SYSTEM Cited by 3 sources
AgentCore Policy¶
What it is¶
AgentCore Policy is the Bedrock AgentCore surface that enforces deterministic, Cedar-based access control over agent tool invocations — independent of what the model reasons or decides. It sits alongside the Gateway and defines which agent sessions may invoke which tools.
Cedar is AWS's open-source policy language for fine-grained, verifiable authorization decisions; Policy uses it so authorization is evaluated by a rules engine, not inferred by the LLM.
Why it exists¶
In a model-driven agent, the model chooses which tools to call — so hard constraints cannot live in the prompt or an orchestration graph. Policy makes the constraint mechanical:
"Policy in Amazon Bedrock AgentCore enforces deterministic access control independently of model reasoning." — AgentFlo (Source: sources/2026-08-20-aws-how-agentflo-built-ai-sales-agents-with-amazon-bedrock-agentcore)
Example rule: a sales agent can't call customer-support-only APIs, regardless of what the conversation or a prompt-injection attempt tries to make it do.
Guardrails embedding¶
Bedrock Guardrails can be embedded in Policy to filter prompt attacks, harmful content, and sensitive information on both requests and responses — layering content-safety filtering on top of tool-authorization rules.
Relation to Gateway and Identity¶
- Policy decides which session may invoke which tool (deterministic authorization).
- Gateway executes the tool call once allowed and holds credentials centrally (patterns/central-proxy-choke-point).
- Identity authenticates the agent identity behind those decisions.
Forbid-wins semantics and tier mapping (2026-08-26)¶
In AWS's graduated autonomy architecture, Policy is the deterministic enforcement layer that maps an agent's autonomy tier to a Cedar policy state, exploiting Cedar's forbid-wins composition — one satisfied forbid overrides any number of permits (deny-wins-policy-composition) (Source: sources/2026-08-26-aws-closing-the-ai-agent-trust-gap-with-graduated-autonomy):
- Probation — a forbid policy blocks write/execute/delete tool actions.
- Promotion — the forbid policy is removed and broader permits take effect.
- Demotion — the forbid policy is re-applied.
Because Gateway in enforce mode lists only tools policy could permit, a tier's unconditional forbids keep blocked tools out of the agent's tool listing altogether. Cedar denies by default, so enforcement never depends on the agent choosing to behave. A single Cedar deny-all policy implements the emergency stop — denying all tool invocations within seconds, no redeploy — and is out of band, evaluated outside the agent's process.
Caveats¶
- Architecture-level disclosure only. The AgentFlo post names Policy's role (Cedar-based, deterministic, tool-scoped, Guardrails-embeddable) but not its internal evaluation model, latency, or policy-authoring workflow.
Seen in¶
- sources/2026-08-20-aws-how-agentflo-built-ai-sales-agents-with-amazon-bedrock-agentcore — Cedar-based deterministic tool authorization for AgentFlo's agents (e.g. sales agent barred from support-only APIs), with Bedrock Guardrails embeddable in Policy for request/response content filtering.
-
sources/2026-08-21-aws-how-agentflo-built-ai-sales-agents-with-amazon-bedrock-agentcore-part-2 — Part 2 details Policy as the during-tool-execution layer of AgentFlo's three-layer guardrails: Cedar rules enforce business constraints (max discount %, tool scope) independent of model reasoning, and integrate with Bedrock Guardrails to run prompt-attack detection / content filtering / sensitive-info blocking at the gateway boundary.
-
sources/2026-08-26-aws-closing-the-ai-agent-trust-gap-with-graduated-autonomy — Policy as the deny-by-default enforcement layer of graduated autonomy: tier mapped to Cedar forbid state (probation forbids write/execute/delete; promotion removes it; demotion re-applies), forbid-wins semantics, tool-listing restricted to permitted tools, and a Cedar deny-all emergency stop.
- sources/2026-09-11-aws-from-zero-shot-forecast-to-purchase-order-with-agentcore
— Policy guards what writes reach external systems, paired with the
Gateway (Gateway validates who is calling via Cognito JWT;
Policy decides whether this call is allowed via Cedar). Two rules on the
single registered write tool
save_decision:allow_write_reporting_only(only the Reporting workflow identity may call it) anddeny_high_value_orders— aforbidoncontext.input.budget_used > 50000regardless of principal. Key insight: the deny is meaningful only at the write boundary — putting it upstream oncalculate_orderwould be ineffective because the agent could re-run the calculation until it passed and the denial wouldn't map to any durable effect.
Related¶
- systems/bedrock-agentcore
- systems/agentcore-gateway
- systems/agentcore-identity
- systems/amazon-bedrock-guardrails
- patterns/central-proxy-choke-point
- three-layer-agent-guardrails
- graduated-autonomy
- deny-wins-policy-composition
- emergency-stop-deny-all
- out-of-band-agent-enforcement
- model-driven-agent-architecture