AWS Architecture Blog

Rennay Dorasamy

Author: Rennay Dorasamy

Rennay Dorasamy is a Senior Cloud Application Architect at AWS Professional Services based in South Africa. With 25+ years of enterprise software engineering experience spanning financial services and telecommunications, he specializes in generative AI and agentic AI application architecture. Rennay is a hands-on builder of multi-agent systems on Amazon Bedrock and AgentCore, a published author (Apress), and holds several AWS certifications. He helps customers design and deliver production-grade AI solutions on AWS.

Secure multi-tenant RAG with Amazon Bedrock and Verified Permissions

This post walks you through a two-layer, defense-in-depth authorization pattern for granular, intra-tenant access control in RAG applications. Defense in depth is a security strategy that uses multiple independent layers of protection. Each layer operates independently. If one layer is misconfigured, the other layer still enforces access control. The pattern runs on Amazon Bedrock, a fully managed service that offers a choice of high-performing foundation models (FMs) from Amazon and AI companies through a single API, along with a broad set of capabilities you need to build generative AI applications with security, privacy, and responsible AI.