Inside Veza’s AI Agent Security for Amazon Bedrock Agents: A Technical Deep Dive
Blog post from Veza
Veza’s AI Agent Security for Amazon Bedrock extends its AWS integration to automatically discover and model Bedrock Agents as non-human identities within a unified Access Graph. The platform traces each agent’s assumed IAM role, effective permissions across AWS resources, connected Action Groups, Knowledge Bases and their S3, SharePoint, Confluence, or Salesforce data sources, models, prompts, and guardrails. By representing both inbound access, such as which IAM principals can invoke or modify an agent, and outbound access to data and services, Veza aims to provide end-to-end visibility into agent permissions and potential blast radius. The distinct relationship between an agent and its IAM role makes delegation auditable and helps identify shared or overly privileged roles. Existing Veza capabilities including access reviews, risk scoring, rules and alerts, and natural-language graph searches can be applied to Bedrock Agents, including alerts for missing guardrails, unowned agents, or access to sensitive resources. Support is generally available to existing AWS integration customers without requiring a separate connector or runtime deployment.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 12 | 6,200 | 1,430 | 272 | +10% |
| Serverless | 6 | 1,019 | 237 | 96 | -45% |
| AI Coding Assistant | 1 | 2,234 | 577 | 171 | +12% |
| RAG | 1 | 1,005 | 263 | 108 | -56% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.