Fetching from the wire…
Top 5 · 2026-03-10 · source-backed
AWS shipped Policy in Amazon Bedrock AgentCore to general availability across 13 regions. The breakthrough: security teams can write agent-to-tool access rules in plain English, which auto-convert to Cedar policies with automated reasoning that catches overly permissive or unsatisfiable conditions. Policy operates outside agent code — no modifications needed. Every enforcement decision is logged to CloudWatch. This is the first hyperscaler to ship declarative, production-grade agent governance as infrastructure. What to do: If you're deploying agents on AWS, start writing Cedar policies today. This is the "IAM for agents" moment. AWS Blog
Each link below shares sources, entities, or timing with this story.
Each tenant gets a dedicated Bedrock AgentCore runtime, every user session runs in its own microVM that's terminated and memory-sanitized on completion, paired with Knowledge Bases metadata filtering, Guardrails on responses, VPC Lattice for private connectivity and per-tenant...
AWS shipped the first cloud-native, declarative agent governance layer to general availability. Policy intercepts AgentCore Gateway tool calls before execution, enforcing Cedar policies auto-generated from natural language rules. Automated reasoning validates each policy again...
AWS's September 11 walkthrough pairs its DevOps Agent with AgentCore Evaluations, aimed at a specific gap: "an agent can successfully invoke Amazon Bedrock, call every tool without errors, and return a response while completely misunderstanding what the user needs." Thirteen L...
AWS made the managed AgentCore harness generally available on June 18. You define model, tools, skills, and memory with CreateHarness, then run it with InvokeHarness. It ships multi-model support (Bedrock, OpenAI, Gemini, LiteLLM), mid-session context preservation, built-in br...
AWS's August 21 post stages agent tool governance as Connect, Control, Catalog and Harden, from one SSO-backed MCP endpoint for a 1-20 user pilot through identity-aware authorization with PII redaction and self-service tool publishing at 100+ users. It supports Cognito-backed...
Plus fine-grained access control and customer-managed key encryption scoped per agent. Unglamorous and load-bearing: you can't systematically measure agent quality when the evidence is scattered across destinations. (AWS)
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.