WorkshopsWorkshopEngineersDeployment4 hours

Deploy Agentic AI Systems for Engineers

Your agents work on your laptop. Production asks harder questions: who each agent is acting as and what it may touch, what stops a prompt injection hidden in a document, which calls can be cached and who pays for the rest, what an agent did last night, and whether a model change made it worse. In this workshop you take a working agentic system through each of them, live, on a working multi-agent system.

Why this matters

Agents that work on a laptop meet hard questions on the way to production. Who is each agent acting as and what may it touch? What stops an instruction hidden in a document? Which calls can be cached and who pays for the rest? What did the agent do last night, and did the last model change make it worse? This workshop takes a working system through each question, live, so your next security review and launch go faster.

Sound familiar?

  • The agent works on your laptop, and the security review has questions nobody can answer.
  • A prompt injection in one document could make an agent act, and no test would catch it.
  • The bill arrives at the end of the month with no way to say which agent or customer spent it.

The four hours, block by block

  1. Identity for every agentWatch it built

    Sign each agent in with its own credentials and act on behalf of the user with Keycloak.

  2. Permissions and policyBuild it together

    Check every action with OpenFGA and write approval rules as code.

  3. GuardrailsBuild it together

    Block prompt injection and keep secrets and personal data out of the model.

  4. The LLM gatewayBuild it together

    Route, cache and budget every model call per tenant.

  5. Traces and dashboardsBuild it together

    Trace every run in Langfuse and watch cost, latency and failures.

  6. Evals in CIBuild it together

    Fail the deploy when a prompt or model change makes an agent worse.

  7. Ship itShip your version

    Deploy the system and onboard a second tenant live.

What you will be able to do

Secure every action
Give each agent its own identity and check every action against the user's permissions.
Deploy behind a gateway
Route, cache and budget every model call per tenant, and trace every run.
Ship what passes evals
Fail a deploy that makes an agent worse.

The ideas behind it

  • Identity and permissions

    Each agent signs in as itself and acts with the permissions of the person it works for.

  • An LLM gateway

    One place for every model call: routing, fallbacks, caching, budgets and the bill per team.

  • Traces and evals

    Every run traced, and a test set that blocks a release when quality drops.

  • Policy and tenants

    Approval rules written as code, and each customer kept apart so one cannot see another's data. The day ends by onboarding a second tenant live.

Where it fits

The parts of a production agent system, in the order the buildcamp builds them. The lit tiles are the ones this workshop builds; the Agentic AI Buildcamp for Engineers builds all of them.

Week 1Architect
  • Roles and modelsOne job per agent, a model chosen for that job, and a token budget.
  • OrchestrationA queue agents pick work from, with hand-offs a person can follow.
  • Context and memoryRetrieval with sources, memory across sessions, prompts laid out for the cache.
  • Tool callingTyped tools that act in GitHub, Linear and Google.
Week 2Build
  • MCP serversEvery tool behind an MCP gateway, scoped to the role that needs it.
  • Durable executionRuns that resume after a crash and never repeat a write.
  • Human in the loopA person approves anything that cannot be undone.
Week 3Secure and deploy
  • Identity and permissionsEach agent signs in as itself and acts on behalf of a user.
  • LLM gatewayRouting, caching and a budget on every model call.
  • Traces, evals and costEvery run traced, scored and charged to the agent that made it.
  • Multi-tenancyEach team or customer kept apart, in data and in the bill.
Week 4Govern and extend
  • Policy as codeRules checked on every action, not written in a document.
  • Signed skillsNew roles built from reviewed, signed skills.

Who it is for

  • Software engineers taking an agentic system from demo to production
  • Platform engineers who will run agents for many teams
  • Tech leads who own reliability and cost

Not for

  • New to Python or to calling an LLM API? Start with the recorded lab Build Your First AI Agent in Python.
  • Looking for no-code tools? Everything here is code.

Before you come

For
Software engineers taking agents from demo to production, and the platform engineers and tech leads who will run them.
You need
Python, Docker and an LLM API key.
Track
Agentic AI for engineers who build and run it.

Questions

Do I need DevOps experience?

No. Python, Docker and an LLM API key are enough. The system deploys with Coolify, a self-hostable platform, and every step is shown and explained.

Is this the same as the design workshop?

No. The design workshop decides the architecture; this one takes a working system to production. Each stands on its own.

Which cloud does it use?

None in particular. Everything runs in containers on a server you control, so the same setup moves to any provider.

Can my employer pay?

Yes. Maven gives you a receipt your company can expense. To train a whole team, see the private team workshops.

What if I miss part of the day?

Every block is recorded on Maven, so you can catch up on anything you missed.

Do I need to take the free Live Labs first?

No. They help, and each one is listed on this page, but the workshop starts from the beginning of its topic.

Go deeper

BuildcampAgentic AI Buildcamp for EngineersDesign, build and deploy a production agentic AI system in four weeks$997

Free Live Labs before it