Conversation
Source: https://aws.amazon.com/about-aws/whats-new/2026/08/agentcorememory-fine-grained-access-control Proposed by the knowledge auto-update pipeline; every edit's justification is in the PR body.
|
Reviewed for factual correctness against current AWS docs (via AWS Knowledge MCP) and the repo's other AgentCore references. Core claim checks out. FGAC for Amazon Bedrock AgentCore Memory is real and GA (Aug 2026): front Memory with a Gateway using OAuth/JWT auth, attach a Cedar policy engine, and Memory operations become Cedar actions with One omission worth flagging (not a blocker): the batch Memory operations ( - 1. **Cedar policy enforcement on tool calls and Memory access** — building authorization logic per-tool (or per-memory-operation) is error-prone; AgentCore now also supports FGAC for Memory via Gateway + Cedar policies
+ 1. **Cedar policy enforcement on tool calls and Memory access** — building authorization logic per-tool (or per-memory-operation) is error-prone; AgentCore now also supports FGAC for Memory via Gateway + Cedar policies (batch Memory operations are IAM-only, not Cedar-governed)Cross-checked other AgentCore reference files for consistency:
Mirror-skip claim verified: Net: approve, with the optional batch-operations caveat above for completeness. |
|
@herosjourney Addressed the batch-operation caveat from your review comment in 43e7b81. The guidance now explicitly names Targeted formatting, Markdown lint, cross-plugin drift, and whitespace checks passed. |
AgentCore Memory guidance previously described Gateway + Cedar without explaining how caller identity is bound to Memory access or which operations are covered. This update makes those boundaries explicit for startup architecture recommendations.
Changes
BatchCreateMemoryRecords,BatchUpdateMemoryRecords, andBatchDeleteMemoryRecordsare outside Cedar FGAC. IAM policies can allow or deny each batch operation as a whole.Sources and scope
Only the existing adoption-guidance item in
architect-for-startups/references/agentcore.mdchanges. There is no correspondingarchitect-for-startupsskill in the migrate plugin.Validation
git diff --checkpassed.