Medium BedrockAgentCore Regional

Bedrock AgentCore custom browsers should have session recording enabled

Description

Flags Amazon Bedrock AgentCore custom browsers without session recording to an S3 destination. Recording provides an audit trail of browser-tool activity.


Remediation

Enable session recording on every AgentCore custom browser and point it at an S3 destination to retain an audit trail.

Steps

  1. Open the Amazon Bedrock AgentCore console and select the browser.
  2. Choose Edit and enable session recording.
  3. Set the S3 bucket (and optional prefix) for recording storage.
  4. Grant the AgentCore service principal write access to the bucket.
  5. Save the changes.