{"id":146053,"date":"2026-08-20T11:41:08","date_gmt":"2026-08-20T11:41:08","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/146053\/"},"modified":"2026-08-20T11:41:08","modified_gmt":"2026-08-20T11:41:08","slug":"aws-limits-ai-agents-data-access-even-when-manipulated","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/146053\/","title":{"rendered":"AWS limits AI agents\u2019 data access, even when manipulated"},"content":{"rendered":"<p>AWS has detailed an approach for propagating user authorization context through <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/21\/report-enterprise-ai-identity-risk\/\" rel=\"nofollow noopener\" target=\"_blank\">AI agents<\/a>, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself.<\/p>\n<p>Customers using Amazon Bedrock AgentCore can build AI agents that pull information from Amazon DynamoDB tables, document repositories, SaaS platforms, and internal knowledge bases to answer questions and automate workflows. Without awareness of the user making a request, however, an agent could return information that the user is not authorized to see.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/AWS-AI_access_controls.webp\" class=\"aligncenter\" alt=\"AWS AI access controls\" title=\"The following diagram shows the architecture used in this demonstration.\"\/><\/p>\n<p class=\"text-center\">The following diagram shows the architecture used in this demonstration. (Source: AWS)<\/p>\n<p>\u201cThe agent acts as an orchestrator, not a gatekeeper,\u201d AWS <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/propagate-user-authorization-context-in-ai-agents-with-amazon-bedrock-agentcore\/\" target=\"_blank\" rel=\"nofollow noopener\">explained<\/a>. \u201cAuthorization is enforced by downstream services.\u201d<\/p>\n<p>CRM access control use case<\/p>\n<p>AWS illustrates the approach with a CRM application where employees from Sales and Finance interact with the same AI agent to access customer information.<\/p>\n<p>Sales employees need access to customer contracts, pricing strategies, and sales pipeline data, while Finance employees need access to invoices, payment records, and financial reports.<\/p>\n<p>The agent can retrieve information from Amazon DynamoDB, documents stored in Amazon Bedrock Knowledge Bases, and external services such as Salesforce.<\/p>\n<p>When a Sales employee asks to see customer contracts, for example, the agent should only be able to retrieve information available to the Sales department and not Finance data.<\/p>\n<p>AWS said enforcing these restrictions outside the agent provides protection even if the agent is manipulated through <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/11\/owasp-prompt-injection-ai-security-failures\/\" rel=\"nofollow noopener\" target=\"_blank\">prompt injection<\/a> or affected by an application bug.<\/p>\n<p>User identity and authorization<\/p>\n<p>Employees first authenticate with their corporate credentials. AWS uses Amazon Cognito as the identity provider in its example, although Microsoft Entra ID and Okta can also be used.<\/p>\n<p>Information about the employee, such as their department, is added to their authentication tokens and carried with requests to the agent.<\/p>\n<p>Amazon Bedrock AgentCore Runtime validates the user\u2019s token and checks their authorization information before allowing the request to reach the agent. Requests from users who do not meet the configured requirements can be rejected before the agent runs.<\/p>\n<p>The authorization context can then be passed on when the agent accesses other services, allowing those services to determine which information the user is permitted to access.<\/p>\n<p>Access controls remain outside the agent<\/p>\n<p>AWS demonstrates the approach across DynamoDB, Amazon Bedrock Knowledge Bases, and Salesforce.<\/p>\n<p>For DynamoDB, access can be restricted to records associated with the user\u2019s department. Salesforce can similarly apply its own sharing rules so that the agent receives only records available to the individual user.<\/p>\n<p>Amazon Bedrock Knowledge Bases uses metadata filtering to limit retrieved documents to the appropriate department. AWS notes that this control operates at the application layer and recommends separate knowledge bases with <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/02\/02\/cloud-security-alliance-securing-ai-identities\/\" rel=\"nofollow noopener\" target=\"_blank\">IAM policies<\/a> where stricter isolation is required.<\/p>\n<p>The broader goal is to avoid giving an AI agent broad access and trusting it to filter sensitive information correctly. Instead, AWS recommends configuring underlying services to reject unauthorized requests \u201cregardless of what the agent asks for.\u201d<\/p>\n<p>\u201cThis way, the agent\u2019s credentials are inherently limited to the requesting user\u2019s permissions, and no amount of prompt manipulation can bypass those boundaries,\u201d authors <a href=\"https:\/\/www.linkedin.com\/in\/anshu-bathla\/\" target=\"_blank\" rel=\"nofollow noopener\">Anshu Bathla<\/a>, <a href=\"https:\/\/www.linkedin.com\/in\/praffulgupta11\/\" target=\"_blank\" rel=\"nofollow noopener\">Prafful Gupta<\/a>, and <a href=\"https:\/\/www.linkedin.com\/in\/rohitverma242\/\" target=\"_blank\" rel=\"nofollow noopener\">Rohit Verma<\/a>, concluded.<\/p>\n","protected":false},"excerpt":{"rendered":"AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be&hellip;\n","protected":false},"author":2,"featured_media":146054,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[23615,179,24,405,7537,322,313,14674,41297],"class_list":["post-146053","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-access-controls","tag-agentic-ai","tag-ai","tag-ai-agents","tag-artificial-intelligence-agents","tag-aws","tag-cybersecurity","tag-identity-management","tag-identity-protection"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/146053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=146053"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/146053\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/146054"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=146053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=146053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=146053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}