AWS described a solution for cross-account access by Bedrock AgentCore agents to knowledge bases without copying data
AWS described an architecture that allows agents in Bedrock AgentCore to generate answers from Bedrock Knowledge Bases in another AWS account without copying data, using AWS STS and a narrowly scoped IAM role. It offers two implementation variants and a GitHub sample.
AWS Machine Learning Blog described an architecture that addresses a situation in which agents deployed through Amazon Bedrock AgentCore in one AWS account need to generate answers from a knowledge base (Amazon Bedrock Knowledge Bases, a fully managed Retrieval Augmented Generation service) stored in another AWS account and backed by Amazon Redshift Serverless. The goal is to enable this access without copying source data between accounts, a common scenario in organizations with separate operational boundaries between accounts.
The technical core of the problem is that resource policies for Bedrock Knowledge Bases support the cross-account operations Retrieve and GetDocumentContent, but do not support RetrieveAndGenerate, which the solution needs to produce a generated answer. The tool therefore uses AWS Security Token Service to assume a narrowly scoped IAM role in the account where the knowledge base resides, and only then calls RetrieveAndGenerate and returns the generated answer and citations to the orchestration layer.
AWS described two implementation variants with the same security boundary for data access. The first, code-based variant deploys a Strands agent to the AgentCore runtime, where custom Python code controls the agent loop and the tool runs through a local MCP subprocess; here, the execution role of the AgentCore runtime assumes the cross-account role. The second variant uses a declarative AgentCore harness with a managed loop, where the path to the tool runs through AgentCore Gateway and AWS Lambda to the knowledge base, and the Lambda execution role assumes the cross-account role. The choice between the variants depends on how much custom control over orchestration the team needs.
In the sample deployment, AWS used the Claude Haiku 4.5 model for RetrieveAndGenerate calls. The complete deployment procedure, including preparation of a structured knowledge base, cross-account IAM roles, and a Streamlit client for comparing both variants, is published in a public GitHub sample. Details can be found in the source article.
Why it matters
Multi-account AWS architectures, such as separate data and application accounts for governance purposes, have so far struggled to provide agents with access to knowledge bases in other accounts because standard resource policies do not support the RetrieveAndGenerate operation across accounts. The described pattern, which temporarily assumes an IAM role through AWS STS, solves this specific technical problem and gives architects a choice between custom control over orchestration and a managed solution without having to duplicate data between accounts.
Two audiences, two different impacts
What this means
For individuals
Developers and architects working with Amazon Bedrock AgentCore gain a concrete, documented procedure, including a GitHub sample, for connecting agents to a knowledge base in another AWS account using AWS STS and a narrowly scoped IAM role, instead of having to build their own ad hoc solution.
For a business
Companies running AI agents and data stores in separate AWS accounts, which is common in regulated organizations or organizations with multiple departments, can maintain data governance boundaries while allowing agents to generate answers from a knowledge base in another account without having to duplicate the data.
DevelopmentCheck the original
Event sources
only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.