{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-07T18:02:46.008Z",
  "record_id": "VXI-EXT-AWS-AC-ID-01-v1",
  "record_kind": "external_reference",
  "title": "Amazon Bedrock AgentCore: Workload identity scope",
  "system": "Amazon Bedrock AgentCore",
  "evidence_family": "identity_access",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Does an AgentCore workload identity authorise every action an agent can request?",
  "near_questions": [
    "What does an AgentCore workload identity identify?",
    "When does AgentCore create a workload identity?",
    "Do custom agent deployments need explicit identity setup?",
    "Does an agent identity grant unrestricted credential access?",
    "Can an AWS workload identity prove user consent?",
    "Which policy controls access to an agent credential provider?",
    "Does agent identification establish authority to spend?",
    "Is workload identity separate from an end user’s identity?",
    "What must be checked after creating an agent identity?",
    "Can an authenticated workload perform an unapproved action?",
    "Which deployment created this AgentCore identity?",
    "What should a workload-identity evidence snapshot retain?"
  ],
  "supported_claims": [
    {
      "claim": "AWS documents workload identities for agents, including automatic creation with AgentCore Runtime or Gateway deployments and explicit creation for custom deployments. An identity can participate in access policies; its existence does not establish permission for every action or the end user’s intent.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "blanket tool permission",
    "verified user intent",
    "automatic identity creation for every custom deployment"
  ],
  "public_summary": "AWS documents workload identities for agents, including automatic creation with AgentCore Runtime or Gateway deployments and explicit creation for custom deployments. An identity can participate in access policies; its existence does not establish permission for every action or the end user’s intent.",
  "related_record_ids": [
    "VXI-EXT-AWS-AC-MEM-01-v1",
    "VXI-EXT-AWS-AC-RT-01-v1",
    "VXI-EXT-AWS-AC-RT-02-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "Understanding agent identities in Amazon Bedrock AgentCore",
    "source_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/understanding-agent-identities.html",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-AWS-AC-ID-01-v1",
    "candidate_record_sha256": "98d9d34281e6893d708d575efbc9113508531683c3f68e1aefcfd894b57ca436",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "The delivered snapshot preserves the review date shown. Recheck current primary documentation and deployment context before relying on present applicability; payment does not trigger fresh research."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "AWS documents workload identities for agents, including automatic creation with AgentCore Runtime or Gateway deployments and explicit creation for custom deployments. An identity can participate in access policies; its existence does not establish permission for every action or the end user’s intent.",
    "required_buyer_context": "The deployment type, workload identity, credential-provider policy, intended tool action and user authorisation.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The full published answer and boundaries are free. Paid access saves the selected route and source versions, with an unsigned receipt when purchased. Preview coverage before paying. Fresh research, bespoke assessment and protected evidence are excluded.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "availability_endpoint": "/api/index/capabilities",
    "operational_status": "AUTOMATIC_SERVICE_CAPABILITIES_GATED",
    "checkout_url": "/index-access"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#aws-agentcore-workload-identity",
  "machine_readable_record": "/varexis-index/records/aws-agentcore-workload-identity.json"
}
