AI inventory

Amazon Bedrock

Amazon Web Services · Cloud AI platform · Confirmed · catalog aws-bedrock. Seen by 1 lane through 1 finding.

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Combined score
90
Critical one lane
People
6
Distinct identities across every lane
Seen by
1
AWS
First seen
Aug 24, 2026
Last seen 13 h ago
awsaccount:123456789012root-useddenied-attemptsbuildersinvocationscustom-modelsagentsinvocations-unlogged
Evidence

Where it was seen

Strongest finding →
AWSaccount 123456789012
Critical90

47 CloudTrail events by 6 identities, 4 denied, 3 resources in account 123456789012

CloudTrail events
47
Identities
6
Denied
4
Root used
yes
6 people · 13 h agoOpen finding →
Next steps

Recommended actions

  1. 01
    The root user of account 123456789012 called Amazon Bedrock APIs. Root should never do day-to-day work: move this to an IAM role, enable MFA on root, and alert on any further root activity.
    AWS
  2. 02
    Bedrock model invocation logging is off in account 123456789012, so prompts and completions leave no record. Turn it on (CloudWatch Logs or S3) before this becomes the default way people reach models.
    AWS
  3. 03
    4 calls were denied by IAM. People are trying to reach Amazon Bedrock; decide whether to grant it through a reviewed role or block it with a service control policy so the attempts stop.
    AWS
  4. 04
    Custom or fine-tuned models exist. Confirm what data trained them, that the training bucket is classified, and that the models are not shared across accounts.
    AWS
  5. 05
    Agents or knowledge bases are configured. Review which S3 buckets, databases, and APIs they can reach; a knowledge base is a permanent grant of that data to whoever can query the agent.
    AWS
Who

People

PersonDepartmentSourcesSeen bySign-ins · 30 d
[email protected] via Developers
n/a
AWS identity
AWS0
dave
dave
n/a
AWS identity
AWS0
frank
frank
n/a
AWS identity
AWS0
[email protected] via PlatformEngineer
n/a
AWS identity
AWS0
[email protected] via Developers
n/a
AWS identity
AWS0
root
root
n/a
AWS identity
AWS0
Vendor

Policy notes

Trains on data
No
Enterprise tier
Available
Org policy
None set

Managed foundation models inside the customer's AWS account; risk is who can invoke, whether invocations are logged, and what agents and knowledge bases can reach.

Billing

What it costs

Last 30 days
$2,182
Previous 30
$1,690
Lanes

Score by source

Each lane scores its own evidence. The combined score takes the strongest lane and adds five points per additional lane, capped at 100.