Bedrock AgentCore Connects to Cross-Account Knowledge Bases

Kunal Ghosh· August 26, 2026 View original

Key takeaways

  • Bedrock AgentCore now supports cross-account knowledge base access.
  • Data duplication is avoided, improving security and governance.
  • Integration supports services like Amazon Redshift Serverless.
  • Two orchestration models (Strands agent, AgentCore harness) are available.

Who benefits

BFSIHealthcareGovernmentEnterprise ITLegal

Summary

Amazon Bedrock AgentCore agents can now access knowledge bases, such as those backed by Amazon Redshift Serverless, located in different AWS accounts without data duplication. The post details the architecture, security, and two orchestration models for this cross-account integration.

Amazon Bedrock has introduced a new capability allowing its AgentCore agents to securely connect with knowledge bases residing in separate AWS accounts. This means that an AI agent operating in one account can retrieve information and generate responses from a knowledge base, potentially backed by services like Amazon Redshift Serverless, located in another account, all without the need to copy or duplicate the source data. The article outlines the technical architecture that enables this cross-account functionality, emphasizing the security boundaries and access controls required for such an setup. It also presents two distinct orchestration models for implementing this integration: one involves a code-based Strands agent, offering programmatic control, while the other utilizes a declarative AgentCore harness, providing a more configuration-driven approach.

Why it matters

This feature enhances data governance and security for enterprises by allowing AI agents to access sensitive information across organizational boundaries without data replication, simplifying compliance and reducing operational overhead.

How to implement this in your domain

  1. 1Configure IAM roles and policies to establish secure cross-account access for Bedrock AgentCore.
  2. 2Design the architecture for connecting your AgentCore agents to a knowledge base in a separate AWS account.
  3. 3Choose between a code-based Strands agent or a declarative AgentCore harness for orchestration based on project needs.
  4. 4Test the end-to-end flow to ensure agents can accurately retrieve and utilize information from the cross-account knowledge base.
  5. 5Document the security and access configurations for auditing and compliance.

Original post by Kunal Ghosh

"Learn how Amazon Bedrock AgentCore agents in one account can generate answers from an Amazon Bedrock knowledge base backed by Amazon Redshift Serverless in another account, without copying source data. This post covers the architecture, security boundary, and two orchestration mo…"

View on X

Originally posted by Kunal Ghosh on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses