Skip to content
redactsure
Book a demo

Explore.

Comparison · By Chris Sowa · Published
Last updated

Does Amazon Bedrock AgentCore Decide What the Agent Sees?

AgentCore provides browser and policy infrastructure, while the application determines what observations reach the model. Verify how the implementation filters screenshots or DOM data and what its session recording retains.

An isolated browser connects to a session-recording tray beside a separate dial controlling which observation is forwarded.

AgentCore provides browser and policy infrastructure, while the application determines what observations reach the model. Verify how the implementation filters screenshots or DOM data and what its session recording retains. AWS separates agent hosting, browser sessions, identity, tools and observability into configurable services. That gives developers room to build input controls and choose a model independently. It does not establish a particular workflow's field-level policy. The review needs the configured browser observation, the model request and the retained audit record. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.

Key findings

What does AgentCore include, in AWS's words?

AWS's overview describes modular services, including the following components. Runtime is a secure, serverless runtime with session isolation. Gateway turns APIs, Lambda functions and services into MCP-compatible tools. Identity handles agent identity, access and authentication, compatible with existing identity providers. Memory covers short-term and long-term memory. Browser is a cloud-based browser runtime for agents to interact with web applications. Code Interpreter is an isolated sandbox. Observability provides tracing and monitoring, OpenTelemetry-compatible. Policy provides deterministic control using natural language or the Dogwood policy language. Evaluations rounds out the list.

The model is the customer's choice: Bedrock models, OpenAI, Google, Anthropic, Amazon Nova, Meta Llama or Mistral. The framework is also the customer's choice, with CrewAI, LangGraph, LlamaIndex and Strands Agents named. AgentCore was announced in preview in July 2025.

The list is infrastructure for an agent a customer's developers assemble. Each service answers a question about where, how and with what. None answers the question of what the model should receive from a given screen for a given task.

What does the Browser tool hand the model?

The page. The Browser tool documentation says the model perceives pages through screenshots and the DOM. A screenshot carries every value drawn on the screen; the DOM carries every value in the page's structure. For a claims platform that is the claimant's name, date of birth, SSN and address alongside the loss date and reserve. For an EHR it is the chart. An unfiltered screenshot or DOM observation can expose what the application shows (What Does an AI Agent See When It Takes a Screenshot?).

Sessions are containerized, isolated and ephemeral. They reset after use and terminate at a time-to-live, 15 minutes by default and up to 8 hours. Live View lets a person watch the session in real time and interact with the browser directly, per the AWS Machine Learning Blog. Both are strengths. A fresh machine per session and a person able to watch are two of the controls regulated work needs.

An ephemeral session limits how long the browser holds the page. It does not limit what the model reads while the session is open. The application determines which browser observations it forwards to the model. Session lifetime does not itself minimize that input.

What does Policy govern?

Tools and actions. Policy gives deterministic control of what an agent may do, expressed in natural language or in Dogwood. That is a permission, and permissions are the right way to govern acts. May the agent call this tool, may it submit this form, may it reach this API through Gateway.

A permission answers "may the agent do this?" An exposure answers "what does the agent receive while it works?" Policy can stop the agent from submitting a payment. It cannot remove the vendor's bank account number from the screenshot the model already read. A policy can restrict read tools, but a permitted read still needs a decision about the fields forwarded to the model (Does Least Privilege Cover What the AI Sees?). The distinction is the same one that separates IAM from a render layer. AgentCore's documentation places Policy with IAM, on the action side.

What is in the session recording?

DOM changes, user actions, console logs and network events, written to the customer's Amazon S3 bucket, with replay in the AWS console. CloudTrail logs the API calls and CloudWatch carries the metrics, per the Browser tool documentation.

That is a strong compliance trail, and it is the customer's own. It can also retain sensitive information from the session, depending on what is captured. The DOM capture holds the values in the page; the network capture holds the responses that filled them. An organization that turns on recording for a claims workflow now holds claimant identifiers in S3 alongside the claims platform. Retention is the customer's decision, and so is the access policy on the bucket. An AI Control Record holds the same trail with every screen stored as tokens. The record of what the agent saw is not itself a store of the identifiers (How to Audit AI Agent Activity).

What is shared with RedactSure, and what is not?

Shared: AgentCore runs in the customer's AWS account, with the customer's keys, with any model, and the record is in the customer's hands. That is separation of model and control. The environment deciding what the agent may do is owned by the customer and independent of whichever model performs the work. On that row AgentCore and RedactSure give the same answer, and it is the answer the model vendors' own agent products do not give.

Not shared: what the model receives. AgentCore hands the model the screenshot and the DOM. A governed environment hands it the task's fields with identifiers as tokens. Not shared: a per-task exposure policy confirmed by a named workflow owner before the run. Not shared: a named person approving each consequential action. Policy governs which tools and actions are permitted; it does not put a person's name on each payment or submission. Not shared: an inherited control set. With AgentCore, the customer's developers assemble Runtime, Browser, Policy, Identity, Observability and a recording policy for each workflow. They decide what to do about exposure themselves.

What does a regulated buyer build, and what does it inherit?

With AgentCore the buyer inherits the infrastructure: the account, the keys, the model choice, the isolated session, Live View, the recording to S3. The buyer builds the rest per workflow: the agent, the tool set, the Policy rules, the identity binding and the recording retention. Any control on what the model reads is also the buyer's to build; AWS's documentation does not describe one. The governed pilot reverses the split. The exposure policy, the named approver, the tokenized record and the model choice come with the environment. The workflow owner's job is to confirm the policy and approve the actions.

In healthcare, HIPAA's minimum necessary standard at 45 CFR 164.502(b) applies to what the model reads from the EHR screen. The S3 recording is a copy of PHI that sits under the organization's business associate arrangements under 45 CFR 164.504(e). HHS's cloud guidance holds that a cloud provider storing ePHI is a business associate even when the data is encrypted and the provider lacks the key (Can an AI Agent Work in Epic Without Holding PHI?).

In insurance, the session recording is an examiner-readable record of an AI system's work, with claimant identifiers in the DOM capture. The NAIC Model Bulletin asks insurers to govern the data their AI systems use. The Insurance Data Security Model Law governs how that data is held (Can an AI Agent Work Guidewire Claims Without PII?).

In payments, a PAN on a portal screen lands in the DOM capture and in the recording. Every system that stores, processes or transmits cardholder data is in scope under the PCI SSC scoping guidance. The PCI tokenization guidelines describe the alternative. A token in place of the PAN keeps the systems that hold only the token out of that analysis (Can an AI Agent Handle Cards Without Wider PCI Scope?).

How does AgentCore compare with a governed environment?

Control AgentCore (from documentation) RedactSure governed environment
Environment and account Customer's AWS account; isolated, ephemeral sessions Secure VM on hardware-encrypted enclaves, in the customer's cloud
Keys The customer's Customer-held; RedactSure holds ciphertext it cannot decrypt
Model choice Any: Bedrock, OpenAI, Google, Anthropic, Nova, Llama, Mistral Claude, GPT, Gemini, open-weights, swappable without moving the controls
What the model receives Screenshots or DOM observations selected by the application The task's fields, identifiers as tokens
Who decides what it sees The application; the customer's developers The Planner, per task; a named person confirms
Action gate Policy: deterministic control of tools and actions A named person approves every consequential action
Record Session recording to S3, CloudTrail, CloudWatch Every action logged, human and computer; all PII as tokens
What is assembled vs inherited Assembled per workflow by the customer's developers Inherited with the environment
Injection collects The page Tokens and remaining task context; consequential actions require approval

Where does RedactSure sit?

RedactSure supplies the rows AgentCore leaves to the customer to build. AI co-workers do real work across an organization's applications inside a governed environment, with no per-application integration and no change to user permissions. The environment is a secure virtual machine deployed into the cloud the customer's posture requires, AWS included, on hardware-encrypted enclaves, with keys the customer holds. Every sensitive value chosen by policy is replaced by a consistent token at the render layer before any model reads the screen. The model is handed the task's fields rather than a picture of the page. The Planner sets which values are tokenized and what the agent may do on each screen. A named person confirms that policy and approves every payment, submission and record change under Supervised Delegation. Deployments are in pilot.

What the organization avoids is a model reading whole pages of claimant, patient or cardholder records and a recording in S3 that holds a second copy of them. Every screen as tokens, every action and every approval lands in the AI Control Record and exports to the customer's SIEM. The human operator can watch, pause and take over the same tokenized stream.

Methodology and limitations

The HIPAA minimum necessary standard has exceptions, including certain treatment disclosures. Its application depends on the purpose and parties. Replacing direct identifiers does not by itself establish HIPAA de-identification or remove all PHI from the remaining context.

The page rests on four AWS documents read as of September 30, 2026. They are the AgentCore developer guide, the Browser tool page, the AWS Machine Learning Blog post introducing the Browser tool and the July 2025 preview announcement. AWS's wording is cited with their dates; where it is silent the page says so rather than inferring. Regulation is read from its text: 45 CFR 164.502(b) and 164.504(e), HHS's cloud guidance, the NAIC bulletin map, NAIC Model Law 668 and PCI Council scoping and tokenization guidance. Case law and enforcement actions were not surveyed.

No hands-on testing of AgentCore was performed; what the Browser tool, Policy and session recording do is AWS's own description. AWS's service terms, shared responsibility model, HIPAA eligibility list, business associate addendum and FedRAMP status were not reviewed. Those documents could disclose encryption of the S3 recording, retention, key management or certifications that the developer guide does not. The July 2025 announcement describes a preview; where it differs from the current developer guide, the page relies on the guide. Vendor features change; the page carries its date and is revised when documentation changes. Statements about claim files, patient charts and cardholder data describe the record type, not any organization; no customer or prospect is described.

Whether a deployment meets the minimum necessary standard, needs a business associate agreement or falls within PCI scope is for the organization's counsel or assessor, not this page.

We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.

What the record shows

AgentCore provides browser and policy infrastructure, while the application determines what observations reach the model. Verify how the implementation filters screenshots or DOM data and what its session recording retains. Compare the browser observation with the model request and the stored recording. Add filtering, approval and retention controls where the workflow needs them.

Frequently asked questions

Does AgentCore run in our AWS account?

Yes, per the documentation. The services run in the customer's AWS account, the session recording writes to the customer's S3 bucket, CloudTrail and CloudWatch carry the logs and metrics, and the model is the customer's choice. That places the environment with the customer rather than the model vendor, which is the separation of model and control principle. It is the strongest part of the design, and RedactSure follows the same one.

Does the Browser tool see the whole page?

Yes. AWS says the model perceives pages through screenshots and the DOM. A screenshot carries what is drawn; the DOM carries what is in the page structure. What the model receives is set by what the application renders, not by the task. The application must establish which observations it forwards and any filtering or replacement applied before the model call. That replacement, at the render layer, is what RedactSure adds.

Is the session recording a copy of our records?

It holds the DOM changes, actions, console logs and network events of the session, so sensitive values may be present in the recording, depending on the capture behavior and configuration. For a claims, patient or cardholder workflow that is a second store of identifiers in S3. Retention and access are the customer's to set, and counsel should treat the bucket as holding the same data class as the source application. An AI Control Record holds the same trail as tokens.

Can RedactSure run on AWS with AgentCore underneath?

The governed environment deploys into the cloud the customer's posture requires, and AWS is one of them. Whether the environment composes with specific AgentCore services such as Gateway, Identity or Observability is a separate question. The exposure control, the named approver and the tokenized record come with the environment either way.

Does Policy give us a named approver?

No. Policy gives deterministic control of which tools and actions the agent may use, which is a permission set. A named approver is a person who confirms the exposure policy before the run and approves each payment, submission or record change while it runs, on the record. A customer can build that step in front of an AgentCore agent; the documentation does not supply it. Supervised Delegation supplies it as part of the RedactSure environment.

How long does an AgentCore build take for one workflow?

The documentation does not say. The component list is the answer: Runtime, Browser, Policy, Identity, Observability, a recording policy and the agent itself, assembled and tested per workflow by the customer's developers. Whatever the customer decides to do about exposure is added on top. A governed pilot starts from the environment and asks the workflow owner to confirm a policy and approve actions.

Sources

Vendor documentation

  1. AWS, "What is Amazon Bedrock AgentCore?" https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/what-is-bedrock-agentcore.html
  2. AWS, "Interact with web applications using Amazon Bedrock AgentCore Browser." https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/browser-tool.html
  3. AWS Machine Learning Blog, "Introducing Amazon Bedrock AgentCore Browser tool." https://aws.amazon.com/blogs/machine-learning/introducing-amazon-bedrock-agentcore-browser-tool
  4. AWS, "Amazon Bedrock AgentCore now available in preview" (July 2025). https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-bedrock-agentcore-preview/

Regulation and standards

  1. 45 CFR 164.502(b), HIPAA minimum necessary standard. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
  2. 45 CFR 164.504(e), HIPAA business associate contracts. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
  3. HHS, "Cloud Computing" guidance under HIPAA. https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
  4. NAIC, Model Bulletin on the Use of AI Systems by Insurers, adoption map. https://content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf
  5. NAIC, Insurance Data Security Model Law (#668). https://content.naic.org/sites/default/files/model-law-668.pdf
  6. PCI Security Standards Council, "Guidance for PCI DSS Scoping and Network Segmentation." https://www.pcisecuritystandards.org/documents/Guidance-PCI-DSS-Scoping-and-Segmentation_v1.pdf
  7. PCI Security Standards Council, Tokenization Guidelines Information Supplement. https://www.pcisecuritystandards.org/documents/Tokenization_Guidelines_Info_Supplement.pdf

RedactSure documents

  1. RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
  2. RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
  3. RedactSure, "Secure AI That Crosses Every Silo" (2026). https://redactsure.com/blog/secure-ai-that-crosses-every-silo/
  4. RedactSure Research, "Should the AI Agent's Secure Environment Belong to the Model Vendor?" (2026). https://redactsure.com/research/should-ai-agent-environment-belong-to-model-vendor
  5. RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
  6. RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
  7. RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
  8. RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
  9. Product behavior described on this page reflects RedactSure's current design. Amazon Web Services, Amazon Bedrock and AgentCore are trademarks of Amazon.com, Inc. or its affiliates; named to identify the products. Compliance determinations belong to the organization's counsel.

See it on your workflow.

Bring one billing, collections, claims or patient-account workflow and your questions.

Book a demo

Book a demo

Having trouble? Open the booking page or email us.