AWS Identity and Access Management Enforces Authorization on Amazon Bedrock AgentCore Service Operations; SailPoint CIEM Analyzes Effective Access
Amazon Bedrock AgentCore enforces authorization for service operations through AWS Identity and Access Management policies, roles, and related IAM constructs. SailPoint CIEM collects and displays effective access and access paths for human identities to Amazon Bedrock and Amazon Bedrock AgentCore resources, enabling analysis of the standing AWS IAM entitlements enforced when a principal invokes an AgentCore service operation.
Linked Evidence
AWS IAM policy determines whether a principal may perform an AgentCore operation — this is authoritative technical documentation for AgentCore's enforcement substrate.
How Amazon Bedrock AgentCore works with IAM — AWS DocumentationSailPoint CIEM has a specific, named capability for ingesting and displaying effective access and access paths to Bedrock and AgentCore resources.
Enhancement: CIEM Support for AWS Bedrock and Bedrock AgentCore as a Cloud Resource — SailPoint Developer CommunityConfiguration documentation supporting the CIEM collection mechanism against Bedrock/AgentCore resources.
AWS Permission Sets — SailPoint Identity Services