How Axonius built secure multi-tenant AI agents on Bedrock AgentCore
Machine Learning Blog
This article describes how Axonius, a SaaS cybersecurity platform, deployed secure multi-tenant AI agents using Amazon Bedrock AgentCore to help security teams analyze asset data and identify risks.
- Evaluated three multi-tenancy patterns: pool (shared runtime), bridge (shared runtime with gateway enforcement), and silo (dedicated runtime per tenant)
- Chose silo model with dedicated AgentCore runtime per customer for maximum isolation and alignment with existing infrastructure
- Each customer's agent runs in isolated microVMs with dedicated VPC connectivity, ensuring tenant data separation
- Implemented token governance using CloudWatch metrics, IAM role tagging, and automated IAM-deny policies for cost control
- Integrated JWT-based authentication, Amazon Bedrock Knowledge Bases for RAG, and Guardrails for response safety
- Used Amazon VPC Lattice for cost-efficient private connectivity across customer VPCs and AWS services
- Reduced deployment time from estimated 8 weeks to 10 days using AgentCore managed runtime
The architecture demonstrates how ISVs can deploy production-ready multi-tenant AI agents with strong security, cost tracking, and operational simplicity using Amazon Bedrock AgentCore.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2026
2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.