aws AWS What's New ·

Amazon Bedrock AgentCore Memory Gains Fine-Grained Access Control

securityawsgaengineeraws-bedrock
feature

Amazon Bedrock AgentCore Memory now supports fine-grained access control (FGAC). This enhancement allows users to enforce per-user and per-tenant memory isolation through AgentCore Gateway without building custom authorization logic. By configuring the Gateway with OAuth and Cedar policies, developers can restrict memory access based on authenticated caller identity, specific namespaces, and individual operations, shifting enforcement to the infrastructure layer. This capability is built on the AgentCore Memory connector and exposes 12 Memory operations as Cedar actions for policy conditions.

Features (1)
  • Fine-grained access control for AgentCore Memory

    Amazon Bedrock AgentCore Memory now supports fine-grained access control (FGAC), enabling per-user and per-tenant memory isolation via AgentCore Gateway. This allows enforcing access based on authenticated caller identity, token claims, and specific Memory operations using Cedar policies. The feature leverages the AgentCore Memory connector, which exposes 12 Memory operations as Cedar actions for policy conditions.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/agentcorememory-fine-grained-access-control

Related releases