Prerequisites
Before you begin using AgentCore insights, ensure you have the following:
Requirements
-
AWS Account with appropriate IAM permissions
-
Amazon CloudWatch access for reading agent session traces and viewing insight results
-
Transaction Search enabled in CloudWatch — see AgentCore Observability for setup instructions
-
AWS Distro for OpenTelemetry (ADOT) SDK instrumenting your agent — your agent must emit traces to CloudWatch Logs
-
An active agent with at least one completed session producing traces in CloudWatch Logs
IAM permissions
Your IAM user or role needs the following permissions to configure and run insights:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "bedrock-agentcore:CreateOnlineEvaluationConfig", "bedrock-agentcore:GetOnlineEvaluationConfig", "bedrock-agentcore:ListOnlineEvaluationConfigs", "bedrock-agentcore:UpdateOnlineEvaluationConfig", "bedrock-agentcore:DeleteOnlineEvaluationConfig", "bedrock-agentcore:StartBatchEvaluation", "bedrock-agentcore:GetBatchEvaluation", "bedrock-agentcore:ListBatchEvaluations" ], "Resource": "*" } ] }
Execution role
The online evaluation configuration requires an execution role (evaluationExecutionRoleArn) that allows the service to:
-
Read traces from CloudWatch Logs
-
Invoke Amazon Bedrock models for insight analysis
-
Store and retrieve insight results
If you have already configured an execution role for AgentCore Evaluations, the same role works for insights. See Evaluations Prerequisites for details on creating this role.
Note
If you plan to use insights findings to generate optimized configurations through AgentCore optimization recommendations, you also need bedrock-agentcore:StartRecommendation, bedrock-agentcore:GetRecommendation, bedrock-agentcore:ListRecommendations, and bedrock-agentcore:DeleteRecommendation permissions. See Optimization Prerequisites for details.