Medium
BedrockAgentCore
Regional
Bedrock AgentCore custom browsers should have session recording enabled
Description
Flags Amazon Bedrock AgentCore custom browsers without session recording to an S3 destination. Recording provides an audit trail of browser-tool activity.
Remediation
Enable session recording on every AgentCore custom browser and point it at an S3 destination to retain an audit trail.
Steps
- Open the Amazon Bedrock AgentCore console and select the browser.
- Choose Edit and enable session recording.
- Set the S3 bucket (and optional prefix) for recording storage.
- Grant the AgentCore service principal write access to the bucket.
- Save the changes.