Add an AWS CloudWatch trace connection
Monitor AI agents built with AWS Bedrock AgentCore by adding an AWS CloudWatch trace connection. AI Control Tower collects trace data through your AWS credentials and a MID Server, without requiring SDK instrumentation.
Before you begin
Confirm the following:
- Your AI agents are built using AWS Bedrock AgentCore.
- Tracing is enabled for each AWS Bedrock AgentCore agent you want to monitor.
- An active MID Server is installed and configured in your ServiceNow instance. See MID Server installation.
- An AWS access key ID and secret access key with permission to read trace data from CloudWatch is available.
- This connector supports access key authentication only. Connections using an assumed role or external ID aren't currently supported.
- The access key must be created and its IAM policy configured in AWS. For details, see the Work Instruction | How to Create AWS Credentials on a Glide Instance [KB3143433] article in Now Support.
- After the access key ID and secret access key are created, work with your instance administrator to store them as a new AWS credential record in .
- You know the AWS region where your AI agents are deployed, such as
us-east-2.
Role required: sn_ai_governance.ai_steward
Procedure
Result
One or more trace connections appear on the Established sub-tab. If you selected both log group options, two connections appear, distinguished by a log group suffix on the connection name. If a connection is active, AI Control Tower begins collecting trace data after the first polling interval.
What to do next
Choose which metrics to include in evaluation scoring. See Activate evaluation scoring for external AI systems.