Skip to content

Connect Amazon Bedrock to Black Cat SSPM

Version française

Connect your Amazon Bedrock account so Black Cat can review the AI agents you have built, their execution roles, action groups, knowledge bases and guardrails.

≈ 10 min · audit access · no write-capable permission

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
sts:GetCallerIdentityLets Black Cat confirm which AWS account it has been given access to.Required
bedrock:ListAgents, bedrock:GetAgent, bedrock:ListTagsForResourceLets Black Cat inventory your Bedrock agents, their status, owners and configuration.Required
bedrock:ListAgentActionGroups, bedrock:GetAgentActionGroupLets Black Cat see what actions each agent can take, including code interpretation and shell access.Required
bedrock:ListAgentKnowledgeBasesLets Black Cat see which knowledge bases each agent can draw on.Required
iam:ListRolePolicies, iam:GetRolePolicy, iam:ListAttachedRolePolicies, iam:GetPolicy, iam:GetPolicyVersionLets Black Cat review the permissions an agent's execution role carries.Required
cloudtrail:LookupEventsLets Black Cat see when each agent was last invoked.Optional

What you'll need

  • Access key identifier Required — From the read-only credentials you create for Black Cat in AWS.
  • Secret access key Required — Issued with the access key identifier and shown only once by AWS.
  • Bedrock region Required — The AWS region your Bedrock agents live in, for example eu-central-1.
  • Role to assume — Optional — the read-only role Black Cat should take on instead of using the access key directly.

Where to create it

What we check on Amazon Bedrock →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan