Image: d2908q01vomqb2.cloudfront.net · rights & removal
Executive Summary
Facts Only
* A user requests data from a lakehouse using an AI agent.
* The agent runs under its own IAM role, which does not inherently reflect the end-user identity for Lake Formation evaluation.
* Identity is propagated through the system via tokens moving across trust boundaries (AgentCore Runtime, Gateway, Lambda).
* An access token authenticates requests at trust boundaries.
* An identity token travels in a custom header to the AgentCore Runtime and subsequent hops.
* Lambda reads the identity token from client context rather than tool arguments.
* Lambda performs a server-side token exchange using IAM Identity Center TIP mechanics to assume a role with user-scoped credentials.
* Lake Formation evaluates grants against the propagated user identity, not the underlying agent role.
* CloudTrail records the assumed role with an onBehalfOf entry identifying the human user for data access.
Full Take
From the original · AWS Security Blog
AWS Security Blog Identity-aware AI data agents with AWS Lake Formation and Trusted Identity Propagation You’re building a data agent that lets business users ask questions about lakehouse data in natural language. You’ve already built governance policies that control who can access which datasets.Read the full story at aws.amazon.com
Sentinel — Human
This text reads like a highly detailed, expert-written technical guide focused on implementing a complex security and identity pattern within an AWS environment.
