Home icon

Amazon Bedrock AgentCore Memory now supports fine-grained access control

News



This article announces fine-grained access control (FGAC) support for Amazon Bedrock AgentCore Memory, enabling per-user and per-tenant memory isolation through AgentCore Gateway.

  • Front Memory resources with AgentCore Gateway configured for OAuth (JWT) authentication
  • Attach Cedar policies to restrict access based on authenticated caller identity
  • Enforce per-user data access and restrict memory records to user token-derived namespaces
  • Allow or deny specific Memory operations per caller without custom authorization logic
  • Move access control enforcement from application code to infrastructure layer using cryptographic identity proof
  • Built on AgentCore Memory connector exposing 12 Memory operations as Cedar actions

FGAC for Memory simplifies access control implementation by leveraging infrastructure-level policy enforcement instead of application-level authorization logic.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 23
2026
Amazon Bedrock AgentCore Memory now supports cross-account access
Sep 8
2026
Amazon Bedrock AgentCore Memory now supports direct ingestion to long-term memory
Aug 24
2026
Amazon Bedrock AgentCore Memory now supports extracting memories from non-conversational JSON payloads
Aug 28
2026
Amazon Bedrock AgentCore Memory now supports flexible namespace variables

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.