SailPoint CIEM Administration of AWS IAM Identity Center Updates Standing Entitlements for Amazon Bedrock AgentCore Service Operations
SailPoint CIEM can participate in administration of AWS IAM Identity Center authorization state, including group membership, account assignments, and permission sets. Those AWS IAM Identity Center and AWS Identity and Access Management constructs can establish standing entitlements that govern which principals may perform Amazon Bedrock AgentCore service operations; an administration event can therefore update standing-entitlement state affecting those operations.
Linked Evidence
SailPoint CIEM has documented, supported provisioning/collection permissions against AWS IAM Identity Center constructs (group membership, account assignments, permission sets), and those constructs' scope explicitly includes Amazon Bedrock and Bedrock AgentCore resources.
AWS Permission Sets — SailPoint Identity ServicesThese IAM constructs determine which principal may perform which AgentCore action on which resource and under which conditions — the standing-entitlement substrate that an AWS IAM Identity Center administration event would update.
How Amazon Bedrock AgentCore works with IAM — AWS Documentation