---
格式版本: 2
标题: "Amazon Bedrock AgentCore Memory now supports fine-grained access control"
原文链接: "https://aws.amazon.com/cn/about-aws/whats-new/2026/08/agentcorememory-fine-grained-access-control/"
发布日期: "2026-08-28"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "llm:local:original_script_field"
发布时间证据: "postDateTime: 2026-08-28T20:00:00Z"
发布时间校准原因: "该候选来自原始脚本字段的postDateTime，明确标注为文章发布时间，且与标题区域发布时间一致。"
发布时间校准置信度: "1"
发布时间候选数量: 1
发布时间严格候选数量: 0
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-31T02:04:31+08:00"
发布时间仲裁状态: "confirmed"
发布时间仲裁尝试次数: 1
发布时间仲裁耗时毫秒: 2744
发现时间: "2026-08-31T02:04:15+08:00"
入库时间: "2026-08-30T18:04:34.115Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://aws.amazon.com/new"
匹配关键词:
  []
相关厂家:
  - "AWS"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 42
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "正文主线是AWS为AgentCore Memory新增细粒度访问控制，涉及OAuth/JWT、Cedar策略、租户隔离及12项Memory操作，属于官方发布且事实完整。固定知识库未发现该功能的历史重复，但未命中不能证明首次出现。新增事实仅为智能体应用层的托管授权能力，没有机架级硬件、互连、供电、液冷、RAS、规模部署或商业交付信号；命中应用导向且非机架级基础设施的强否决，不能进入超节点情报库。"
AI质检模型: "gpt-5.6-sol"
AI质检时间: "2026-08-31T02:05:08+08:00"
AI主题相关性: 1
AI来源权威性: 15
AI新颖性: 11
AI技术细节: 5
AI商业部署信号: 1
AI完整性: 9
AI评分提示词版本: "v17-精简生产版"
AI评分提示词SHA256: "48fb9777f386026761b4873eaff30807694fb11e9b352d7c69bf2dfde750cc7d"
AI评分知识库版本: "knowledge_base_v1-20260819+runtime.55"
AI评分知识库SHA256: "ca56afec1ff616b1fa4394cd1d08b1e2a6af47eccbe70c802c9f1fea6037e803"
AI评分知识库检索词: "[\"AWS\",\"https://aws.amazon.com/new\",\"RAS\",\"FGAC\",\"OAuth\",\"JWT\"]"
AI评分知识库命中: "[{\"id\":\"runtime-9f43a79e9c23b1f329d8a71a\",\"title\":\"AWS and NVIDIA to Deliver 2 Million Additional GPUs and Next-Generation Infrastructure for Agentic and Physical AI\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-26\",\"matchedTerms\":[\"AWS\",\"RAS\"],\"rank\":-6.718534189832346},{\"id\":\"runtime-b86df24f43e82ced83868dce\",\"title\":\"AWS, Anthropic Complete Project Rainier AI Cluster\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-17\",\"matchedTerms\":[\"AWS\",\"RAS\"],\"rank\":-6.1364352429386155},{\"id\":\"runtime-0eb5e80d3c503014391649da\",\"title\":\"122亿美元！Marvell拿下谷歌AI芯片大单\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-20\",\"matchedTerms\":[\"AWS\"],\"rank\":-6.016116415561409},{\"id\":\"runtime-52343a012216677e078ffdd2\",\"title\":\"NVIDIA NVLink Fusion Expands With NVHBM Custom High-Bandwidth Memory\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-26\",\"matchedTerms\":[\"AWS\",\"RAS\"],\"rank\":-5.833498871408439},{\"id\":\"runtime-15c79e6868a9b43f99c061a9\",\"title\":\"Nvidia’s AI Boom Tests Data Center Infrastructure Limits\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-27\",\"matchedTerms\":[\"AWS\",\"RAS\"],\"rank\":-5.71550546138341}]"
AI摘要: "Amazon Bedrock AgentCore Memory新增细粒度访问控制（FGAC），通过AgentCore Gateway结合OAuth（JWT）认证和Cedar策略，实现按用户和租户的内存隔离，无需构建自定义授权逻辑；"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-08-30T18:08:08.965Z"
采集批次: "2026年8月31日2点04分09秒"
采集批次ID: "20260831-020409-922"
去重键: "https://aws.amazon.com/cn/about-aws/whats-new/2026/08/agentcorememory-fine-grained-access-control"
---

Amazon Bedrock AgentCore Memory now supports fine-grained access control (FGAC), enabling you to enforce per-user and per-tenant memory isolation through AgentCore Gateway without building custom authorization logic.

With FGAC, you can front your Memory resource with an AgentCore Gateway configured for OAuth (JWT) authentication and attach Cedar policies that restrict access based on the authenticated caller's identity. You can enforce that each user only accesses their own actor's data, restrict memory records to namespaces derived from the user's token claims, and allow or deny specific Memory operations per caller. This lets you move access control enforcement from application code to the infrastructure layer using cryptographic proof of identity. FGAC for Memory is built on the AgentCore Memory connector, a managed gateway connector that wires a gateway target to the Memory data plane and exposes 12 Memory operations as Cedar actions with their request attributes available for policy conditions.

To get started, see [Fine-grained access control for Memory](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-gateway-fgac.html) in the Amazon Bedrock AgentCore Developer Guide.
