Skip to content

Image: d2908q01vomqb2.cloudfront.net · rights & removal

Executive Summary

The identity-aware AI data agent pattern allows for the enforcement of existing Lake Formation governance policies on AI queries by propagating per-user identity through the system without modifying application code or Layer 4 access controls. The process involves two tokens: an access token for authentication and an identity token, which are propagated across boundaries in a controlled manner that bypasses direct exposure to the foundation model. Identity is securely handled server-side within a Lambda function where it is exchanged for specific Lake Formation credentials needed for querying data via Athena. This delegation ensures that Lake Formation evaluates the real user's grants against the query, and CloudTrail records the actual human identity behind the data access.

Facts Only

* A user requests data from a lakehouse using an AI agent.
* The agent runs under its own IAM role, which does not inherently reflect the end-user identity for Lake Formation evaluation.
* Identity is propagated through the system via tokens moving across trust boundaries (AgentCore Runtime, Gateway, Lambda).
* An access token authenticates requests at trust boundaries.
* An identity token travels in a custom header to the AgentCore Runtime and subsequent hops.
* Lambda reads the identity token from client context rather than tool arguments.
* Lambda performs a server-side token exchange using IAM Identity Center TIP mechanics to assume a role with user-scoped credentials.
* Lake Formation evaluates grants against the propagated user identity, not the underlying agent role.
* CloudTrail records the assumed role with an onBehalfOf entry identifying the human user for data access.

Full Take

The design introduces a sophisticated separation of concerns where control over data access is decoupled from the execution environment of the AI agent. The pattern demonstrates that identity can be treated as a context object, flowing across architectural layers (HTTP transport) without becoming part of the reasoning engine (Foundation Model). This challenges the default assumption that any component processing an agent's request must necessarily have direct knowledge of the end-user's identity, pushing authorization responsibility to a specialized layer—Lake Formation. The core tension lies between maintaining the agility of AI agent execution and preserving granular security governance. If the system relies on complex token exchange within ephemeral functions like Lambda to map session context to data access, it suggests that operational security often requires introducing explicit, verifiable delegation steps rather than relying solely on inherited role permissions. This forces an inquiry into where the necessary trust boundaries are most effectively drawn when abstract reasoning layers are introduced between the end-user and the data store. What happens when the identity propagation mechanism itself becomes a single point of failure for authorization?

From the original · AWS Security Blog

AWS Security Blog Identity-aware AI data agents with AWS Lake Formation and Trusted Identity Propagation You’re building a data agent that lets business users ask questions about lakehouse data in natural language. You’ve already built governance policies that control who can access which datasets.
Read the full story at aws.amazon.com

Sentinel — Human

Confidence

This text reads like a highly detailed, expert-written technical guide focused on implementing a complex security and identity pattern within an AWS environment.

Signals Detected
low severity: Moderate sentence length variance; clear, technical expository rhythm.
low severity: High coherence. The argument flows logically from problem to specific solution and technical implementation.
low severity: Structured presentation of steps, prerequisites, configuration points, and the end-to-end flow strongly suggests a deliberate instructional writing style.
low severity: Specific references to AWS services (Lake Formation, IAM Identity Center, Bedrock AgentCore) and precise technical architecture points suggest domain expertise and real-world implementation knowledge.
Human Indicators
Use of complex, nested technical concepts that require deep contextual understanding (e.g., TIP role, token exchange flow).
The structure is geared toward teaching a specific, non-trivial architectural pattern, characteristic of high-level technical blogging.
Inclusion of specific, actionable configuration steps and caveats regarding the limitations (e.g., FM not seeing the token) indicate lived experience with the system being described.
Identity-aware AI data agents with AWS Lake Formation and Trusted Identity Propagation | Huntaegis