AWS managed policies for Amazon Bedrock AgentCore
An AWS managed policy is a standalone policy that is created and administered by AWS. AWS managed policies are designed to provide permissions for many common use cases so that you can start assigning permissions to users, groups, and roles.
Keep in mind that AWS managed policies might not grant least-privilege permissions for your specific use cases because they’re available for all AWS customers to use. We recommend that you reduce permissions further by defining customer managed policies that are specific to your use cases.
You cannot change the permissions defined in AWS managed policies. If AWS updates the permissions defined in an AWS managed policy, the update affects all principal identities (users, groups, and roles) that the policy is attached to. AWS is most likely to update an AWS managed policy when a new AWS service is launched or new API operations become available for existing services.
For more information, see AWS managed policies in the IAM User Guide.
Topics
AWS managed policy: BedrockAgentCoreNetworkServiceRolePolicy
AWS managed policy: AmazonBedrockAgentCoreMemoryBedrockModelInferenceExecutionRolePolicy
AWS managed policy: BedrockAgentCoreRuntimeIdentityServiceRolePolicy
AWS managed policy: BedrockAgentCoreRuntimeInstancesServiceRolePolicy
AWS managed policy: BedrockAgentCoreRuntimeInstancesOperatorRolePolicy
AWS managed policy: BedrockAgentCoreRuntimeInstancesInstanceRolePolicy
AWS managed policy: BedrockAgentCoreFullAccess
You can attach BedrockAgentCoreFullAccess to your users, groups, and roles.
This policy grants permissions that allow full access to the Amazon Bedrock AgentCore.
Permissions details
This policy includes the following permissions:
-
bedrock-agentcore(Amazon Bedrock Agent Core) – Allows principals full access to all Amazon Bedrock Agent Core resources. -
iam(AWS Identity and Access Management) – Allows principals to list and get information about roles and policies, and to pass roles with "BedrockAgentCore" in the name to the bedrock-agentcore service. Also allows creating service-linked roles for CloudWatch Application Signals, Amazon Bedrock AgentCore network, and Amazon Bedrock AgentCore runtime identity. -
secretsmanager(AWS Secrets Manager) – Allows principals to create, update, retrieve, and delete secrets with names that begin with "bedrock-agentcore". -
kms(AWS Key Management Service) – Allows principals to list and describe keys, and to decrypt data within the same AWS account when called via the Amazon Bedrock AgentCore service. -
s3(Amazon Simple Storage Service) – Allows principals to get objects from S3 buckets with names that begin with "bedrock-agentcore-gateway-" when called via the Amazon Bedrock AgentCore service. -
lambda(AWS Lambda) – Allows principals to list Lambda functions. -
logs(Amazon CloudWatch Logs) – Allows principals to access, query, and manage log data in log groups related to Amazon Bedrock AgentCore and Application Signals, including creating log groups and streams. -
application-autoscaling(Application Auto Scaling) – Allows principals to describe scaling policies. -
application-signals(Amazon CloudWatch Application Signals) – Allows principals to retrieve information about application signals and start discovery. -
autoscaling(Amazon EC2 Auto Scaling) – Allows principals to describe Auto Scaling resources. -
cloudwatch(Amazon CloudWatch) – Allows principals to retrieve and list metrics, generate queries, and access other CloudWatch resources. -
oam(Amazon CloudWatch Observability Access Manager) – Allows principals to list sinks. -
rum(Amazon CloudWatch RUM) – Allows principals to retrieve and list RUM resources. -
synthetics(Amazon CloudWatch Synthetics) – Allows principals to describe and get information about Synthetics resources. -
xray(AWS X-Ray) – Allows principals to retrieve trace information, manage trace segment destinations, and work with indexing rules. -
ecr(Amazon Elastic Container Registry) – Allows principals to describe repositories, list images, and describe images. -
bedrock(Amazon Bedrock) – Allows principals to invoke foundation models and inference profiles for evaluation purposes.
Considerations
Note the following limitations of this policy:
-
iam:CreateRoleis not included. When you create certain AgentCore resources (for example, harness or runtime) in the console, you can elect for the console to auto-create the resource’s execution role on your behalf. This requiresiam:CreateRolepermissions, which are not included in this managed policy. For more information, see Troubleshooting iam:CreateRole authorization in the console. -
iam:PassRoleis scoped by role name. When you create certain AgentCore resources (for example, harness or runtime), you must haveiam:PassRolepermissions on the resource’s execution role. This managed policy only includesiam:PassRolepermissions for roles with names matching*BedrockAgentCore*. For more information, see Troubleshooting iam:PassRole authorization. -
GetWorkloadAccessTokenForUserIdis included. This policy grants permission to callGetWorkloadAccessTokenForUserId, which allows issuing workload access tokens using a caller-supplied user identifier string without IdP token verification. This is suitable for development and quickstart scenarios. For production deployments, create custom IAM policies that only grantGetWorkloadAccessTokenForJWT(which validates the JWT signature, issuer, and expiry) and explicitly denyGetWorkloadAccessTokenForUserIdif your workloads always have a JWT available. For more information, see Get workload access token.
AWS managed policy: BedrockAgentCoreNetworkServiceRolePolicy
This policy is attached to a service-linked role that allows the service to perform actions on your behalf. You cannot attach this policy to your users, groups, or roles.
This policy grants permissions that allow AgentCore to create and manage network interfaces in your VPC when running in VPC mode.
Permissions details
This policy includes the following permissions:
-
ec2(Amazon Elastic Compute Cloud) – Allows the service to create, manage, and delete network interfaces in your VPC, assign and unassign private IP addresses, and describe VPC resources. Network interfaces are tagged with "AmazonBedrockAgentCoreManaged" to ensure the service only manages resources it creates.
You can view this policy at BedrockAgentCoreNetworkServiceRolePolicy.
For more information about the service-linked role that uses this policy, see Using service-linked roles for Amazon Bedrock AgentCore.
AWS managed policy: AmazonBedrockAgentCoreMemoryBedrockModelInferenceExecutionRolePolicy
You can attach AmazonBedrockAgentCoreMemoryBedrockModelInferenceExecutionRolePolicy to your users, groups, and roles.
This policy grants permissions that allow full access to the Amazon Bedrock Agent Core Memory.
Permissions details
This policy includes the following permissions.
-
bedrock– Allows principals to call the Amazon BedrockInvokemodelandInvokeModelWithResponseStreamactions. This is required so that an agent can store memories. -
bedrock-mantle– Allows principals to call theCreateInferenceandCallWithBearerTokenactions. This is required so that the service can process memories using Amazon Bedrock Mantle models.
AWS managed policy: BedrockAgentCoreRuntimeIdentityServiceRolePolicy
This policy is attached to a service-linked role that allows the service to perform actions on your behalf. You cannot attach this policy to your users, groups, or roles.
This policy grants permissions that allow access to identity and token management resources that are required for AgentCore Runtime authentication and authorization.
Permissions details
This policy includes the following permissions:
-
bedrock-agentcore(Amazon Bedrock Agent Core) – Allows the service to get workload access tokens for JWT authentication and user ID-based authentication. Specifically allowsGetWorkloadAccessToken,GetWorkloadAccessTokenForJWT, andGetWorkloadAccessTokenForUserIdactions on the default workload identity directory and its associated workload identities.
Policy contents
You can view the complete policy at BedrockAgentCoreRuntimeIdentityServiceRolePolicy.
For more information about the service-linked role that uses this policy, see Using service-linked roles for Amazon Bedrock AgentCore.
AWS managed policy: BedrockAgentCoreRuntimeInstancesServiceRolePolicy
This policy is attached to a service-linked role that allows the service to perform actions on your behalf. You cannot attach this policy to your users, groups, or roles.
This policy grants permissions that allow AgentCore to clean up the Amazon EC2 compute resources that a capacity provider creates for the Instances compute type.
Permissions details
This policy includes the following permissions:
-
ec2(Amazon Elastic Compute Cloud) – Allows the service to describe compute resources and to terminate instances, detach and delete Amazon EBS volumes, and delete launch templates that the service manages. Access is scoped to resources that AgentCore manages, using theec2:ManagedResourceOperatorcondition key. -
autoscaling(Amazon EC2 Auto Scaling) – Allows the service to describe and delete the Auto Scaling groups that it creates, and to complete lifecycle actions. Access is scoped to resources tagged withbedrock-agentcore:capacity-provider-id. -
events(Amazon EventBridge) – Allows the service to remove targets from, and delete, the EventBridge rules that it manages. Access is scoped to resources with theevents:ManagedBycondition key set tobedrock-agentcore.amazonaws.com.
Policy contents
You can view the complete policy at BedrockAgentCoreRuntimeInstancesServiceRolePolicy.
For more information about the service-linked role that uses this policy, see Using service-linked roles for Amazon Bedrock AgentCore.
AWS managed policy: BedrockAgentCoreRuntimeInstancesOperatorRolePolicy
You can attach BedrockAgentCoreRuntimeInstancesOperatorRolePolicy to the capacity provider operator role that you specify when you create a capacity provider for the Instances compute type. AgentCore assumes the operator role to create and manage compute resources in your account on your behalf.
This policy grants permissions that allow AgentCore to create and manage the Amazon EC2 compute and associated resources for a capacity provider.
Permissions details
This policy includes the following permissions:
-
ec2(Amazon Elastic Compute Cloud) – Allows the service to describe, create, tag, and manage the EC2 resources that back a capacity provider, including launch templates, fleets, instances, network interfaces, and Amazon EBS volumes. Access to create resources is scoped by thebedrock-agentcore:capacity-provider-idrequest tag, and access to manage existing resources is scoped by theec2:ManagedResourceOperatorcondition key. Instances are launched only from Amazon-owned AMIs. -
autoscaling(Amazon EC2 Auto Scaling) – Allows the service to create and manage the Auto Scaling groups that launch instances. Access is scoped to Auto Scaling groups named with theagentcore-managed-instances-prefix and tagged withbedrock-agentcore:capacity-provider-id. -
events(Amazon EventBridge) – Allows the service to create and manage the EventBridge rules (named with theagentcore-lifecycle-events-prefix) that deliver instance lifecycle events. -
iam– Allows the service to create the Auto Scaling service-linked role and to pass the default instance role (with theAmazonBedrockAgentCoreCapacityProviderDefaultInstanceRoleprefix) to Amazon EC2.
Policy contents
You can view the complete policy at BedrockAgentCoreRuntimeInstancesOperatorRolePolicy.
AWS managed policy: BedrockAgentCoreRuntimeInstancesInstanceRolePolicy
This is the default policy for the instance role of instances managed by AgentCore Runtime Instances. AgentCore attaches this policy to the default instance role that it creates for a capacity provider.
This policy grants permissions that allow an instance to write its system logs.
Permissions details
This policy includes the following permissions:
-
bedrock-agentcore(Amazon Bedrock AgentCore) – Allows an instance to callPutSystemLogEventsso that AgentCore can collect system logs from the instance.
Policy contents
You can view the complete policy at BedrockAgentCoreRuntimeInstancesInstanceRolePolicy.
AgentCore updates to AWS managed policies
View details about updates to AWS managed policies for AgentCore since this service began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the AgentCore Document history page.
| Change | Description | Date |
|---|---|---|
|
BedrockAgentCoreRuntimeInstancesServiceRolePolicy – New policy |
Added a new AWS managed policy that allows AgentCore to clean up the Amazon EC2 compute resources created for the Instances compute type. |
August 6, 2026 |
|
BedrockAgentCoreRuntimeInstancesOperatorRolePolicy – New policy |
Added a new AWS managed policy that allows AgentCore to create and manage Amazon EC2 compute and associated resources for a capacity provider through the operator role. |
August 6, 2026 |
|
BedrockAgentCoreRuntimeInstancesInstanceRolePolicy – New policy |
Added a new AWS managed policy that serves as the default instance role policy for instances managed by AgentCore Runtime Instances, allowing an instance to write its system logs. |
August 6, 2026 |
|
AmazonBedrockAgentCoreMemoryBedrockModelInferenceExecutionRolePolicy – Updated policy |
Added Amazon Bedrock Mantle permissions ( |
July 17, 2026 |
|
BedrockAgentCoreFullAccess – Updated policy |
Added Amazon Elastic Container Registry permissions ( |
December 2, 2025 |
|
BedrockAgentCoreFullAccess – Updated policy |
Added the |
November 3, 2025 |
|
BedrockAgentCoreRuntimeIdentityServiceRolePolicy – New policy |
Added a new AWS managed policy that allows AgentCore to manage workload identity access tokens and OAuth credentials for agent runtimes. |
October 10, 2025 |
|
BedrockAgentCoreFullAccess – Updated policy |
Added permission to create the Amazon Bedrock AgentCore runtime identity service-linked role. |
October 9, 2025 |
|
BedrockAgentCoreFullAccess – Updated policy |
Added permission to create the Amazon Bedrock AgentCore runtime identity service-linked role. |
October 8, 2025 |
|
BedrockAgentCoreFullAccess – Updated policy |
Added permission to create the Amazon Bedrock AgentCore network service-linked role. |
September 19, 2025 |
|
BedrockAgentCoreNetworkServiceRolePolicy – New policy |
Added a new AWS managed policy that allows AgentCore to create and manage network interfaces in your VPC when running in VPC mode. |
September 19, 2025 |
|
AgentCore started tracking changes |
AgentCore started tracking changes for its AWS managed policies. |
July 16, 2025 |