Add an AWS Bedrock or AWS Bedrock Agent Core connection
Connect AWS Bedrock or AWS Bedrock Agent Core to AI Control Tower so AI agent containment using kill switch protocol can reach and deactivate agents running on AWS.
Before you begin
Confirm the following:
- You have an AWS Identity and Access Management (IAM) service account with the
permissions required for the connector you're configuring:
- For AWS Bedrock Agent Core, in the
bedrock-agentcore:namespace onruntime/*resources:GetResourcePolicy,PutResourcePolicy,DeleteResourcePolicy. - For AWS Bedrock Agent (classic), in the
bedrock:namespace onagent/*andagent-alias/*resources:ListAgentAliases,UpdateAgentAlias,TagResource,UntagResource,ListTagsForResource.
- For AWS Bedrock Agent Core, in the
- The AWS access key ID and secret access key for that service account are available.
Role required: sn_ai_governance.ai_steward
About this task
Adding this connection has two parts: first you create a Connection & Credential Alias that stores your AWS credentials, then you attach that alias to the security connector in AI Control Tower.
Procedure
Result
The connector appears on the Established connections sub-tab. AI Control Tower can now use this connection to apply AI agent containment using kill switch protocol to agents running on the connected AWS Bedrock or AWS Bedrock Agent Core service.