rel(etl, sources, "Fetch (build-time)")
Rel(newsroom, aggregate, "Artifacts")
Rel(aggregate, render, "article.md")
Rel(render, html, "Static HTML")
Rel(etl, data, "CSV/JSON")
Rel(render, s3, "Deploy")
Rel(etl, s3, "Deploy")
UpdateLayoutConfig($c4ShapeInRow="3", $c4BoundaryInRow="1")
All of these are client-side TypeScript dashboards rendered from pre-computed CSV/JSON โ no backend queries.
| Dashboard | Intelligence Question | Primary Evidence |
|---|---|---|
| Party Cohesion | How often do a party's MPs vote together? | Vote records per dok_id, party whip deviations |
| Coalition Dynamics | Which parties co-vote, and is it strengthening? | Pairwise co-vote matrices over time |
| Bloc Alignment | Is the left/right bloc structure holding? | Bloc-level agreement indices |
| Party-vs-Party | Head-to-head agreement/conflict on issues | Issue-tagged vote divergence |
| Agenda Tracking | What is each party pushing this session? | Motion/interpellation volume by policy area |
Structured intelligence tradecraft applied to public data only, fully within Hack23 ISMS and GDPR Art. 9 lawful bases 9(2)(e)/9(2)(g):
dok_id, named actor, vote count, or primary-source URL; reliability grading per editorial standardsgraph TB
subgraph SRC["๐ฅ Build-Time Inputs (public data)"]
V["Vote records<br/>3.5M+ votes"]
D["Documents<br/>109,000+"]
M["MP registry<br/>349 current / 2,494 historical"]
end
subgraph PROC["โ๏ธ CI Analytics (Node scripts, no runtime)"]
NET["Network graphs<br/>centrality / clustering"]
TMP["Temporal trends<br/>agenda / discipline"]
ANO["Anomaly detection<br/>explainable flags"]
end
subgraph OUT["๐ฅ๏ธ Static OSINT Views (TS + D3.js)"]
SC["Neutral scorecards"]
GV["Graph visualisations"]
TL["Temporal timelines"]
end
V --> NET
V --> ANO
D --> TMP
M --> NET
NET --> GV
TMP --> TL
ANO --> SC
style SRC fill:#e3f2fd,stroke:#1565c0,color:#000000
style PROC fill:#fff3e0,stroke:#e65100,color:#000000
style OUT fill:#e8f5e9,stroke:#2e7d32,color:#000000
๐ฃ Horizon 3 (v3.0+, 2028โ2037). Everything from ยง3 onward describes the post-static serverless backend. It is activated only after Horizon 2 has exhausted the value of the static model. Until then, these are targets, not deployed systems.
Vision: Transform Riksdagsmonitor into a multi-country political intelligence platform with AI-enhanced analysis and real-time monitoring, built entirely on AWS serverless services.
C4Context
title Future Riksdagsmonitor Context - AWS Serverless (2026-2028)
Person(global_user, "Global Users", "14+ languages, mobile apps, web PWA")
Person(researcher, "Academic Researchers", "GraphQL API access, data export")
Person(media, "News Media", "Embeds, webhooks, RSS feeds")
Person(business, "Business Intelligence", "Political risk API, regulatory monitoring")
System(riksdag, "Riksdagsmonitor", "AWS Serverless Political Intelligence Platform")
System_Ext(nordic_apis, "Nordic Parliament APIs", "DK, NO, FI legislative data")
System_Ext(eu_api, "EU Parliament API", "European legislative data")
System_Ext(bedrock, "Amazon Bedrock", "Claude Opus 4.8, Llama 4 405B, Nova Premier")
System_Ext(riksdag_api, "Swedish Riksdag API", "data.riksdagen.se open data")
Rel(global_user, riksdag, "HTTPS via CloudFront, mobile apps via AppSync")
Rel(researcher, riksdag, "GraphQL API (AWS AppSync)")
Rel(media, riksdag, "REST API (API Gateway)")
Rel(business, riksdag, "Enterprise GraphQL API")
Rel(riksdag, nordic_apis, "Lambda functions fetch data")
Rel(riksdag, eu_api, "EventBridge scheduled polling")
Rel(riksdag, bedrock, "AI content generation via Lambda")
Rel(riksdag, riksdag_api, "Primary data source via Lambda")
UpdateLayoutConfig($c4ShapeInRow="3", $c4BoundaryInRow="1")
Architecture: Pure AWS serverless with zero infrastructure managementโno Kubernetes, no containers, no EC2 instances. Enhanced with AWS WAF, KMS encryption, and multi-region deployment.
C4Container
title Riksdagsmonitor AWS Serverless Architecture (2027-2028)
Person(user, "Users", "Multi-platform access")
System_Boundary(security, "AWS Security Layer") {
Container(waf, "AWS WAF", "Web Application Firewall", "DDoS protection, rate limiting, geo-blocking")
Container(cloudfront, "CloudFront + Shield", "Global CDN", "Edge caching, Standard DDoS protection")
}
System_Boundary(riksdag, "Riksdagsmonitor Platform - AWS Serverless") {
Container(amplify_web, "Web PWA", "AWS Amplify Hosting", "Progressive Web App, SSR")
Container(amplify_mobile, "Mobile Apps", "AWS Amplify + AppSync", "iOS/Android native apps")
Container(appsync, "GraphQL API", "AWS AppSync", "Managed GraphQL, real-time subscriptions")
Container(api_gateway, "REST API", "Amazon API Gateway", "Legacy REST endpoints, usage plans")
Container(lambda_news, "News Generator", "AWS Lambda (Python)", "Bedrock integration for articles")
Container(lambda_translate, "Translation Service", "AWS Lambda (Python)", "14-language support")
Container(lambda_api, "API Functions", "AWS Lambda (Python)", "API handlers, business logic")
Container(lambda_etl, "Data Pipeline", "AWS Lambda (Python)", "ETL, data ingestion")
Container(bedrock_kb, "Vector Search", "Bedrock Knowledge Base", "RAG, semantic search, embeddings")
Container(neptune, "Graph Database", "Neptune Serverless", "Political networks, entity relationships")
Container(opensearch, "Full-Text Search", "OpenSearch Serverless", "Document search, analytics dashboards")
Container(timestream, "Time-Series DB", "Amazon Timestream", "Historical trends, election forecasting")
Container(aurora, "Relational DB", "Aurora Serverless v2", "political_data DB, multi-AZ")
Container(dynamodb, "NoSQL DB", "DynamoDB Global Tables", "Sessions, cache, multi-region")
Container(step_functions, "Workflows", "AWS Step Functions", "Content generation orchestration")
Container(eventbridge, "Event Bus", "EventBridge", "Event routing, scheduled polling")
Container(s3, "Object Storage", "S3 + CRR", "Static assets, cross-region replication")
Container(kms, "Encryption", "AWS KMS", "Data encryption at rest, key rotation")
}
System_Ext(bedrock, "Amazon Bedrock", "Claude Opus 4.8, Llama 4 405B, Nova Premier")
System_Ext(sagemaker, "SageMaker Serverless", "Custom ML models, election forecasting")
System_Ext(data_sources, "External APIs", "Riksdag, Nordic, EU Parliament APIs")
Rel(user, waf, "HTTPS traffic")
Rel(waf, cloudfront, "Filtered requests")
Rel(cloudfront, amplify_web, "Serve web app")
Rel(user, amplify_mobile, "Native SDK")
Rel(amplify_web, appsync, "GraphQL over HTTPS")
Rel(amplify_mobile, appsync, "GraphQL + subscriptions")
Rel(appsync, lambda_api, "Invoke resolvers")
Rel(api_gateway, lambda_api, "Invoke handlers")
Rel(lambda_api, aurora, "Read/write data (encrypted)")
Rel(lambda_api, dynamodb, "Cache, sessions (encrypted)")
Rel(lambda_api, opensearch, "Full-text search")
Rel(lambda_api, bedrock_kb, "Vector search")
Rel(lambda_api, neptune, "Graph queries")
Rel(lambda_api, timestream, "Time-series queries")
Rel(lambda_news, bedrock, "Text, image generation")
Rel(lambda_translate, bedrock, "Claude Opus 4.8 translation")
Rel(lambda_etl, data_sources, "Fetch political data")
Rel(step_functions, lambda_news, "Orchestrate AI pipeline")
Rel(eventbridge, lambda_etl, "Scheduled data refresh")
Rel(lambda_api, s3, "Store generated content")
Rel(cloudfront, s3, "Origin fetch")
Rel(kms, aurora, "Encrypt data")
Rel(kms, dynamodb, "Encrypt data")
Rel(kms, s3, "Encrypt objects")
UpdateLayoutConfig($c4ShapeInRow="3", $c4BoundaryInRow="1")
Focus: AI-powered content generation using Amazon Bedrock for all AI operationsโno direct OpenAI/Anthropic API calls.
C4Component
title AI Content Engine - Amazon Bedrock Integration (2026-2027)
Container_Boundary(ai_engine, "AI Content Engine - AWS Serverless") {
Component(event_detector, "Event Detector", "Lambda + EventBridge", "Monitors Riksdag API for new events")
Component(data_extractor, "Data Structurer", "Lambda (Python)", "Extracts and structures event data")
Component(bedrock_text, "Text Generator", "Lambda + Bedrock (Claude Opus 4.8)", "Article generation, 14 languages")
Component(bedrock_image, "Image Generator", "Lambda + Bedrock (Nova Premier)", "Multimodal generation")
Component(bedrock_audio, "Audio Generator", "Lambda + Polly Neural", "Podcast narration, 14 languages")
Component(quality_validator, "Quality Validator", "Lambda + Bedrock (Claude Opus 4.8)", "Hallucination detection, fact-check")
Component(translator, "Multi-Language", "Lambda + Bedrock (Claude Opus 4.8)", "14+ languages, cultural adaptation")
Component(step_func, "Content Pipeline", "Step Functions", "Orchestrates AI workflow")
Component(s3_publisher, "Content Publisher", "Lambda + S3 + CloudFront", "Invalidates CDN, updates site")
ComponentDb(aurora_content, "Content DB", "Aurora Serverless v2", "Generated articles, metadata")
ComponentDb(dyn_cache, "Cache", "DynamoDB", "API responses, user sessions")
}
System_Ext(bedrock, "Amazon Bedrock", "Claude Opus 4.8, Nova Premier, Llama 4 405B")
System_Ext(polly, "Amazon Polly", "Neural TTS, 14 languages")
System_Ext(riksdag_api, "riksdag-regering-mcp", "32 tools for Swedish political data")
Rel(riksdag_api, event_detector, "Event webhooks, EventBridge polling")
Rel(event_detector, data_extractor, "Raw event data")
Rel(data_extractor, step_func, "Trigger pipeline")
Rel(step_func, bedrock_text, "Generate text")
Rel(step_func, bedrock_image, "Generate images")
Rel(step_func, bedrock_audio, "Generate audio")
Rel(bedrock_text, bedrock, "Claude Opus 4.8 API")
Rel(bedrock_image, bedrock, "Nova Premier API")
Rel(bedrock_audio, polly, "Neural TTS API")
Rel(bedrock_text, quality_validator, "Generated text")
Rel(quality_validator, bedrock, "Claude Opus 4.8 validation")
Rel(quality_validator, translator, "Validated text")
Rel(translator, bedrock, "Claude Opus 4.8 translation")
Rel(translator, aurora_content, "Store content")
Rel(aurora_content, s3_publisher, "Retrieve approved content")
Rel(s3_publisher, dyn_cache, "Invalidate cache")
UpdateLayoutConfig($c4ShapeInRow="3", $c4BoundaryInRow="1")
Objective: Automate daily news generation from Swedish Parliament activity using Amazon Bedrock exclusively for all AI operations.
Features:
AWS Serverless Stack:
Content Types:
Quality Standards:
Amazon Bedrock Advantages:
Objective: Implement election forecasting and coalition modeling using AWS SageMaker Serverless Inference and Amazon Bedrock.
Features:
AWS Serverless Stack:
Predictive Models:
Election Forecasting Model (2026 Election)
Coalition Formation Model
Vote Prediction Model (MP-level)
Serverless ML Architecture:
Objective: Implement knowledge graphs and semantic search using Amazon Neptune Serverless and Amazon Bedrock Knowledge Bases.
Features:
AWS Serverless Stack:
Knowledge Graph Schema:
Semantic Search via Bedrock Knowledge Bases:
AWS-Native Data Services:
Objective: Deploy conversational interfaces using Amazon Bedrock and AWS AppSync real-time subscriptions.
Features:
AWS Serverless Stack:
Use Cases:
AWS-Native Voice Interfaces:
Master catalog: the capabilities below are the architecture realisation of
FUTURE_MINDMAP.mdยงPolitical-Intelligence Capability Catalog. Sections 3โ4 describe the generic AWS serverless platform and the Bedrock content/predictive roadmap; this section describes the intelligence-specific layers an operative requires โ multi-INT collection & fusion, processing & provenance, an analytic-tradecraft engine (SAT + forecasting + I&W), production/dissemination, and assurance/counter-AI โ and maps each to named managed services. Everything operates on public data under GDPR Art. 9 bases 9(2)(e)/9(2)(g) with human-in-the-loop sign-off.
The v1.x/v2.0 newsroom is a single-source, document-centric, build-time pipeline. It reads parliamentary documents superbly but does not (yet) fuse them with the financial, lobbying, procurement and discourse context around them; does not run indications-and-warning tripwires; cannot wargame coalition dynamics; and produces point-in-time articles rather than standing estimative products. Horizon 3 closes those gaps by adding five intelligence-specific architectural layers on top of the serverless substrate from ยง3.
graph TB
subgraph DIR["๐ฏ Direction (Step Functions)"]
PIR["PIR engine<br/>auto-generate + roll-forward"]
TRIP["Tripwire registry<br/>I&W thresholds"]
end
subgraph COL["๐ก Collection & Fusion (Lambda + Kinesis)"]
ER["Entity-resolution<br/>service"]
FIN["FININT ingest<br/>funding ยท lobbying ยท procurement"]
SOC["SOCMINT ingest<br/>privacy-bounded"]
FUSE["Multi-INT fusion<br/>graph builder"]
end
subgraph PROC["โ๏ธ Processing & Provenance (Lambda)"]
IE["Entity/event/relation<br/>extraction (Bedrock)"]
PROV["Provenance + C2PA<br/>signing/verify"]
DF["Deepfake / synthetic<br/>media detector"]
end
subgraph ANA["๐ง Analytic Engine (Bedrock Agents + SageMaker)"]
SAT["SAT orchestrator<br/>ACH ยท KAC ยท premortem"]
FCAST["Calibrated forecasting<br/>+ Brier feedback"]
IW["I&W evaluator"]
WAR["Agent-based<br/>wargaming sim"]
FIMI["FIMI / CIB<br/>detector"]
end
subgraph PROD["๐ Production & Dissemination (API Gateway + AppSync)"]
COP["Common Operating<br/>Picture"]
NIE["Estimative products<br/>NIE-style"]
BRIEF["Daily Brief +<br/>PIR briefings"]
CHAT["Conversational<br/>analyst (RAG)"]
ALERT["Tip-and-cue<br/>alerting"]
end
subgraph ASR["โ๏ธ Assurance & Counter-AI (Bedrock Guardrails)"]
NEU["Neutrality / bias<br/>symmetry auditor"]
RED["Pipeline red-team"]
CAI["Counter-AI<br/>injection/poison guard"]
HITL["Human-in-the-loop<br/>sign-off"]
end
DIR --> COL --> PROC --> ANA --> PROD
ANA --> ASR
PROD --> ASR
ASR --> HITL
IW --> TRIP
FCAST --> PIR
style DIR fill:#e8f5e9,stroke:#2e7d32,color:#000000
style COL fill:#e3f2fd,stroke:#1565c0,color:#000000
style PROC fill:#f3e5f5,stroke:#6a1b9a,color:#000000
style ANA fill:#fff3e0,stroke:#e65100,color:#000000
style PROD fill:#fce4ec,stroke:#b71c1c,color:#000000
style ASR fill:#fffde7,stroke:#f57f17,color:#000000
| Layer | Capability | Primary managed service(s) | Notes |
|---|---|---|---|
| Collection | Entity resolution across registries | Lambda + Neptune + OpenSearch (embedding match) | Record-linkage; provenance-tagged |
| Collection | FININT (funding/lobbying/procurement) | Lambda ingest + Aurora + S3 | Public registers only |
| Collection | Multi-INT fusion graph | Neptune Serverless | OSINT+FININT+GEOINT+ECONINT mesh |
| Collection | Privacy-bounded SOCMINT | Lambda + Comprehend (aggregate) | No individual profiling; aggregate stance/salience |
| Processing | Entity/event/relation extraction | Bedrock (Claude) + Comprehend | 14-language IE |
| Processing | Content provenance + C2PA | Lambda + KMS signing + S3 Object Lock | Tamper-evident chain-of-custody |
| Processing | Deepfake / synthetic-media detection | SageMaker Serverless Inference | Refuse-to-cite gate |
| Analysis | SAT automation (ACH/KAC/premortem) | Bedrock Agents | ICD 203-graded |
| Analysis | Calibrated forecasting + Brier loop | SageMaker + Timestream | Continuous calibration ledger |
| Analysis | Indications & Warning tripwires | Lambda + EventBridge + Timestream | Threshold/anomaly evaluators |
| Analysis | Agent-based wargaming | Step Functions + Bedrock Agents | Coalition/vote simulation |
| Analysis | FIMI / CIB detection | Neptune + SageMaker | Coordinated-inauthentic-behaviour graph signals |
| Production | Common Operating Picture | AppSync subscriptions + DynamoDB | Live fused situational view |
| Production | Estimative products (NIE) | Bedrock + Knowledge Bases | Standing key-judgment products |
| Dissemination | Conversational analyst (RAG) | Bedrock Agents + Knowledge Bases | Citation-grounded |
| Dissemination | Tip-and-cue alerting | EventBridge + SNS/AppSync | Watchlist-driven |
| Assurance | Neutrality / bias auditor | Lambda + Bedrock Guardrails | Per-party arithmetic symmetry |
| Assurance | Pipeline red-team | Step Functions (scheduled) | Adversarial self-test |
| Assurance | Counter-AI integrity guard | Bedrock Guardrails + WAF + input validation | Prompt-injection / data-poisoning defence |
The I&W engine is the architectural heart of the "warns about tomorrow" vision: a set of explainable indicator models whose threshold crossings re-task collection (tip-and-cue) and emit confidence-scored warnings for human review.
graph LR
subgraph IN["๐ฅ Indicator Inputs (public)"]
VT["Vote cohesion /<br/>rebellion deltas"]
AT["Attendance /<br/>quorum signals"]
CAL["Calendar /<br/>agenda shifts"]
ECON["IMF/SCB<br/>economic stress"]
DISC["SOCMINT<br/>salience spikes"]
end
subgraph EVAL["โ๏ธ Tripwire Evaluators (Lambda)"]
T1["Government-collapse<br/>indicator"]
T2["Snap-election<br/>indicator"]
T3["Coalition-rupture<br/>indicator"]
T4["Budget-crisis<br/>indicator"]
T5["Integrity-incident<br/>indicator"]
end
subgraph OUT["๐ฃ Warning Products"]
W["Confidence-scored<br/>warning"]
RT["Re-task collection<br/>(tip-and-cue)"]
H["Human analyst<br/>review + sign-off"]
end
IN --> EVAL --> OUT
W --> H
RT --> IN
style IN fill:#e3f2fd,stroke:#1565c0,color:#000000
style EVAL fill:#fff3e0,stroke:#e65100,color:#000000
style OUT fill:#fce4ec,stroke:#b71c1c,color:#000000
Architectural fitness controls (intelligence-specific).
FUTURE_STATEDIAGRAM.md).FUTURE_THREAT_MODEL.md and FUTURE_SECURITY_ARCHITECTURE.md).| Phase | Period | Intelligence capability milestone |
|---|---|---|
| Static fusion seeds | 2026โ2027 (H2) | Build-time entity resolution, conflict screening, SAT automation, influence networks, neutrality auditing |
| Runtime fusion + warning | 2028โ2029 (H3) | Multi-INT fusion mesh, provenance/deepfake gates, calibrated forecasting, I&W tripwires, conversational analyst, FIMI detection |
| Estimative + simulation | 2030โ2031 (H3) | Causal policy-impact inference, agent-based wargaming, Common Operating Picture, NIE-style estimative products |
| Autonomous intelligence | 2032โ2037 | Always-on multi-parliament fusion, generative scenario synthesis, election-night live cell, real-time democracy-health index |
Phase 1: Nordic Expansion (2027-2028)
Countries:
AWS Serverless Integration:
Phase 2: EU Parliament Integration (2028-2029)
Scope:
Current: 14 languages
Future (2027-2028): 30+ languages via Amazon Bedrock Claude Opus 5.x
AWS Translation Stack:
AWS Translation Services:
Historical Depth:
AWS Serverless Data Pipeline:
Real-Time Updates:
AWS Real-Time Stack:
Current Architecture (2026 Q1):
Static HTML/CSS โ CloudFront โ S3
Phase 1: Add Serverless API (2026 Q2-Q3)
Static Frontend โ CloudFront โ S3
โ
API Gateway โ Lambda โ Aurora Serverless v2
Phase 2: Add Amazon Bedrock AI (2026 Q4-2027 Q1)
Static Frontend โ CloudFront โ S3
โ
API Gateway โ Lambda โ Aurora Serverless v2
Lambda โ Amazon Bedrock (Claude Opus 4.8)
Phase 3: Add AppSync + Mobile (2027 Q2-Q4)
Web PWA (Amplify) โ CloudFront
Mobile Apps โ AppSync (GraphQL) โ Lambda โ Aurora / DynamoDB
Lambda โ Bedrock Knowledge Bases
Lambda โ Neptune Serverless
PWA / Service Worker โ implemented in v0.8.60 The static-site phase already ships a Workbox-free service worker (
public/sw.js, registered fromsrc/browser/main.ts) implementingstale-while-revalidatefor/cia-data/*.csv|*.json(and the raw.githubusercontent.com CIA fallback) pluscache-firstfor HTML documents and CSS. Two named caches (riksdagsmonitor-v1,cia-data-v1) are versioned and outdated entries are removed onactivate. This complements the localStorage 7-day TTL cache insrc/browser/shared/data-loader.tswith a network-layer cache that survives tab/browser restarts, enables full PWA install (the manifest'sdisplay: standaloneis now backed by an SW), and provides degraded offline read-only access. Lighthouse PWA "installable" passes on production builds. Future phases extend this with Workbox-driven precaching as the AWS Amplify SSR PWA layer comes online.
Phase 4: Full Serverless (2028+)
Amplify Hosting (SSR) โ CloudFront
โ
AppSync โ Lambda โ All AWS Serverless DBs
Step Functions โ Bedrock + SageMaker
EventBridge โ Scheduled workflows
Compute:
| Current | Future | Rationale |
|---|---|---|
| Static HTML | AWS Lambda (Python 3.12, Node.js 26) | Serverless functions, pay-per-request |
| N/A | AWS Amplify Hosting | Server-side rendering (SSR), edge functions |
API:
| Current | Future | Rationale |
|---|---|---|
| None | Amazon API Gateway (REST) | RESTful API, usage plans, caching |
| None | AWS AppSync (GraphQL) | Real-time subscriptions, offline sync |
AI/ML:
| Current | Future (AWS Serverless) | Rationale |
|---|---|---|
| None | Amazon Bedrock (Claude Opus 4.8, Llama 4 405B, Nova Premier) | Bleeding-edge AI, no API keys, data in AWS |
| None | SageMaker Serverless Inference | Custom ML models, pay-per-invocation |
Databases:
| Current | Future (AWS Serverless) | Rationale |
|---|---|---|
| None | Aurora Serverless v2 (PostgreSQL) | Auto-scaling RDS, pause/resume |
| None | Amazon DynamoDB | NoSQL, single-digit ms latency |
| None | Amazon Neptune Serverless | Graph database, pay-per-query |
| None | OpenSearch Serverless | Full-text + vector search |
| None | Amazon Timestream | Time-series data, automatic tiering |
Storage:
| Current | Future | Rationale |
|---|---|---|
| Amazon S3 | Amazon S3 (+ Intelligent-Tiering) | Object storage, 11 9's durability |
| CloudFront | CloudFront (+ Origin Shield) | CDN, low-latency global delivery |
Orchestration:
| Current | Future | Rationale |
|---|---|---|
| None | AWS Step Functions | Visual workflows, pay-per-state |
| None | Amazon EventBridge | Event bus, cron scheduling |
Observability:
| Current | Future | Rationale |
|---|---|---|
| None | CloudWatch Logs + Insights | Centralized logging, SQL queries |
| None | CloudWatch Metrics + Alarms | Auto-scaling triggers, alerting |
| None | AWS X-Ray | Distributed tracing, latency analysis |
Technology Stack:
Features:
API Features:
API Capabilities:
Features:
Phase 1: Foundation (2026 Q2-Q3)
Phase 2: AI Content Generation (2026 Q4-2027 Q1)
Phase 3: API Launch (2027 Q2-Q3)
Phase 4: Semantic Search (2027 Q4-2028 Q1)
Phase 5: Mobile Apps (2028 Q2-Q3)
Always maintain static site as fallback:
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Bedrock Hallucination | HIGH | HIGH | Dual validation (Claude Opus 4.8 + human review), fact-check against Riksdag data |
| Lambda Cold Starts | MEDIUM | MEDIUM | Provisioned concurrency for critical functions, keep-warm EventBridge rules |
| AppSync Rate Limits | LOW | MEDIUM | Request throttling, DynamoDB caching, CloudFront in front |
| Aurora Serverless Pauses | MEDIUM | LOW | Min capacity 0.5 ACU (faster wake-up), read replicas for queries |
| AWS Service Limits | LOW | HIGH | Request limit increases proactively, monitor Service Quotas |
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| AWS Region Outage | LOW | HIGH | Multi-AZ deployment, Route 53 failover to different region |
| Bedrock Model Deprecation | MEDIUM | MEDIUM | Abstract AI layer, support multiple Bedrock models (Claude, Llama, Titan) |
| Cost Overruns | MEDIUM | HIGH | CloudWatch Billing Alarms, Cost Anomaly Detection, Budget limits |
| Vendor Lock-In | HIGH | MEDIUM | Accept AWS lock-in as strategic decision per ISMS SUPPLIER.md |
| Metric | Current (2026 Q1) | Target (2028) | Measurement |
|---|---|---|---|
| API Response Time (p95) | N/A | <200ms | CloudWatch Insights |
| Lambda Cold Start (p95) | N/A | <500ms | X-Ray traces |
| Bedrock Latency (Claude Opus 4.8) | N/A | <2s (first token) | CloudWatch metrics |
| AppSync Subscription Latency | N/A | <100ms | CloudWatch metrics |
| Uptime | 99.998% | 99.99% | CloudWatch alarms |
gantt
title AWS Serverless Implementation Timeline (2026-2029)
dateFormat YYYY-MM-DD
section Phase 1: Foundation
Lambda + Aurora Serverless Deployment :2026-04-01, 90d
Amazon Bedrock Integration (Claude Opus 4.8) :2026-05-01, 60d
Step Functions Content Pipeline :2026-06-01, 45d
section Phase 2: AI Content
Bedrock Text Generation (14 languages) :2026-10-01, 90d
Bedrock Image Generation (Nova Premier) :2026-11-01, 60d
Amazon Polly Audio Generation :2026-12-01, 45d
section Phase 3: API Launch
AWS AppSync GraphQL Deployment :2027-04-01, 90d
API Gateway REST Endpoints :2027-05-01, 60d
Public API Authentication (Cognito) :2027-06-01, 45d
section Phase 4: Semantic Search
Neptune Serverless Deployment :2027-10-01, 90d
Bedrock Knowledge Base Integration :2027-11-01, 60d
OpenSearch Serverless Deployment :2027-12-01, 45d
section Phase 5: Mobile Apps
AWS Amplify iOS App Development :2028-04-01, 120d
AWS Amplify Android App Development :2028-04-01, 120d
Push Notifications (SNS + APNs/FCM) :2028-06-01, 60d
App Store + Google Play Launch :2028-08-01, 30d
section Phase 6: Advanced AI
SageMaker Serverless Inference :2028-10-01, 90d
Amazon Lex Conversational AI :2029-01-01, 90d
Bedrock Agents (Multi-Agent Systems) :2029-04-01, 90d
2026:
2027:
2028:
2029+:
Riksdagsmonitor's AWS serverless architecture fully aligns with all five pillars of the AWS Well-Architected Framework, ensuring enterprise-grade reliability, security, performance, cost optimization, and operational excellence.
graph TB
subgraph "AWS Well-Architected Framework"
Security[๐ Security Pillar<br/>KMS, WAF, GuardDuty, Security Hub]
Reliability[โก Reliability Pillar<br/>Multi-AZ, Global Tables, Resilience Hub]
Performance[โก Performance Efficiency<br/>CloudFront, Lambda, Aurora Serverless]
Cost[๐ฐ Cost Optimization<br/>Serverless Pricing, Auto-Scaling]
Operations[๐ง Operational Excellence<br/>CloudWatch, X-Ray, EventBridge]
end
subgraph "Riksdagsmonitor Implementation"
App[Riksdagsmonitor Platform]
App --> Security
App --> Reliability
App --> Performance
App --> Cost
App --> Operations
end
Security --> KMS[AWS KMS Encryption]
Security --> WAF[AWS WAF Protection]
Security --> GuardDuty[GuardDuty Threat Detection]
Security --> SecurityHub[Security Hub Monitoring]
Reliability --> MultiAZ[Multi-AZ Deployment]
Reliability --> GlobalTables[DynamoDB Global Tables]
Reliability --> ResilienceHub[AWS Resilience Hub]
Performance --> CloudFront[CloudFront CDN]
Performance --> Lambda[Lambda Auto-Scaling]
Performance --> Aurora[Aurora Serverless v2]
Cost --> PayPerUse[Pay-Per-Use Pricing]
Cost --> AutoScale[Auto-Scaling]
Cost --> CostExplorer[Cost Explorer Monitoring]
Operations --> CloudWatch[CloudWatch Logs/Metrics]
Operations --> XRay[X-Ray Distributed Tracing]
Operations --> EventBridge[EventBridge Automation]
style Security fill:#FF6B6B,color:#000000
style Reliability fill:#4ECDC4,color:#000000
style Performance fill:#45B7D1,color:#000000
style Cost fill:#FFA07A,color:#000000
style Operations fill:#98D8C8,color:#000000
Identity & Access Management:
Data Protection:
Infrastructure Protection:
Detection & Response:
graph LR
subgraph "Security Services"
WAF[AWS WAF<br/>Web Protection]
GuardDuty[GuardDuty<br/>Threat Detection]
SecurityHub[Security Hub<br/>Centralized Monitoring]
KMS[AWS KMS<br/>Encryption Keys]
CloudTrail[CloudTrail<br/>Audit Logs]
Config[AWS Config<br/>Compliance Checks]
end
subgraph "Application Layer"
CloudFront[CloudFront + Shield]
AppSync[AppSync GraphQL]
Lambda[Lambda Functions]
Aurora[Aurora Serverless v2]
DynamoDB[DynamoDB]
S3[S3 Storage]
end
WAF -->|Protect| CloudFront
CloudFront -->|Route| AppSync
AppSync -->|Invoke| Lambda
Lambda -->|Query| Aurora
Lambda -->|Read/Write| DynamoDB
Lambda -->|Store| S3
GuardDuty -->|Monitor| Lambda
GuardDuty -->|Monitor| S3
SecurityHub -->|Aggregate| GuardDuty
SecurityHub -->|Aggregate| Config
CloudTrail -->|Log| Lambda
CloudTrail -->|Log| Aurora
KMS -->|Encrypt| Aurora
KMS -->|Encrypt| DynamoDB
KMS -->|Encrypt| S3
Config -->|Validate| Lambda
Config -->|Validate| Aurora
style WAF fill:#FF6B6B,color:#000000
style GuardDuty fill:#FF6B6B,color:#000000
style SecurityHub fill:#FF6B6B,color:#000000
style KMS fill:#FF6B6B,color:#000000
Foundations:
Workload Architecture:
Change Management:
Failure Management:
graph TB
subgraph "Primary Region: eu-north-1"
AZ1[Availability Zone 1<br/>Aurora Primary + Lambda]
AZ2[Availability Zone 2<br/>Aurora Replica + Lambda]
AZ3[Availability Zone 3<br/>Aurora Replica + Lambda]
Aurora_Primary[Aurora Serverless v2 Primary]
Aurora_Replica1[Aurora Read Replica]
Aurora_Replica2[Aurora Read Replica]
AZ1 --> Aurora_Primary
AZ2 --> Aurora_Replica1
AZ3 --> Aurora_Replica2
end
subgraph "Secondary Region: eu-west-1"
AZ4[Availability Zone 1<br/>Aurora Global DB Replica]
AZ5[Availability Zone 2<br/>Aurora Global DB Replica]
Aurora_Global[Aurora Global Database]
AZ4 --> Aurora_Global
AZ5 --> Aurora_Global
end
Aurora_Primary -->|Async Replication| Aurora_Global
Route53[Route 53 Health Checks<br/>Automatic Failover]
Route53 -->|Primary| AZ1
Route53 -->|Failover| AZ4
Backup[AWS Backup<br/>35-day Retention]
Backup -->|Backup| Aurora_Primary
Backup -->|Backup| Aurora_Global
style AZ1 fill:#4ECDC4,color:#000000
style AZ2 fill:#4ECDC4,color:#000000
style AZ3 fill:#4ECDC4,color:#000000
style AZ4 fill:#45B7D1,color:#000000
style AZ5 fill:#45B7D1,color:#000000
Selection:
Review:
Monitoring:
Tradeoffs:
graph LR
subgraph "Edge Layer"
User[Global Users]
CloudFront[CloudFront CDN<br/>450+ Edge Locations<br/>< 100ms latency]
end
subgraph "API Layer"
AppSync[AppSync GraphQL<br/>Managed Service<br/>Auto-Scaling]
Lambda[Lambda Functions<br/>512MB-3GB Memory<br/>Sub-second execution]
end
subgraph "Data Layer"
Aurora[Aurora Serverless v2<br/>0.5-128 ACU<br/>Auto-Scaling]
DynamoDB[DynamoDB On-Demand<br/>Auto-Scaling<br/>Single-digit ms]
DAX[DynamoDB DAX<br/>In-Memory Cache<br/>Sub-ms latency]
OpenSearch[OpenSearch Serverless<br/>Auto-Scaling<br/>Full-text search]
end
User -->|TLS 1.3| CloudFront
CloudFront -->|GraphQL| AppSync
AppSync -->|Invoke| Lambda
Lambda -->|Query| Aurora
Lambda -->|Read| DynamoDB
DynamoDB --> DAX
Lambda -->|Search| OpenSearch
XRay[AWS X-Ray<br/>Distributed Tracing<br/>End-to-End Visibility]
CloudWatch[CloudWatch<br/>Metrics & Logs<br/>Real-Time Monitoring]
Lambda --> XRay
Aurora --> XRay
Lambda --> CloudWatch
Aurora --> CloudWatch
style CloudFront fill:#45B7D1,color:#000000
style Lambda fill:#45B7D1,color:#000000
style Aurora fill:#45B7D1,color:#000000
style DynamoDB fill:#45B7D1,color:#000000
Practice Cloud Financial Management:
Expenditure & Usage Awareness:
Cost-Effective Resources:
Manage Demand & Supply:
Optimize Over Time:
Organization:
Prepare:
Operate:
Evolve:
graph TB
subgraph "Observability"
CloudWatch[CloudWatch<br/>Logs + Metrics + Alarms]
XRay[X-Ray<br/>Distributed Tracing]
DevOpsGuru[DevOps Guru<br/>ML Insights]
end
subgraph "Automation"
EventBridge[EventBridge<br/>Event-Driven Automation]
SystemsManager[Systems Manager<br/>Runbooks + Parameters]
Lambda_Ops[Lambda Functions<br/>Operational Tasks]
end
subgraph "Application"
Lambda_App[Lambda Functions<br/>Application Code]
Aurora_App[Aurora Serverless v2]
DynamoDB_App[DynamoDB]
end
Lambda_App -->|Logs| CloudWatch
Lambda_App -->|Traces| XRay
Aurora_App -->|Metrics| CloudWatch
DynamoDB_App -->|Metrics| CloudWatch
CloudWatch -->|Alarms| EventBridge
EventBridge -->|Trigger| Lambda_Ops
Lambda_Ops -->|Execute| SystemsManager
CloudWatch --> DevOpsGuru
XRay --> DevOpsGuru
style CloudWatch fill:#98D8C8,color:#000000
style XRay fill:#98D8C8,color:#000000
style EventBridge fill:#98D8C8,color:#000000
Riksdagsmonitor integrates all major AWS security services to provide defense-in-depth protection across the entire stack, from edge to data layer.
graph TB
subgraph "Edge Security"
CloudFront[CloudFront + AWS Shield Standard<br/>DDoS Protection]
WAF[AWS WAF<br/>Web Application Firewall<br/>Rate Limiting, Geo-Blocking]
end
subgraph "Application Security"
AppSync[AWS AppSync<br/>GraphQL API + Authorization]
Lambda[Lambda Functions<br/>IAM Role-Based Access]
Secrets[AWS Secrets Manager<br/>Database Credentials]
end
subgraph "Data Security"
KMS[AWS KMS<br/>Encryption Key Management<br/>CMK with Auto-Rotation]
Aurora[Aurora Serverless v2<br/>Encrypted at Rest with KMS]
DynamoDB[DynamoDB<br/>Encrypted at Rest with KMS]
S3[S3 Buckets<br/>Encrypted with KMS, Versioning]
end
subgraph "Detection & Response"
GuardDuty[Amazon GuardDuty<br/>Threat Detection<br/>ML-Powered Anomaly Detection]
SecurityHub[AWS Security Hub<br/>Centralized Security Monitoring<br/>CIS, PCI DSS, NIST Compliance]
CloudTrail[AWS CloudTrail<br/>API Call Logging<br/>Forensics & Compliance]
Config[AWS Config<br/>Resource Configuration Tracking<br/>Compliance Validation]
Macie[Amazon Macie<br/>Sensitive Data Discovery<br/>S3 Data Classification]
end
subgraph "Compliance & Governance"
IAM[AWS IAM<br/>Identity & Access Management<br/>OIDC for GitHub Actions]
Organizations[AWS Organizations<br/>Multi-Account Management<br/>Service Control Policies]
end
CloudFront --> WAF
WAF --> AppSync
AppSync --> Lambda
Lambda --> Secrets
Lambda --> Aurora
Lambda --> DynamoDB
Lambda --> S3
KMS --> Aurora
KMS --> DynamoDB
KMS --> S3
GuardDuty --> SecurityHub
Config --> SecurityHub
Macie --> SecurityHub
CloudTrail --> SecurityHub
IAM --> Lambda
Organizations --> IAM
style WAF fill:#FF6B6B,color:#000000
style GuardDuty fill:#FF6B6B,color:#000000
style SecurityHub fill:#FF6B6B,color:#000000
style KMS fill:#FF6B6B,color:#000000
style CloudTrail fill:#FF6B6B,color:#000000
Capabilities:
Threat Detection:
Integration:
Compliance Frameworks:
Findings Aggregation:
Automated Remediation:
Managed Rule Groups:
Custom Rules:
Logging & Monitoring:
Key Management:
Data Encryption:
Compliance:
flowchart LR
subgraph "Data Flow with KMS Encryption"
User[User Request]
AppSync[AppSync GraphQL]
Lambda[Lambda Function]
KMS[AWS KMS<br/>Decrypt/Encrypt]
Aurora[Aurora Serverless v2<br/>Encrypted at Rest]
S3[S3 Bucket<br/>Encrypted with SSE-KMS]
end
User -->|HTTPS Request| AppSync
AppSync -->|Invoke| Lambda
Lambda -->|Request Decryption| KMS
KMS -->|Decrypted Data Key| Lambda
Lambda -->|Query| Aurora
Lambda -->|Store| S3
Aurora -->|Encrypted Data| KMS
S3 -->|Encrypted Objects| KMS
CloudTrail[AWS CloudTrail<br/>Log All KMS Operations]
KMS --> CloudTrail
style KMS fill:#FF6B6B,color:#000000
style Aurora fill:#4ECDC4,color:#000000
style S3 fill:#4ECDC4,color:#000000
Logging Coverage:
Retention & Storage:
Security:
Configuration Tracking:
Managed Rules:
Compliance Packs:
Riksdagsmonitor implements a comprehensive multi-region strategy for high availability, disaster recovery, and data residency compliance, with primary operations in eu-north-1 (Stockholm) and failover to eu-west-1 (Ireland).
graph TB
subgraph "Global Edge Layer"
Route53[Route 53<br/>Health Checks + Failover<br/>Latency-Based Routing]
CloudFront[CloudFront<br/>450+ Global Edge Locations<br/>Automatic Failover]
end
subgraph "Primary Region: eu-north-1 Stockholm"
ALB_Primary[Application Load Balancer<br/>Multi-AZ]
AppSync_Primary[AppSync GraphQL<br/>Primary Endpoint]
Lambda_Primary[Lambda Functions<br/>Reserved Concurrency]
Aurora_Primary[Aurora Global Database<br/>Primary Cluster<br/>Write + Read]
DynamoDB_Primary[DynamoDB Global Table<br/>Primary Region]
S3_Primary[S3 Bucket<br/>Cross-Region Replication]
OpenSearch_Primary[OpenSearch Serverless<br/>Multi-AZ Collection]
end
subgraph "Secondary Region: eu-west-1 Ireland"
ALB_Secondary[Application Load Balancer<br/>Multi-AZ]
AppSync_Secondary[AppSync GraphQL<br/>Secondary Endpoint]
Lambda_Secondary[Lambda Functions<br/>Reserved Concurrency]
Aurora_Secondary[Aurora Global Database<br/>Secondary Cluster<br/>Read-Only]
DynamoDB_Secondary[DynamoDB Global Table<br/>Replica Region]
S3_Secondary[S3 Bucket<br/>Replication Target]
OpenSearch_Secondary[OpenSearch Serverless<br/>Multi-AZ Collection]
end
Route53 -->|Primary| CloudFront
CloudFront -->|Route| ALB_Primary
Route53 -->|Failover| ALB_Secondary
ALB_Primary --> AppSync_Primary
ALB_Secondary --> AppSync_Secondary
AppSync_Primary --> Lambda_Primary
AppSync_Secondary --> Lambda_Secondary
Lambda_Primary --> Aurora_Primary
Lambda_Primary --> DynamoDB_Primary
Lambda_Primary --> S3_Primary
Lambda_Primary --> OpenSearch_Primary
Lambda_Secondary --> Aurora_Secondary
Lambda_Secondary --> DynamoDB_Secondary
Lambda_Secondary --> S3_Secondary
Lambda_Secondary --> OpenSearch_Secondary
Aurora_Primary -->|Async Replication<br/>< 1 second| Aurora_Secondary
DynamoDB_Primary -->|Active-Active<br/>< 1 second| DynamoDB_Secondary
S3_Primary -->|Cross-Region Replication<br/>< 15 minutes| S3_Secondary
Backup[AWS Backup<br/>Multi-Region Backup Vaults<br/>35-day Retention]
Backup --> Aurora_Primary
Backup --> Aurora_Secondary
Backup --> DynamoDB_Primary
Backup --> DynamoDB_Secondary
style Route53 fill:#4ECDC4,color:#000000
style CloudFront fill:#4ECDC4,color:#000000
style Aurora_Primary fill:#45B7D1,color:#000000
style Aurora_Secondary fill:#95E1D3,color:#000000
style DynamoDB_Primary fill:#45B7D1,color:#000000
style DynamoDB_Secondary fill:#95E1D3,color:#000000
Configuration:
Features:
Failover Strategy:
Configuration:
Use Cases:
Benefits:
Configuration:
Replicated Content:
Metadata Replication:
Health Check Configuration:
Failover Policy:
Recovery Time:
Backup Plans:
Cross-Region Backup Copy:
Backup Testing:
AWS Resilience Hub provides automated operational readiness validation, disaster recovery testing, and business continuity management for Riksdagsmonitor.
graph TB
subgraph "Resilience Hub Workflow"
Discover[Discover Application<br/>Components & Dependencies]
Define[Define RTO/RPO<br/>Business Requirements]
Assess[Assess Resilience<br/>Against Requirements]
Recommend[Resilience<br/>Recommendations]
Test[Resilience Testing<br/>Automated Validation]
Monitor[Continuous Monitoring<br/>Drift Detection]
end
subgraph "Application Components"
AppSync[AppSync GraphQL]
Lambda[Lambda Functions]
Aurora[Aurora Global Database]
DynamoDB[DynamoDB Global Tables]
S3[S3 + CRR]
end
Discover --> AppSync
Discover --> Lambda
Discover --> Aurora
Discover --> DynamoDB
Discover --> S3
Define --> Assess
Assess --> Recommend
Recommend --> Test
Test --> Monitor
Monitor --> Assess
EventBridge[EventBridge<br/>Automated DR Drills]
CloudWatch[CloudWatch<br/>RTO/RPO Tracking]
Test --> EventBridge
Monitor --> CloudWatch
style Discover fill:#98D8C8,color:#000000
style Assess fill:#98D8C8,color:#000000
style Test fill:#4ECDC4,color:#000000
Defined Objectives:
โ RTO (Recovery Time Objective): < 5 minutes
โ RPO (Recovery Point Objective): < 1 second
Service-Level Objectives:
Assessment Results:
โ Overall Resilience Score: 92/100 (Excellent)
โ Infrastructure Resilience: 95/100
โ Application Resilience: 90/100
โ Data Resilience: 95/100
Identified Gaps:
Monthly Automated Tests:
Aurora Failover Test - Promote secondary to primary
DynamoDB Failover Test - Redirect Lambda to secondary region
S3 Failover Test - Switch CloudFront origin to secondary bucket
Lambda Cold Start Test - Measure cold start latency after failover
Quarterly DR Drills:
Continuous Drift Detection:
Riksdagsmonitor provides native integrations with enterprise Security Information and Event Management (SIEM) platforms, Security Orchestration Automation and Response (SOAR) systems, and Governance, Risk, and Compliance (GRC) platforms.
graph TB
subgraph "Riksdagsmonitor AWS"
CloudTrail[CloudTrail<br/>API Audit Logs]
GuardDuty[GuardDuty<br/>Threat Detection]
SecurityHub[Security Hub<br/>Security Findings]
CloudWatch[CloudWatch<br/>Application Logs]
VPCFlow[VPC Flow Logs<br/>Network Traffic]
end
subgraph "Data Lake"
S3Logs[S3 Bucket<br/>Centralized Log Storage<br/>7-year retention]
Kinesis[Kinesis Data Firehose<br/>Real-Time Streaming]
end
subgraph "SIEM Platforms"
Splunk[Splunk Enterprise]
Elastic[Elastic Security]
QRadar[IBM QRadar]
Sentinel[Microsoft Sentinel]
end
subgraph "SOAR Platforms"
Phantom[Splunk SOAR Phantom]
Cortex[Palo Alto Cortex XSOAR]
Swimlane[Swimlane]
end
subgraph "GRC Platforms"
OneTrust[OneTrust GRC]
ServiceNow[ServiceNow GRC]
Archer[RSA Archer]
end
CloudTrail --> S3Logs
GuardDuty --> SecurityHub
CloudWatch --> Kinesis
VPCFlow --> S3Logs
SecurityHub --> Kinesis
S3Logs --> Splunk
S3Logs --> Elastic
S3Logs --> QRadar
Kinesis --> Sentinel
SecurityHub --> Phantom
SecurityHub --> Cortex
GuardDuty --> Swimlane
CloudTrail --> OneTrust
SecurityHub --> ServiceNow
SecurityHub --> Archer
style SecurityHub fill:#FF6B6B,color:#000000
style S3Logs fill:#4ECDC4,color:#000000
style Kinesis fill:#45B7D1,color:#000000
Splunk Enterprise Integration:
Elastic Security Integration:
IBM QRadar Integration:
Microsoft Sentinel Integration:
Splunk SOAR (Phantom) Integration:
Palo Alto Cortex XSOAR Integration:
Swimlane Integration:
OneTrust GRC Integration:
ServiceNow GRC Integration:
RSA Archer Integration:
Enterprise API Features:
API Monitoring:
Developer Portal:
| Document | Type | Purpose | Status |
|---|---|---|---|
| Current Architecture | ๐๏ธ Architecture | C4 model current structure (Context, Container, Component diagrams) | โ Active |
| Security Architecture | ๐ก๏ธ Security | Current security controls, CSP implementation, SLSA Level 3 | โ Active |
| State Diagrams | ๐ Behavior | Current system state transitions and lifecycles | โ Active |
| Future Flowcharts | ๐ Process | Bedrock AI workflows, Step Functions orchestration | โ Active |
| Mindmaps | ๐ง Concept | Current system component relationships | โ Active |
| SWOT Analysis | ๐ผ Business | Current strategic assessment and positioning | โ Active |
| CI/CD Workflows | ๐ง DevOps | Current GitHub Actions automation | โ Active |
| Data Model | ๐ Data | Current client-side data structures, CIA integration | โ Active |
| Threat Model | ๐ฏ Security | STRIDE threat analysis, attack surfaces | โ Active |
| Agents | ๐ค Automation | GitHub Copilot custom agents (14 agents) | โ Active |
| Skills | ๐ Knowledge | Agent skill libraries (57 specialized skills) | โ Active |
| Labels | ๐ท๏ธ Organization | GitHub issue labels and management | โ Active |
| Document | Type | Purpose | Status |
|---|---|---|---|
| Future Architecture | ๐ Evolution | This document: AWS serverless roadmap, AI enhancement | โ Active |
| Future Security Architecture | ๐ก๏ธ Security | Planned AWS security enhancements (GuardDuty, Security Hub, WAF) | โ Active |
| Future State Diagrams | ๐ Behavior | AI-enhanced state transitions, event-driven workflows | โ Active |
| Future Flowcharts | ๐ Process | Bedrock AI workflows, Step Functions orchestration | โ Active |
| Future Mindmaps | ๐ง Concept | Future capability evolution, AWS service relationships | โ Active |
| Future SWOT Analysis | ๐ผ Business | Future strategic opportunities and growth strategies | โ Active |
| Future Threat Model | ๐ฏ Security | Future threat analysis for planned features | โ Active |
| Future Workflows | ๐ง DevOps | Enhanced CI/CD with advanced pipelines | โ Active |
| Future Data Model | ๐ Data | Aurora, DynamoDB, Neptune data architecture | โ Active |
| Resource | Category | Description |
|---|---|---|
| Hack23 ISMS SUPPLIER.md | ๐ข Governance | AWS as strategic supplier, vendor management |
| Hack23 AI Policy | ๐ค AI Governance | Amazon Bedrock usage, AI ethics, transparency |
| Hack23 Secure Development Policy | ๐ Security | SDLC requirements, code security standards |
| AWS Well-Architected Framework | โ๏ธ AWS | 5 pillars: Security, Reliability, Performance, Cost, Operations |
| Amazon Bedrock Documentation | ๐ค AI/ML | Claude Opus 4.8, Llama 4 405B, Nova Premier APIs |
| AWS Serverless Resources | โก Serverless | Lambda, AppSync, Step Functions best practices |
| AWS Security Hub | ๐ก๏ธ Security | Centralized security monitoring, compliance frameworks |
| Aurora Serverless v2 | ๐พ Database | Auto-scaling serverless database documentation |
| DynamoDB Global Tables | ๐ NoSQL | Multi-region replication, active-active tables |
| AWS Resilience Hub | ๐ฅ DR/BC | Operational readiness, RTO/RPO validation |
๐ Documentation Navigation Tips:
Riksdagsmonitor's future architecture is a deliberately staged, three-horizon evolution โ not a single leap to the cloud. Horizon 1 (v1.x) is the proven static baseline shipping today: pre-rendered HTML/CSS in 14 languages on CloudFront + multi-region S3, with an autonomous AI newsroom in the build pipeline. Horizon 2 (v2.0, 2026โ2027) keeps that zero-backend delivery model unchanged and instead deepens the intelligence โ party-focused dashboards and advanced OSINT/INTOP analytics โ capturing the bulk of near-term value at near-zero attack surface and cost. Horizon 3 (v3.0+, 2028โ2037) migrates to a pure AWS serverless backend (Amazon Bedrock, Lambda, API Gateway, Aurora Serverless v2, Neptune, OpenSearch, Timestream) only once the static model is exhausted, exposing a public political-intelligence API. Every horizon preserves the security-first principles of our ISMS, neutrality across all parties, and GDPR Article 9 discipline for political data.
Key Architectural Achievements: The hybrid architecture preserves riksdagsmonitor's sophisticated 14-agent GitHub Copilot ecosystem (content-generator, news-journalist, intelligence-operative) as the primary orchestration layer, while introducing AWS serverless services (Aurora Serverless v2, DynamoDB, Neptune Serverless, OpenSearch Serverless) as the scalable data backend. This design leverages the strengths of both platforms: agents provide specialized domain expertise and safe-outputs workflows, while AWS delivers multi-region reliability, enterprise-grade security services (GuardDuty, Security Hub, WAF), and unlimited data processing capacity. The 4-phase enhancement roadmap (Enhanced Journalism 2026, Predictive Analytics 2027, Semantic Intelligence 2028, Conversational AI 2029+) introduces progressively advanced capabilities using bleeding-edge AI models (Claude Opus 4.8 for 2026, Opus 5.x for 2027-2028, Opus 6.0 for 2028+) delivered through Amazon Bedrock's unified interface.
Strategic Value Proposition: The architecture delivers measurable technical advantages across all AWS Well-Architected pillars. Security is enhanced through defense-in-depth integration of seven AWS security services plus agent-based safe-outputs validation. Reliability improves via multi-region deployment (Aurora Global Database, DynamoDB Global Tables, S3 Cross-Region Replication) achieving RTO < 5 minutes and RPO < 1 second. Performance scales elastically through serverless auto-scaling combined with agent-driven optimization. Operational excellence is achieved through comprehensive automation, Infrastructure as Code (CDK/Terraform), and continuous resilience validation via AWS Resilience Hub (resilience score 92/100). The platform maintains pure technical focus with zero infrastructure management overhead, enabling the development team to concentrate on feature delivery and democratic transparency innovation rather than operations.
Migration Roadmap Summary: The 4-phase migration strategy balances technical risk with capability advancement. Phase 1 (2026 Q2-Q3) establishes the AWS foundation with Lambda, Aurora Serverless v2, and Bedrock integration while preserving GitHub Actions agent workflows. Phase 2 (2026 Q4-2027 Q1) adds real-time capabilities through AppSync GraphQL and Kinesis Data Streams for event-driven architecture. Phase 3 (2027 Q2-Q4) introduces graph intelligence via Neptune Serverless and vector search through OpenSearch Serverless with Bedrock Knowledge Bases. Phase 4 (2028+) completes the transformation with conversational AI using Amazon Lex, Bedrock Agents, and Claude Opus 6.0 for natural language interfaces. Each phase includes comprehensive rollback procedures, automated testing gates, and gradual traffic migration to ensure zero-downtime deployment.
Path Forward: Success depends on disciplined execution of the technical roadmap, continuous security validation per ISO 27001/NIST CSF 2.0/CIS Controls frameworks, and preservation of the agentic orchestration architecture that distinguishes riksdagsmonitor from conventional platforms. The hybrid model positions riksdagsmonitor as a reference implementation for intelligent civic technology, demonstrating how advanced AI agents and cloud infrastructure combine to serve democratic transparency at scale. Future enhancements will extend geographic coverage to Nordic parliaments (Denmark, Norway, Finland), expand language support to 30+ languages via Bedrock's multilingual capabilities, and deepen intelligence analysis through SageMaker election forecasting models. The architecture provides a sustainable foundation for riksdagsmonitor's evolution as Sweden's premier political accountability platform for the next decade.
AI Model Evolution โ DevSecOps & Development Perspective (verbatim, 2026โ2037):
| Year | AI Model | DevSecOps Capability Evolution |
|---|---|---|
| 2026 | Opus 4.6โ4.9 | ๐ข AI-assisted code review, automated test generation, agentic CI/CD workflows |
| 2027 | Opus 5.x | ๐ต Predictive vulnerability detection, intelligent dependency management |
| 2028 | Opus 6.x | ๐ฃ Multi-modal security analysis (code + architecture + runtime), automated threat modeling |
| 2029 | Opus 7.x | ๐ Autonomous security pipeline orchestration, self-healing build systems |
| 2030 | Opus 8.x | ๐ด Near-expert automated security review, AI-driven architecture validation |
| 2031โ2033 | Opus 9โ10.x / Pre-AGI | โช Autonomous secure development lifecycle management |
| 2034โ2037 | AGI / Post-AGI | โญ Transformative software engineering with built-in security assurance |
Same AI curve, translated into Riksdagsmonitor product / OSINT / data terms:
| Year | AI Model | What it unlocks for political intelligence |
|---|---|---|
| 2026 | Opus 4.6โ4.9 | ๐ข Build-time newsroom (Horizon 1/2): evidence-graded articles, 14-language translation, source-graded OSINT scorecards |
| 2027 | Opus 5.x | ๐ต Deeper static analytics (Horizon 2): coalition/cohesion modelling, anomaly detection, predictive party-agenda signals |
| 2028 | Opus 6.x | ๐ฃ Bedrock runtime (Horizon 3 start): RAG over 109,000+ docs, multi-modal briefings, knowledge-graph reasoning over coalition networks |
| 2029 | Opus 7.x | ๐ Conversational political-intelligence API: natural-language queries against votes/documents via Bedrock Agents |
| 2030 | Opus 8.x | ๐ด Near-expert autonomous forecasting: election scenarios, coalition-formation probabilities, neutral cross-party analysis |
| 2031โ2033 | Opus 9โ10.x / Pre-AGI | โช Multi-parliament federation: comparative Nordic/EU analysis on a shared data mesh |
| 2034โ2037 | AGI / Post-AGI | โญ Real-time democracy index with human-in-the-loop governance, full ISMS/GDPR oversight on every inference |
โ๏ธ Governance guardrail. Every AI generation above operates strictly on public data, with neutrality across all parties, documented uncertainty, and human-in-the-loop oversight per the Hack23 AI Policy. Future capabilities are targets, never achieved metrics, and political opinions are treated as GDPR Article 9 special-category data (lawful bases 9(2)(e)/9(2)(g)).
Anthropic Opus Model Cadence:
Extended Architecture Roadmap:
| Phase | Period | AI Model | Architecture Impact |
|---|---|---|---|
| Enhanced Journalism | 2026 Q2-Q3 | Opus 4.8-4.9 | Bedrock integration, agentic content generation |
| Predictive Analytics | 2027 | Opus 5.x | SageMaker Serverless, real-time prediction pipelines |
| Semantic Intelligence | 2028 | Opus 6.x | Neptune Serverless knowledge graphs, multi-modal content |
| Conversational AI | 2029 | Opus 7.x | Amazon Lex, Bedrock Agents, natural language interfaces |
| Near-Expert Analysis | 2030 | Opus 8.x | Autonomous political analysis, 50+ language native support |
| Global Coverage | 2031-2033 | Opus 9-10.x / Pre-AGI | 50+ parliament architecture, federated data mesh |
| AGI-Era Platform | 2034-2037 | Post-Opus / AGI | 195 parliament network, autonomous intelligence, quantum-ready |
Competitor & Paradigm Shift Considerations:
๐ Document Control:
โ
Approved by: James Pether Sรถrling, CEO
๐ค Distribution: Public
๐ท๏ธ Classification:
๐
Effective Date: 2026-05-31
โฐ Next Review: 2026-08-31
๐ฏ Framework Compliance:
Baseline (current state): IMF is already the primary economic-data source today via
scripts/imf-client.tsand the cache inanalysis/imf/+analysis/daily/*/economic-data.jsonโ seeARCHITECTURE.mdยงIMF andFLOWCHART.mdยงIMF for the current-state baseline.Forward evolution: This section describes how the already-implemented IMF integration evolves toward the AWS-serverless future state. World Bank is retained as a non-economic container (governance / environment / social residue). SCB remains the Swedish-specific national-statistics layer.
Authoritative hub:
analysis/imf/README.mdยทanalysis/imf/agentic-integration.mdยทanalysis/imf/indicators-inventory.jsonยทanalysis/imf/data-dictionary.mdยท.github/aw/ECONOMIC_DATA_CONTRACT.md
Building on the current scripts/imf-client.ts + filesystem cache, the future state migrates IMF integration into Lambda + Aurora while preserving the same vintage-tagged, SHA-256-pinned, supersedes-chain semantics that exist today.
C4Container
title IMF in the Future Container View
Person(reader, "Reader / Researcher", "Riksdagsmonitor.com")
System_Boundary(rm, "Riksdagsmonitor โ AWS Serverless") {
Container(api, "API Gateway", "REST / WebSocket", "Edge entry")
Container(lambda, "Lambda Workers", "Node 26 / TypeScript", "News + analysis pipeline")
Container(bedrock, "Amazon Bedrock", "Claude Sonnet ยท Haiku", "AI analysis")
Container(neptune, "Neptune Graph", "Property graph", "Political relationships")
Container(aurora, "Aurora Serverless", "PostgreSQL", "Time-series + voting")
Container(opensearch, "OpenSearch Vector", "k-NN", "Semantic article search")
Container(s3, "S3 + CloudFront", "Static + cache", "Public site")
}
System_Ext(imf, "IMF Public APIs", "Datamapper REST + SDMX 3.0 โ PRIMARY ECONOMIC")
System_Ext(wb, "World Bank API", "Governance ยท environment ยท social residue")
System_Ext(scb, "SCB PxWeb v2", "Swedish ground truth")
System_Ext(rd, "Riksdag Open Data", "Parliamentary primary source")
Rel(reader, api, "HTTPS")
Rel(api, lambda, "Invoke")
Rel(lambda, bedrock, "Generate")
Rel(lambda, imf, "WEO ยท FM ยท IFS ยท BOP ยท DOTS ยท GFS_COFOG ยท PCPS ยท ER ยท MFS")
Rel(lambda, wb, "WGI ยท environment only")
Rel(lambda, scb, "PxWeb (SE-specific)")
Rel(lambda, rd, "Riksdag API")
Rel(lambda, aurora, "Persist")
Rel(lambda, neptune, "Graph upsert")
Rel(lambda, opensearch, "Embed + index")
Rel(lambda, s3, "Publish")
| Indicator class | Primary | Secondary | Why |
|---|---|---|---|
| Macro (GDP, growth, unemployment, inflation, fiscal balance, debt, current account) | IMF WEO + Fiscal Monitor | SCB (Sweden monthly) | Freshness + T+5 projections; SNA 2008 / GFSM 2014 / BPM6 cross-country comparability |
| Bilateral trade flows | IMF DOTS | โ | Partner-country dimension, monthly cadence |
| Monthly inflation, policy rates | IMF IFS / MFS_IR | SCB / Riksbank | Standardised cross-country |
| Government spending by function (defence/health/education/social protection) | IMF GFS_COFOG | โ | Committee-aligned (FรถU/SoU/UbU/SfU) |
| Commodity prices, exchange rates | IMF PCPS / ER | โ | Canonical benchmarks |
| Governance (CC.EST, RL.EST, VA.EST, GE.EST, RQ.EST, PV.EST) | World Bank WGI | โ | IMF has no equivalent |
| Environment (CO2, renewables, forest, water) | World Bank | โ | IMF has no equivalent |
| Social/education residue (literacy, school participation, gender ratios) | World Bank | GFS_COFOG 09 | IMF has no equivalent |
| Defence spending depth (long historicals) | World Bank MS.MIL.* | GFS_COFOG 02 | WB deeper history |
| Swedish ground truth (monthly labour, regional, budget execution) | SCB | โ | National statistics authority |
Canonical rule. Every economic claim in a Riksdagsmonitor article cites an IMF dataflow first; World Bank citations are reserved for governance, environment and social residue (the classes IMF does not publish). SCB is the Swedish-specific ground truth layer. See ECONOMIC_DATA_CONTRACT.md v2.1 for the banned-phrase list and vintage discipline (>6 mo โ annotation).
imf_cache (dataflow, indicator, country, vintage_label, retrieved_at, payload_jsonb, sha256). Vintage-tagged keys prevent silent overwrite when WEO AprโOct cycle ships.staleness_annotated=true flag. Defends future articles against silent staleness.economic-coverage-audit emits provider-mix telemetry (imf% / wb% / scb%) into CloudWatch; alarm if WB economic-citation share rises above 5%.Egress hosts (allow-list): www.imf.org (Datamapper REST ยท WEO/FM, unauthenticated), api.imf.org (SDMX 3.0 REST ยท IFS/BOP/DOTS/GFS/PCPS/ER/MFS_IR/MFS_PR, subscription-key authenticated via the Azure APIM Ocp-Apim-Subscription-Key header / IMF_SDMX_SUBSCRIPTION_KEY secret). Both HTTPS-only; payloads are public macro statistics with no PII.
| ๐ Platforms | ๐ฆ Open-Source Projects | ๐ก๏ธ Governance & Standards |
|---|---|---|
| ๐ณ๏ธ Riksdagsmonitor โ Swedish Parliament intelligence ๐ช๐บ EU Parliament Monitor โ European coverage ๐ต๏ธ Citizen Intelligence Agency โ political-data engine ๐ Hack23 AB โ corporate site ๐ฐ Hack23 Blog โ engineering & policy ๐ผ Hack23 on LinkedIn | ๐ณ๏ธ Hack23/riksdagsmonitor ๐ต๏ธ Hack23/cia ๐ช๐บ Hack23/euparliamentmonitor ๐ Hack23/european-parliament-mcp โ Hack23/cia-compliance-manager ๐ฅ Hack23/black-trigram ๐ Hack23/homepage | ๐ก๏ธ Hack23 ISMS-PUBLIC โ public ISMS ๐ Information Security Policy ๐ค AI Policy ๐งช Secure Development Policy ๐ฏ Threat Modeling Policy โ ๏ธ Vulnerability Management ๐ท๏ธ Classification Framework |
๐ณ๏ธ Empower citizens ยท ๐ Strengthen democratic accountability ยท ๐ต๏ธ Illuminate the political process
ยฉ 2008โ2026 Hack23 AB (Org.nr 559534-7807) ยท Maintainer: James Pether Sรถrling, CISSP CISM