AWS Partner Network (APN) Blog
SailPoint Agent Identity Security for AI agents on Amazon Bedrock AgentCore
By: Kirby Fitch, Lead Product Manager – SailPoint
By: Michael Conti, Product Marketing Manager – SailPoint
By: Imaan Tariq, Customer Solutions Manager – AWS
By: Nabil Ezzarhouni, Specialist Solutions Architect, GenAI – AWS
![]() |
| SailPoint |
![]() |
If you’re deploying AI agents across your organization, you’ve likely hit a familiar wall: How do you govern autonomous systems that can access sensitive data, dynamically request permissions, and take actions without direct human oversight?
Recent research shows that 80% of organizations report AI agents performing unintended actions, and 96% of technology professionals identify security concerns about AI agents (SailPoint, AI Agents: The New Attack Surface, 2025). Traditional identity and access management approaches, which were designed for human users and service accounts, fall short when applied to AI agents that interact with multiple systems and operate autonomously.
In this post, we explore how SailPoint’s Agent Identity Security (AIS) solution, built on Amazon Web Services (AWS), addresses these challenges through centralized identity governance for AI agents, and how your organization can get started securing your AI agents.
AIS in action
SailPoint’s AIS extends proven identity principles to autonomous AI. With AIS, you can gain centralized visibility and help maintain control over AI agents in your environment regardless of where they’re deployed on AWS.
The solution addresses the core challenges security teams face today: AI agents operating without oversight, over-permissioned agents with excessive access rights, and the lack of clear ownership and accountability for agent actions.
With AIS, you can automatically discover AI agents across your cloud environments, assign clear ownership to each agent, conduct regular access reviews and permission revocation, and gain visibility into both direct and indirect access pathways. This means you can apply the same governance rigor to AI agents that you’ve long applied to human identities so that every agent has the right level of access, your team regularly reviews it, and you can quickly revoke an agent’s access if needed.
The innovative solution
SailPoint’s journey to AIS began with a realization that AI agents represent a fundamentally new type of identity, one that requires purpose-built identity governance and security capabilities. Working closely with AWS since early 2025, SailPoint developed AIS as a cloud-based solution that integrates deeply with Amazon Bedrock AgentCore, the AWS agentic solution for hosting, connecting, and managing AI agents at scale.
This collaboration reflects a shared vision: making AI adoption more secure and scalable for enterprises. While AWS provides the infrastructure and tools for building powerful AI agents through Amazon Bedrock AgentCore, SailPoint assures those agents operate within proper governance guardrails. With this solution, organizations can confidently deploy AI agents knowing they have the same level of identity security and compliance they expect from their human workforce.
A collaborative story
The collaboration between SailPoint and AWS meant AIS could integrate directly with Amazon Bedrock AgentCore Identity, giving customers a unified way to discover and govern AI agents across their AWS environment. AWS experts worked alongside SailPoint’s product and engineering teams to design an architecture that scales to support the rapid growth of AI agents that enterprises are experiencing today.
AWS experts continue to work alongside SailPoint’s product and engineering teams to design an architecture that uses the full power of AWS services while integrating with Amazon Bedrock AgentCore Identity. This co-development approach helped verify that AIS would not only meet current enterprise security requirements but also scale to support the explosive growth of AI agents expected in the coming years.
Powering the solution with AWS services
SailPoint AIS is built on AWS, using a combination of managed services for compute, data, messaging, and identity to deliver a scalable, highly available governance solution for AI agents. The following diagram shows how these services integrate to deliver the AIS solution:
![]() |
Figure #1 – AWS architecture supporting AIS
Technical architecture: Building AIS on AWS
SailPoint AIS demonstrates how to build a reliable, more secure system for managing AI agent identities using AWS services. The architecture uses cloud-based services to deliver real-time identity aggregation, governance, and lifecycle management for AI agents across Amazon Bedrock AgentCore.
Architecture overview
The solution runs entirely within AWS while using an Amazon Virtual Private Cloud (Amazon VPC) for network isolation and security. You access SailPoint Identity Security Cloud (ISC) through an Application Load Balancer, which provides high availability and efficient request distribution across the infrastructure.
Container orchestration with Amazon EKS
At the core of the architecture, Amazon Elastic Kubernetes Service (Amazon EKS) orchestrates containerized microservices, allowing independent scaling of components based on demand. This approach provides the flexibility to handle varying workloads while maintaining operational efficiency.
Within the Amazon EKS clusters, three specialized services work together to deliver comprehensive AI agent identity management:
- Task Management Service handles the orchestration of AI agent identity aggregation workflows. It manages task definitions, executes aggregation jobs, and provides real-time status updates to end users. The service also maintains historical records of previous aggregations for audit trails and compliance reporting.
- Non-Human Identity (NHI) Service serves as the central authority for non-human identities and accounts within the system. This service manages machine account classification, exposes APIs for retrieving defined machine accounts and identities, and handles the full lifecycle of AI agent identities, including creation, updates, and deletion during aggregation processes.
- Connectivity Services bridge SailPoint’s system with AWS identity sources. These services retrieve data from configured SailPoint Connectors and stream it to downstream consumers. For AI agent identity management, the AWS Service Management Connector specifically targets Amazon Bedrock AgentCore, extracting agent metadata and streaming it to the NHI Service for identity management within ISC.
Data layer architecture
The architecture employs purpose-built data stores optimized for specific use cases:
- Amazon ElastiCache for Redis provides low-latency tracking of rapidly changing aggregation status. During active identity aggregation, Redis maintains real-time state information. After an aggregation reaches a terminal state (Complete, Errored, Canceled, or Terminated), the Task Management Service updates the persistent task status record.
- Amazon Relational Database Service (Amazon RDS) for PostgreSQL serves as the durable data store for the NHI Service, maintaining the authoritative record of non-human identities, their attributes, and relationships.
- Amazon Managed Streaming for Apache Kafka (Amazon MSK) supports event-driven communication between services. Amazon MSK streams AI agent data from Connectivity Services to the NHI Service and distributes various event types to ISC microservices for asynchronous processing, such as audit events, workflow triggers, and entity change notifications.
Integration with Amazon Bedrock
The architecture’s integration with Amazon Bedrock represents a key capability in AI agent governance. The AWS Service Management Connector continuously discovers AI agents from Amazon Bedrock AgentCore, extracting critical identity attributes such as agent names, roles, permissions, and associated resources. This data flows through the Connectivity Services into the broader identity governance framework, which means you can apply the same governance policies to AI agents that you use for human and service identities.
Scalability and resilience
The architecture’s cloud-based design delivers both horizontal and vertical scalability. Amazon EKS automatically scales container instances based on workload demands, while Amazon MSK partitions allow parallel processing of identity events. The Application Load Balancer distributes traffic across multiple Availability Zones, providing high availability even during infrastructure failures.
This architecture demonstrates how AWS services can be composed to build enterprise-grade identity governance solutions that extend traditional identity management into the emerging domain of AI agent security.
Unlocking business value and future vision
The business impact of AIS spans multiple teams across your organization. Built on SailPoint’s unified identity control plane, AIS expands governance to AI agents without adding new silos or operational complexity. Identity teams can apply consistent access controls as agents emerge, while AI and automation leaders gain clear guardrails around how agents are created, authenticated, and scaled.
AIS provides a centralized console where security teams can view all discovered AI agents, their ownership, and assigned entitlements in one place:
Figure #2 – A single, unified view of identities gives administrators granular control over non-human identity permissions, cutting through the complexity of modern IT environments
Security teams benefit from deeper visibility into agent activity by enabling faster detection of risky behavior. Compliance teams can demonstrate to auditors that AI agents are governed with the same rigor as human identities.
Organizations can run periodic access certification campaigns for AI agents so permissions remain appropriate and compliant over time.
Figure #3 – The application provides a clear, comprehensive view of compliance where every entitlement has a clear owner and purpose during access certification
Before AIS, organizations faced a binary choice: Slow down AI agent deployment to manually govern each agent, or accept ungoverned risk as agents proliferated across their environment. There was no way to apply identity governance to AI agents at the same scale and rigor as human identities. AIS eliminates that trade-off. Organizations can now run access certification campaigns across their entire AI agent population, enforce least-privilege policies as agents scale, and maintain a complete audit trail of agent permissions—capabilities that were previously only available for human users.
The result is that teams can confidently deploy AI agents at scale without choosing between speed and security. The business impact of AIS spans multiple teams across your organization. Built on SailPoint’s unified identity control plane, AIS expands governance to AI agents without adding new silos or operational complexity. Identity teams can apply consistent access controls as agents emerge, while AI and automation leaders gain clear guardrails around how agents are created, authenticated, and scaled.
Looking ahead, SailPoint and AWS are committed to continued innovation in AI agent governance. As AI capabilities evolve from rudimentary task automation to complex multi-agent systems, the identity security framework must evolve in parallel. On SailPoint’s product roadmap, planned enhancements to AIS intend to address emerging challenges such as agent-to-agent authentication, dynamic permission adjustment based on context, and integration with AI observability applications for sophisticated agent lifecycle management.
The following Identity Graph provides a visual map of an agent’s entitlements and relationships, making it effortless to understand and audit what each agent can access:
Figure #4 – With deep observability, the Identity Graph visualizes how an agent integrates, providing crucial context and insight into its relationships and access
The collaboration between SailPoint and AWS demonstrates how established security principles can be adapted for the AI era. By extending proven identity security capabilities to AI agents and building on AWS cloud infrastructure, you can embrace the transformative potential of AI while maintaining the security and compliance standards your business demands.
Get started today
Ready to bring enterprise-grade identity security to your AI agents?
- Explore SailPoint Agentic AI capabilities and the AWS alliance
- Explore Amazon Bedrock and Amazon Bedrock AgentCore
- Learn more about Agent Identity Security in action
SailPoint Technologies – AWS Partner Spotlight
SailPoint Technologies is an AWS Advanced Technology Partner and AWS Competency Partner that provides identity security solutions. With SailPoint, you can manage and govern identities, access, and entitlements with precision while automating security operations and maintaining compliance across your digital environment.
Contact SailPoint Technologies | Partner Overview | AWS Marketplace






