Amazon Bedrock AgentCore Memory Gains Fine-Grained Access Control
Amazon Bedrock AgentCore Memory now supports fine-grained access control (FGAC). This enhancement allows users to enforce per-user and per-tenant memory isolation through AgentCore Gateway without building custom authorization logic. By configuring the Gateway with OAuth and Cedar policies, developers can restrict memory access based on authenticated caller identity, specific namespaces, and individual operations, shifting enforcement to the infrastructure layer. This capability is built on the AgentCore Memory connector and exposes 12 Memory operations as Cedar actions for policy conditions.
Features (1) ›
- Fine-grained access control for AgentCore Memory
Amazon Bedrock AgentCore Memory now supports fine-grained access control (FGAC), enabling per-user and per-tenant memory isolation via AgentCore Gateway. This allows enforcing access based on authenticated caller identity, token claims, and specific Memory operations using Cedar policies. The feature leverages the AgentCore Memory connector, which exposes 12 Memory operations as Cedar actions for policy conditions.
https://aws.amazon.com/about-aws/whats-new/2026/08/agentcorememory-fine-grained-access-control
Related releases
- Amazon Bedrock AgentCore Memory Gains Flexible Namespace Variables AWS What's New ·
- SpaceXAI Grok 4.6 Now Available on Amazon Bedrock in AWS GovCloud (US) AWS What's New ·
- Amazon Bedrock AgentCore expands to two new AWS Regions AWS What's New ·
- AWS Enhances Bedrock Guardrails to Cover AI Agent Tool Interactions AWS Security Blog ·
- Amazon Bedrock AgentCore Memory now extracts long-term memories from JSON payloads AWS What's New ·
- OpenAI GPT-5.6 Terra and Luna Models Now Available in AWS GovCloud AWS What's New ·