Amazon Bedrock AgentCore Memory now supports fine-grained access control

Amazon Bedrock AgentCore Memory Updates
Amazon Bedrock AgentCore Memory now supports fine-grained access control (FGAC), enabling you to enforce per-user and per-tenant memory isolation through AgentCore Gateway without building custom authorization logic.
What to do
- Configure AgentCore Gateway for OAuth (JWT) authentication.
- Attach Cedar policies to restrict access based on the authenticated caller's identity.
- Enforce that each user only accesses their own actor's data.
- Restrict memory records to namespaces derived from the user's token claims.
- Allow or deny specific Memory operations per caller.
For more details, see Fine-grained access control for Memory in the Amazon Bedrock AgentCore Developer Guide.
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



