Skip to content
Agents and automation

A runtime for agents, and a new population of identities.

Bedrock AgentCore provides managed infrastructure for running agents on AWS, including the memory, tools, and identity plumbing an agent needs to act rather than only answer. Our work is scoping agent runtimes, ownership, and the audit trail they produce.

AgentCore gives agents a managed runtime on AWS. Each one authenticates, holds permissions, and acts, which makes it an identity problem before it is a platform one.

What it is

Bedrock AgentCore provides managed infrastructure for running agents on AWS, including the memory, tools, and identity plumbing an agent needs to act rather than only answer.

It is for organizations moving agents from pilot to something operational, at which point the number of non-human identities in the estate starts increasing faster than anyone is tracking.

source build review deploy run scope check built inside the permission model, not beside it L1 L2 L3 L4

What it does

Agents get a managed runtime

Which removes the infrastructure problem and leaves the accountability one.

Each agent authenticates

So each is, in principle, enumerable, scoped, and revocable.

Where it fits

L4, agents and automation, governed from L1 and evidenced at L3. An agent runtime creates identities that act on their own schedule. Whether each has an owner, a scope, and a review date is the difference between an operational capability and an unmanaged one.

Where it earns its place

An organization moving agents out of pilot

One agent is a project. Twenty is a population, and populations need a lifecycle.

An estate that cannot enumerate service accounts

Adding agents to a population nobody can list makes the next review harder, not easier.

Proof

23%

Of organizations report having an identity strategy that covers agents at all.

Cloud Security Alliance and Strata, 2026.

Questions we get

Is this an infrastructure engagement?
No. Our involvement is the identity and governance layer around the runtime, alongside the estate it will reach into.
How does this relate to agents inside Atlassian?
Same discipline, different surface. An estate usually ends up with agents in several places and one review that has to cover all of them.

Find out what an agent would inherit.

Fixed scope. The assessment reads the three layers an agent lands on, identity, platform and governance, before anything is switched on. You get the findings, the ownership gaps, and the order to close them in.