Skip to content
Security & risk

AWS Adds Access Controls for AI Agents Calling External Tools

Short answer

AWS released Bedrock AgentCore Gateway, a managed layer that authenticates and authorizes AI agents before they can call external tools, APIs or databases, and logs every call. It closes a common gap where agents built for automation get broad, unaudited access to backend systems.

What this means for operators

If your company has connected an AI agent to your CRM, ticketing system, or internal APIs to automate sales outreach or support triage, that agent likely has more access than it needs and no audit trail of what it actually did. AgentCore Gateway lets you set per-tool permissions (e.g., an agent can read customer records but not modify billing) and get a log of every call, which matters the moment a customer asks what data an AI touched or a security review asks the same question. For a 10-200 person company without a dedicated security team, this shifts agent governance from a custom-built afterthought to a configuration you turn on, provided you're already on AWS or willing to route agent traffic through Bedrock.

AWS has released Bedrock AgentCore Gateway, a managed governance layer for AI agents that need to call external tools, APIs, and databases, according to the AWS Machine Learning Blog.

The gateway sits between an AI agent and the tools it's allowed to use, enforcing authentication and fine-grained authorization on each call. Instead of an agent holding broad, standing credentials to internal systems, the gateway can restrict access per tool, per action, and log every request for audit purposes.

This addresses a gap that has grown alongside agentic AI adoption: many teams have wired agents into CRMs, support platforms, and internal databases faster than they've built controls around what those agents can actually do once connected. A support agent given access to a ticketing API for automation purposes could, without guardrails, also read or modify records outside its intended scope. AgentCore Gateway is built to make that scope explicit and enforceable rather than implicit.

For companies already running workloads on AWS, the feature integrates with existing IAM-style permissioning, meaning governance can be configured without building a custom authorization layer from scratch. AWS positions this as part of the broader Bedrock AgentCore stack aimed at making agentic deployments auditable enough for regulated or security-conscious environments.

What changes for operators. A 10-200 person B2B company automating sales or support with AI agents typically has none of this governance in place today — access is granted broadly because building granular permissions is expensive and time-consuming for a small team. AgentCore Gateway turns that into a managed configuration: define which tools an agent can call, under what conditions, and get a log for compliance or incident review. That matters increasingly as customers and partners start asking vendors what access their AI systems have to sensitive data, a question that's becoming common in vendor security questionnaires and enterprise procurement.

The tradeoff is lock-in: the governance benefit is tied to using Bedrock's agent stack specifically, so companies running agents on other platforms (LangChain, custom orchestration, or non-AWS agent frameworks) don't get this by default and would need equivalent controls elsewhere. For teams already committed to AWS, it's a lower-effort way to close a real audit gap before it becomes a client-facing question or a security incident.

Source: AWS Machine Learning Blog

Next step

Discovery Sprint

If that argument holds for your operation, the next step is measuring it. Thirty minutes on one process, and we say whether the arithmetic is likely to close.

Put a time in the calendar

Thirty minutes, free. The sprint is what the call is about.

Fee
$2,500
Length
1-2 weeks

Refunded in full if we conclude you should not build.