Coverage
Workload collection reads metadata and environment-variable names, not secret
values.
Connection
The generated setup artifact grants explicit read actions for every collector;
it does not grant wildcard Bedrock or AgentCore mutations. Equivalent custom
policies should mirror the current
List, Get, and Describe operations in
the generated policy. bedrock-agentcore:InvokeGateway is separately scoped
to gateway ARNs because MCP tools/list is a signed gateway invocation, not a
control-plane read.
Feature-specific requirements
Do not treat one successful AWS API call as validation for every feature. Add only the permission group for the features you enable and use the generated artifacts as the source of truth for their current action list.
Workload attribution additionally uses
ecs:ListClusters,
eks:ListClusters, lambda:ListFunctions, iam:GetRole, and
iam:ListAttachedRolePolicies. Cloud artifact discovery and image acquisition
use ecr:DescribeRepositories, ecr:ListImages, ecr:BatchGetImage,
ecr:GetDownloadUrlForLayer, and ecr:GetAuthorizationToken.
S3 data labels are optional and require s3:GetBucketTagging,
s3:GetObjectTagging, s3:GetBucketLocation, and s3:ListAllMyBuckets.
Restrict object-tag access to approved buckets when using a custom policy.
Setup
- Open Integrations → Amazon Web Services, enter the regions, Role ARN, and account ID, then open Guided setup.
- Deploy the generated OIDC provider, trust policy, and read-only role in every account in scope, then save its ARN and region list in Forge.
- Select Test. Forge validates role assumption and the enabled service reads independently.
- Select Sync and confirm account- and region-specific counts in Inventory.
- Enable Bedrock model invocation logging separately if direct model-call telemetry is required.
tools/list response. A tool is related to a target only when
AWS’s advertised name supplies an unambiguous target prefix; gateway helper
tools remain gateway-scoped.
Guided setup provides a CloudFormation stack. Review the OIDC issuer, subject,
audience, account, regions, and optional S3 resources before applying it.
Operator access and artifact scanning
Native NHI containment, identity rightsizing, and Agent access use a separate operator or broker connection. The inventory role remains read-only. Guided setup generates the bounded trust, permission policy, validation, and offboarding artifacts for the selected purpose. See Non-human identities, Identity rightsizing, and Agent identities for the feature workflows. Saving an inventory connection does not enable IAM mutation or Agent credential issuance. ECR image scanning uses the registry permissions above. Filesystem snapshot scanning is opt-in and additionally requires an exact scanner AMI for every selected region plus the generated, tag-constrained EC2, EBS snapshot, instance-profile, network-interface, and cleanup permissions. See Cloud artifact scanning.Runtime
AgentCore Gateway inline policy
- In Integrations → Amazon Web Services → Guided setup, copy and deploy the generated CloudFormation stack in the account that owns your AgentCore Gateways. For AWS Organizations, deploy the generated organization stack to the member accounts in scope. The stack creates the Gateway operator role, request and response interceptor Lambdas, a short-lived runtime credential store, and session state. You do not need to replace an existing Gateway or change its tool targets.
- Save the AWS connection and run Sync. Forge discovers Gateways in the selected regions and attaches its two interceptors to eligible Gateways. Repeat Sync after adding a Gateway or region. The ordinary scheduler also reconciles new Gateways.
- Check the Sync diagnostics and read the Gateway in AWS with
aws bedrock-agentcore-control get-gateway --gateway-identifier <gateway-id> --region <region>. Protection requires both Forge interceptor ARNs ininterceptorConfigurationsand Gateway statusREADY. If either slot already contains a customer interceptor, Forge leaves it intact and reports observing coverage. That Gateway remains observe-only until its interceptors can be composed safely. - Call a low-risk MCP tool through the Gateway and confirm the Forge policy decision appears in Activity. Exercise a block policy and verify the target did not run. For redaction, inspect the content returned to the caller.
tools/call requests before target execution and responses
before delivery:
Direct calls that bypass the Gateway are not protected by these interceptors.
HTTP and inference target traffic is not covered by the MCP tool-call policy
path. A response policy cannot undo side effects already performed by a tool.
The older generated example that creates a new Lambda tool target is not part
of Guided setup. It contains a sample tool implementation and does not protect
the targets on your existing Gateway.
Verification
If inventory is partial, inspect the per-account, per-region, and per-resource-
family result rather than expanding the role globally. Healthy families remain
usable and visible; a failed Agent Registry read does not erase successful
Bedrock, workload, or NHI inventory. Partial inventory is not complete
rightsizing evidence: each rightsizing dimension still has to pass its own
usage, history, mutation, readback, and rollback checks.
Permission troubleshooting
Run validation through Test so the same OIDC assertion andAssumeRoleWithWebIdentity path used by scheduled sync is exercised. For
supporting diagnosis, inspect the role trust and run the generated validation
script in the target account; do not replace the Forge federation test with
long-lived access keys.
AccessDenied includes the denied action and resource; add that action only at
the intended account/resource scope. Verify identity and location before
editing policy:
agent-registry-control is not a recognized AWS CLI command, update AWS CLI
before testing. Do not substitute the public-preview AgentCore registry
command.
Simulation versus the actual endpoint
iam:SimulatePrincipalPolicy is useful supporting evidence, but an allowed
simulation is not proof that the service endpoint will accept the request. Test
with credentials for the exact assumed role and call the exact endpoint, action,
account, Region, and resource ARN reported by Forge. If simulation allows the
action but the real call returns 403, keep the real endpoint result as the
blocker and check service control policies, permissions boundaries, session or
resource policies, endpoint policy, service availability, and API namespace.
For Agent Registry specifically, test agent-registry-control with an
agent-registry:* read action; do not use the public-preview AgentCore registry
endpoint as proof.
CloudTrail and IAM history
LookupEvents returns the past 90 days of management events for one account
and one Region; it does not prove data-event coverage or retained history
beyond that window. For recent diagnosis, query the exact action and Region,
for example:
us-east-1 event history. Use the Region reported by Forge for regional
service activity, but use us-east-1 when diagnosing IAM mutation history.
Action-level usage requires the event classes for the permissions being
evaluated, complete pagination, and exact attribution to the role session.
Service-level Access Advisor timestamps are investigation evidence, not proof
that an individual action was unused.
Rightsizing also needs grant-lifetime evidence. Use continuous AWS Config
history for the IAM resource when available, or complete successful IAM
mutation history for the entire analysis window together with the current IAM
snapshot. That history must cover every relevant create, delete, inline-policy,
managed-policy attachment, trust-policy, group-membership, and access-key
change for the target. A missing Region, page, selector, retention interval, or
unmatched IAM mutation leaves that dimension partial and blocks an executable
removal; Forge does not interpret missing history as inactivity.
InvalidIdentityToken means AWS rejected the federated token before service
permissions were evaluated. Re-run Guided setup: it verifies the exact OIDC
provider ARN and issuer, adds the generated audience without removing other
client IDs, and validates the role trust audience and subject. If that exact
readback passes, check the provider thumbprints or issuer certificate-chain
fallback and confirm that the system clock is correct.