Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Amazon Bedrock agents as NHIs: what identity teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Amazon Bedrock agents, roles, knowledge bases, prompts, and guardrails can be represented as first-class non-human identities in a single access graph, with the IAM role carrying the true blast radius and automatic discovery following the next AWS extraction, according to Veza. That matters because identity review, least privilege, and access tracing must extend to AI agents, not stop at human users.

NHIMG editorial — based on content published by Veza: How Veza models every Bedrock agent, action group, knowledge base, and IAM role in a single access graph

By the numbers:

Questions worth separating out

Q: How should security teams govern Amazon Bedrock agents as identities?

A: Treat each Bedrock agent as a first-class non-human identity and review the role it assumes, the tools it can invoke, and the people who can manage it.

Q: Why do Bedrock agents create more access risk than standard workloads?

A: They combine delegated runtime behaviour with assumed IAM roles and connected data sources, so their effective reach can exceed what a simple workload inventory suggests.

Q: What breaks when teams review AI agents without checking the assumed role?

A: They miss the true blast radius.

Practitioner guidance

What's in the full article

Veza's full article covers the implementation detail this post intentionally leaves for the source:

  • The exact Access Graph relationships used to model Bedrock agents, roles, prompts, guardrails, and knowledge bases.
  • The worked claims-triage example showing how permissions, data sources, and model attachments are traversed end to end.
  • The specific Access Reviews, Blast Radius, and Rules & Alerts behaviours that extend to Bedrock on day one.
  • The Bedrock and Bedrock AgentCore distinctions for teams comparing runtime coverage and native service coverage.

👉 Read Veza's walkthrough of Amazon Bedrock agent access graph modelling →

Amazon Bedrock agents as NHIs: what identity teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Identity-first modelling is the only workable control plane for Bedrock agents. The article shows why agent governance collapses when teams treat the model, the tool, and the runtime as separate problems. Bedrock agents assume roles, inherit tool reach, and can be invoked by humans, which means the real question is delegated authority across the full path. Practitioners should treat the agent as a governed identity object, not just an application feature.

A few things that frame the scale:

  • 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to Ultimate Guide to NHIs.
  • NHIs outnumber human identities by 25x to 50x in modern enterprises, which is why agent inventories now need lifecycle controls rather than ad hoc tracking.

A question worth separating out:

Q: Who should be accountable for changes to a Bedrock agent and its permissions?

A: The owner of the agent, the team that manages its IAM role, and the reviewers who certify its access should all be explicitly named. If a human principal can invoke or modify the agent, that entitlement must be part of accountability, not treated as an implementation detail.

👉 Read our full editorial: Veza models Bedrock agents as first-class NHIs in one access graph



   
ReplyQuote
Share: