Amazon Bedrock makes it easier for enterprise teams to build AI agents on AWS. That is good for innovation, but it creates a familiar governance challenge: once agents start appearing across business units, security and risk teams need to know what exists, who owns it, what it can reach, and whether it has been reviewed.
The problem: provider adoption moves faster than governance
Bedrock gives teams a powerful way to build agents that can reason over data, use tools and participate in business workflows. But without a central control plane, each team may manage its own agents locally. One group tracks ownership in a spreadsheet. Another keeps configuration in AWS. A third launches a production agent before security has a full picture.
The result is not a lack of IAM. It is a lack of governed AI asset management. The enterprise needs a consistent view across providers, business units and environments.
The governance target is the AI agent your enterprise created, configured and operates — not every foundation model available in the provider catalog.
Why importing the whole model catalog is the wrong signal
Provider catalogs contain reference models, options and capabilities that may be available to a cloud account. They are useful context, but they are not automatically enterprise-owned AI assets. Treating every available foundation model as a governed asset creates noise: false inventory growth, confusing ownership, inflated risk reports and cleanup work for governance teams.
What the enterprise needs to govern are the AI systems it actually builds or operates: Bedrock agents, their business purpose, ownership, lifecycle, configuration context, connected systems and review state.
How AuthSpoke supports Amazon Bedrock
AuthSpoke connects to Amazon Bedrock through the Enterprise Connector Framework. The connector is designed around the way enterprises actually govern provider assets:
- Connect — create an Amazon Bedrock connector instance with the right region and credential configuration.
- Test — validate connectivity and permissions before importing anything.
- Preview — review discovered Bedrock agents before they become governed records.
- Import — bring selected Bedrock agents into AuthSpoke as governed AI assets.
- Synchronize — keep imported assets aligned as provider state changes.
- Audit — preserve activity, decisions and changes for review and compliance.
What happens after a Bedrock agent is imported
Once imported, a Bedrock agent is no longer just a provider-side configuration. It becomes part of the enterprise AI asset inventory. AuthSpoke can track:
- Owner, business unit and accountable team
- Environment, lifecycle state and governance state
- Business purpose, classification and criticality
- Provider metadata and source connector context
- Relationships to models, tools, MCP servers and systems
- Activity history and audit evidence
- Governance findings, reviews, exemptions and remediation tasks
This gives security and platform teams the operating model they need: AWS remains the place where Bedrock runs, while AuthSpoke becomes the place where enterprise governance is coordinated.
AuthSpoke focuses the registry on AI assets the enterprise actually owns and operates. Bedrock foundation-model catalog entries can remain provider reference data; Bedrock agents become governed assets.
From inventory to runtime access governance
Knowing a Bedrock agent exists is the start. The harder, operational question is: what can this agent actually reach at runtime, with what permissions, and can you prove it? An agent that summarizes a codebase or triages issues needs access to real systems — and that access must be least-privilege, approved, verifiable and revocable.
AuthSpoke extends the same control plane from inventory into runtime authorization. It becomes the broker between a Bedrock agent and the systems it uses, so the agent never holds standing credentials of its own.
The agent asks AuthSpoke; AuthSpoke checks the approved assignment, mints a short-lived token scoped to exactly that resource and permission, performs the call, and records it. The agent never sees the underlying credential.
End to end: a Bedrock agent reading a GitHub repository
Take a common case — a Bedrock agent that reads repository documentation to answer questions. With AuthSpoke every step of the path is governed:
- Request — grant the agent a specific access profile (for example, Repository Reader) on a specific repository.
- Evaluate and approve — access policies run, then an authorized reviewer approves.
- Provision and verify — AuthSpoke provisions the access and independently verifies it against the provider, not just its own records.
- Runtime call — when the agent invokes its tool (through a Bedrock action group), AuthSpoke identifies the agent from a signed token, confirms the verified assignment, and mints an installation token restricted to that one repository and the minimum permission the operation needs.
- Audit — every call is allowed or denied and recorded — with the operation, repository, result and source — and no tokens, keys or file contents are stored in the log.
- Revoke — revoking the assignment stops token issuance immediately; the next call is denied.
The result is provable, real-time access governance: the agent reads live data through a least-privilege, short-lived token it never holds, and every use is attributable and exportable for audit.
Tokens are minted per call, scoped to a single resource and the exact permission required, and expire in minutes. A read-only profile can never write; a revoked assignment can never call. Enforcement is independent of the agent, so the model cannot talk its way past it.
The business outcome
For enterprise leaders, the value is simple: Bedrock adoption can continue without leaving governance behind. Teams can build on AWS, while security, risk and compliance get a clean control plane for visibility, accountability and review.
- Discover Bedrock agents created by the organization
- Import them into a governed AI Registry
- Assign ownership, lifecycle and business context
- Apply AI Governance policies and evaluations
- Broker least-privilege, approved runtime access to systems like GitHub
- Mint short-lived, scoped tokens per call — the agent holds no credentials
- Record every access as allowed or denied, with no secrets stored
- Revoke instantly, and maintain audit evidence across provider-driven change
Why this matters for enterprise AI programs
Cloud-native AI platforms will continue to expand. Enterprises will not govern them by asking every team to manually update a spreadsheet. They need connector-driven discovery, controlled import, metadata, lifecycle, policy and audit across the AI systems they actually run.
AuthSpoke gives Amazon Bedrock agents a place in that operating model: visible, owned, reviewed and auditable.
Bring Bedrock agents into your AI control plane
Use AuthSpoke to discover, register, govern and audit the Bedrock agents your enterprise builds and operates.