Quick summary

  • An AI agent that accesses enterprise data should not act only through a shared service identity. AWS describes propagating user authorization context so an agent returns data according to the requester’s permissions.
  • If an agent does not know who is asking, it may disclose data that the requester is not allowed to see.
  • Trial one internal-data agent with two user roles and verify that authorization context changes the result.

What happened

AI agents can query DynamoDB, document repositories, SaaS platforms, and internal knowledge bases. The central security question is not merely whether the agent is authenticated; it is whether the agent preserves the requesting user’s permissions.

AWS highlights this risk in its Bedrock AgentCore authorization-context guidance: an agent unaware of the caller can return data the user should not see.

A service identity is not a substitute for user permissions

An agent may need a technical identity to invoke a tool. If every request instead runs with the agent’s broad permissions, user-level authorization can disappear from the data path.

Authorization context traveling with a request through an agent, tool, and data store.
Authorization context traveling with a request through an agent, tool, and data store.

A stronger design carries identity and authorization context through retrieval, then lets the data system or tool enforce the resulting decision.

What should teams establish before deployment?

  • Whom does the agent represent for every data-source call?
  • Where is permission enforced: the agent, gateway, tool, or data store?
  • Can logs show the requester, tool invocation, and denied result?
  • Does the agent fail safely when context cannot be propagated?

Trial this with clearly bounded data

A useful pilot includes internally open data and group-restricted data. Ask the same question as two users with different entitlements; the answer should differ when policy requires it.

Do not evaluate only answer quality. Test whether the agent withholds restricted content, metadata, and paths as well.

In 5 Minutes

  • Agents need caller context, not just service credentials.
  • Authorization must survive tool and data calls.
  • Logs should connect actor, tool, and policy decision.
  • Test entitlement differences against controlled real data.

Sources

Why developers should care

If an agent does not know who is asking, it may disclose data that the requester is not allowed to see.

  1. 1Trial one internal-data agent with two user roles and verify that authorization context changes the result.