Skip to main content
Forge assumes a customer-owned cross-account IAM role to discover AI resources and workload metadata across selected AWS accounts and regions. Gateway inline policy also requires the generated Gateway operator role and interceptor resources in each account that contains a protected Gateway.

Coverage

Workload collection reads metadata and environment-variable names, not secret values.

Connection

The generated setup artifact grants explicit read actions for every collector; it does not grant wildcard Bedrock or AgentCore mutations. Equivalent custom policies should mirror the current List, Get, and Describe operations in the generated policy. bedrock-agentcore:InvokeGateway is separately scoped to gateway ARNs because MCP tools/list is a signed gateway invocation, not a control-plane read.

Feature-specific requirements

Do not treat one successful AWS API call as validation for every feature. Add only the permission group for the features you enable and use the generated artifacts as the source of truth for their current action list. Workload attribution additionally uses ecs:ListClusters, eks:ListClusters, lambda:ListFunctions, iam:GetRole, and iam:ListAttachedRolePolicies. Cloud artifact discovery and image acquisition use ecr:DescribeRepositories, ecr:ListImages, ecr:BatchGetImage, ecr:GetDownloadUrlForLayer, and ecr:GetAuthorizationToken. S3 data labels are optional and require s3:GetBucketTagging, s3:GetObjectTagging, s3:GetBucketLocation, and s3:ListAllMyBuckets. Restrict object-tag access to approved buckets when using a custom policy.

Setup

  1. Open Integrations → Amazon Web Services, enter the regions, Role ARN, and account ID, then open Guided setup.
  2. Deploy the generated OIDC provider, trust policy, and read-only role in every account in scope, then save its ARN and region list in Forge.
  3. Select Test. Forge validates role assumption and the enabled service reads independently.
  4. Select Sync and confirm account- and region-specific counts in Inventory.
  5. Enable Bedrock model invocation logging separately if direct model-call telemetry is required.
Saving a new connection triggers its first inventory run. Manual Sync and the periodic scheduler use the same idempotent collector and persistence path. Coverage is recorded per region and resource family; an AgentCore denial does not discard successful Bedrock or AgentCore families from the same run. For an MCP AgentCore gateway, Forge stores the gateway as an MCP server, each gateway target as a connector, and each advertised tool separately with its description and input schema. Forge combines control-plane schemas with a SigV4-signed MCP tools/list response. A tool is related to a target only when AWS’s advertised name supplies an unambiguous target prefix; gateway helper tools remain gateway-scoped. Guided setup provides a CloudFormation stack. Review the OIDC issuer, subject, audience, account, regions, and optional S3 resources before applying it.

Operator access and artifact scanning

Native NHI containment, identity rightsizing, and Agent access use a separate operator or broker connection. The inventory role remains read-only. Guided setup generates the bounded trust, permission policy, validation, and offboarding artifacts for the selected purpose. See Non-human identities, Identity rightsizing, and Agent identities for the feature workflows. Saving an inventory connection does not enable IAM mutation or Agent credential issuance. ECR image scanning uses the registry permissions above. Filesystem snapshot scanning is opt-in and additionally requires an exact scanner AMI for every selected region plus the generated, tag-constrained EC2, EBS snapshot, instance-profile, network-interface, and cleanup permissions. See Cloud artifact scanning.

Runtime

AgentCore Gateway inline policy

  1. In Integrations → Amazon Web Services → Guided setup, copy and deploy the generated CloudFormation stack in the account that owns your AgentCore Gateways. For AWS Organizations, deploy the generated organization stack to the member accounts in scope. The stack creates the Gateway operator role, request and response interceptor Lambdas, a short-lived runtime credential store, and session state. You do not need to replace an existing Gateway or change its tool targets.
  2. Save the AWS connection and run Sync. Forge discovers Gateways in the selected regions and attaches its two interceptors to eligible Gateways. Repeat Sync after adding a Gateway or region. The ordinary scheduler also reconciles new Gateways.
  3. Check the Sync diagnostics and read the Gateway in AWS with aws bedrock-agentcore-control get-gateway --gateway-identifier <gateway-id> --region <region>. Protection requires both Forge interceptor ARNs in interceptorConfigurations and Gateway status READY. If either slot already contains a customer interceptor, Forge leaves it intact and reports observing coverage. That Gateway remains observe-only until its interceptors can be composed safely.
  4. Call a low-risk MCP tool through the Gateway and confirm the Forge policy decision appears in Activity. Exercise a block policy and verify the target did not run. For redaction, inspect the content returned to the caller.
Forge evaluates MCP tools/call requests before target execution and responses before delivery: Direct calls that bypass the Gateway are not protected by these interceptors. HTTP and inference target traffic is not covered by the MCP tool-call policy path. A response policy cannot undo side effects already performed by a tool. The older generated example that creates a new Lambda tool target is not part of Guided setup. It contains a sample tool implementation and does not protect the targets on your existing Gateway.

Verification

If inventory is partial, inspect the per-account, per-region, and per-resource- family result rather than expanding the role globally. Healthy families remain usable and visible; a failed Agent Registry read does not erase successful Bedrock, workload, or NHI inventory. Partial inventory is not complete rightsizing evidence: each rightsizing dimension still has to pass its own usage, history, mutation, readback, and rollback checks.

Permission troubleshooting

Run validation through Test so the same OIDC assertion and AssumeRoleWithWebIdentity path used by scheduled sync is exercised. For supporting diagnosis, inspect the role trust and run the generated validation script in the target account; do not replace the Forge federation test with long-lived access keys. AccessDenied includes the denied action and resource; add that action only at the intended account/resource scope. Verify identity and location before editing policy:
The caller account must equal the saved account ID. The returned role ARN must match the saved Role ARN, including partition, path, and role name. Run the failed regional API in the Region shown by Forge; a healthy response in a different account or Region does not resolve the blocker. If agent-registry-control is not a recognized AWS CLI command, update AWS CLI before testing. Do not substitute the public-preview AgentCore registry command.

Simulation versus the actual endpoint

iam:SimulatePrincipalPolicy is useful supporting evidence, but an allowed simulation is not proof that the service endpoint will accept the request. Test with credentials for the exact assumed role and call the exact endpoint, action, account, Region, and resource ARN reported by Forge. If simulation allows the action but the real call returns 403, keep the real endpoint result as the blocker and check service control policies, permissions boundaries, session or resource policies, endpoint policy, service availability, and API namespace. For Agent Registry specifically, test agent-registry-control with an agent-registry:* read action; do not use the public-preview AgentCore registry endpoint as proof.

CloudTrail and IAM history

LookupEvents returns the past 90 days of management events for one account and one Region; it does not prove data-event coverage or retained history beyond that window. For recent diagnosis, query the exact action and Region, for example:
IAM is a global service, and AWS records its management events in the us-east-1 event history. Use the Region reported by Forge for regional service activity, but use us-east-1 when diagnosing IAM mutation history. Action-level usage requires the event classes for the permissions being evaluated, complete pagination, and exact attribution to the role session. Service-level Access Advisor timestamps are investigation evidence, not proof that an individual action was unused. Rightsizing also needs grant-lifetime evidence. Use continuous AWS Config history for the IAM resource when available, or complete successful IAM mutation history for the entire analysis window together with the current IAM snapshot. That history must cover every relevant create, delete, inline-policy, managed-policy attachment, trust-policy, group-membership, and access-key change for the target. A missing Region, page, selector, retention interval, or unmatched IAM mutation leaves that dimension partial and blocks an executable removal; Forge does not interpret missing history as inactivity. InvalidIdentityToken means AWS rejected the federated token before service permissions were evaluated. Re-run Guided setup: it verifies the exact OIDC provider ARN and issuer, adds the generated audience without removing other client IDs, and validates the role trust audience and subject. If that exact readback passes, check the provider thumbprints or issuer certificate-chain fallback and confirm that the system clock is correct.