Seven modules that build from threat model to a fully governed production agent. Each module maps to one or more of the seven Amazon Bedrock AgentCore security surfaces.
One live environment that grows with the course. Sign in as a real Amazon Cognito user, chat with a real agent on Amazon Bedrock AgentCore Runtime, then flip a control off and on and watch the same attack leak data or get denied. Every verdict in the Security Trace panel comes from a real AWS authorization decision, not a simulation.
Designing agent platforms that must pass security and compliance review before production.
Owning the guardrails, IAM policies, SCPs, and audit posture for agentic workloads.
Building and deploying agents on Amazon Bedrock AgentCore who need secure-by-default patterns.
Know exactly where AWS's responsibility ends and yours begins — including session-to-user binding.
Use Token Vault and the 8 Amazon Bedrock AgentCore IAM condition keys to enforce least privilege per user and session.
Control agent-to-tool access at the Gateway with deterministic, auditable authorization.
Enforce CMK encryption, namespace isolation, and memory-poisoning mitigations.
Trace reasoning end-to-end and validate posture with Security Hub controls.
Layer all seven controls into a production-ready agent deployment.
Seven interactive explainers, one per module. Click any module to open its explainer page.
The live lab the modules build toward — real Cognito, real Amazon Bedrock AgentCore Runtime, real IAM verdicts.
Every Amazon Bedrock AgentCore deployment has these seven surfaces. The course covers each one, grounded in official AWS documentation and AWS blog posts.
Token Vault, OAuth 2.0, SigV4, API keys, IAM condition keys. M2
CMK encryption, namespace isolation, poisoning mitigation. M5
Deterministic, auditable authorization; default-deny. M4
MicroVM per session; control/data plane separation. M3
VPC mode, private connectivity, org-level guardrails. M3
OTEL tracing, CloudTrail, Security Hub controls. M6
Central policy choke point; MCP mediation; interceptors. M4
This course is grounded in official, publicly available AWS documentation and blog posts. Every source is linked below, and each module page cites the specific sources behind its claims.