Skip to main content

How it works

The Bedrock connector:
  • Discovers all Bedrock agents via boto3.list_agents()
  • Streams invocations by reading InvokeAgent events from CloudTrail
Elitery deploys and manages the connector inside your AWS environment or customer cluster.

What Elitery needs from you

IAM permissions — Elitery requires a read-only IAM role with:
CloudTrail setup — ensure CloudTrail is logging to CloudWatch Logs with Bedrock API calls enabled. Provide Elitery with:
For Kubernetes deployments, Elitery uses IAM Roles for Service Accounts (IRSA) — no AWS keys are stored directly.

What your developers do

Nothing. Bedrock agents are fully managed — no code changes required. For precise checks on critical Bedrock agents, add the SDK or a plain HTTP quality signal after invoking the agent: