Skip to content
context AI agents

A guide by Amazon Web Services on a multi-account AI agent architecture with AgentCore Gateway and MCP

only one source so far

AWS published a technical guide on an architecture where an AI agent accesses data scattered across many AWS accounts through a unified AgentCore Gateway and the MCP protocol, without centralizing the data.

AWS published a guide on its blog on how to build an AI agent capable of working with data scattered across many AWS accounts, without that data having to be copied or centralized. The goal is for each line-of-business (LOB) team to retain ownership and isolation of its data within its own account, while still allowing the agent to query across all accounts through a single interface.

The architecture has three layers: a central platform account, where the agent and large language model inference run via Amazon Bedrock; distributed LOB accounts, where individual teams package their data and tools into MCP servers; and Amazon Bedrock AgentCore Gateway as an integration layer that aggregates MCP servers behind a single endpoint. According to AWS, this hub-and-spoke model gives the agent unified search and tool invocation, while data physically remains in its original account and only the specific query result travels outward.

The guide further describes cross-account MCP integration, authentication via AgentCore Identity and Okta (OAuth 2.0 M2M credentials verified through Okta OIDC), fine-grained authorization using the Policy tool in AgentCore (Cedar), and governance elements such as Amazon Bedrock Guardrails and centralized cost tracking through a single billing boundary. Both agents and MCP servers run on AgentCore Runtime — a serverless, framework-independent environment with session isolation in dedicated micro-VMs and pay-as-you-go pricing. For new implementations, according to AWS, Amazon Bedrock Managed Knowledge Base can be connected directly to the Gateway as a native connector, without needing to operate your own retrieval infrastructure.

The rest of the description of the individual implementation steps was not available in the source.

What changed

Why it matters

The guide addresses a specific problem for enterprise AI agents — how to give an agent access to data from many separate AWS accounts without having to deal with cross-account IAM permissions or copying data between accounts. For companies operating multiple business units with their own AWS accounts, this is a ready-made architectural pattern that combines governance (guardrails, authorization, billing) with decentralized data ownership at the level of individual teams.

Two audiences, two different impacts

What this means

01

For individuals

For architects and developers working with AWS, this is a concrete reference pattern for connecting an AI agent to cross-account MCP servers using AgentCore Gateway, Identity, and Okta.

What to do Study the guide as a reference architecture for implementing cross-account MCP integration in AWS.
More practical updates →
02

For a business

According to this guide, companies with data split across multiple AWS accounts can deploy an AI agent with centralized management of access, authorization, and costs, without having to copy or centralize data from individual accounts.

Development
What to decide Evaluate whether the platform account / LOB accounts / AgentCore Gateway pattern matches the existing division of AWS accounts and data governance within the company.
More business impacts →
AgentCore Gateway AI agents Amazon Bedrock AWS Model Context Protocol Multi-account architektura

Check the original

Event sources

only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
AWS Machine Learning Blog primary source · first detected Build a multi-account AI agent with AgentCore Gateway and MCP