
Agent platform
Requirements
4
before agents go live
Connections
1
in your workspace
Agents found
0
across those connections
Governed
0%
0 of 0 in the register
Compliance requirements
IAM least privilege
FFIECUse a read-only role assumed by TRUINT with bedrock:ListAgents and bedrock:GetAgent only.
Guardrail attachment
ECOA / Reg BEvery agent alias serving customers must have a Bedrock guardrail with denied topics and PII filters.
Model invocation logging
BCBS 239Enable invocation logging to CloudWatch or S3 in every region where agents run.
Region and residency
OCC 2013-29Record the regions used and confirm they match the bank data residency standard.
Integration steps
Create a read-only role
Provision an IAM role limited to Bedrock agent read actions in each active region.
Export the agent list
Automatic discovery is not wired yet, so export agent names, aliases and models from the console or CLI.
Connect here
Create a manual connection and paste the agent list, one per line as name | model | description.
Attach evidence
Link guardrail configuration and invocation log locations to each governed asset.
Your connections
Technical details
Evidence collected