◈ AWS AGENTCORE BLUEPRINTS
PART V · MULTI-AGENT AND ARCHITECTURE · CHAPTER 34 / 36
TOCCONSULTING.FR
AMAZON BEDROCK / PART V, MULTI-AGENT AND ARCHITECTURE

GOVERNANCE AT ORG SCALE

CHAPTER 34 / 36
IN ONE LINE set the rules once, for many teams and accounts
REV 2026.07

When one team builds an agent, governance is easy. When fifty teams build agents in fifty AWS accounts, you need to set rules once and have them apply everywhere, share vetted tools instead of rebuilding, and see and audit it all from one place, without slowing the teams down. That operating model is AWS Organizations plus AgentCore's governance layer.

New to these words? Read chapter 02. Related: Registry (chapter 25), Policy (chapter 23), Observability (chapter 19), Multi-tenant (chapter 32).
[ 1 ] WHY YOU NEED IT

Left alone, teams build overlapping agents and tools in separate accounts, with inconsistent security and no shared view. The fix is a central operating model: guardrails that apply to every account, a shared catalog of approved tools and agents, central rules on what agents may do, and one place to audit cost and behavior, while each team keeps its own account to move fast.

CENTRAL TEAM OWNS
The guardrails, the shared catalog, the audit and cost view.
EACH TEAM OWNS
Its own account and agents, within the guardrails.
[ 2 ] THE ACCOUNT LAYOUT
AWS ORGANIZATION (one company, organized into OUs)
MANAGEMENT

The org root. SCPs and billing.

SECURITY / AUDIT

Org CloudTrail, security tooling.

LOG ARCHIVE

Central, locked-down logs.

MONITORING

Central CloudWatch, one pane of glass.

SHARED SERVICES

The central Registry and Gateway.

WORKLOAD ACCOUNTS (many)   Each team runs its own agents on AgentCore Runtime here, with its own data, inside the org's guardrails. New accounts are onboarded automatically.
[ 3 ] FOUR LEVERS OF CENTRAL CONTROL
GUARDRAILS
SET IT EVERYWHERE

SCPs decide which models accounts may use; Amazon Bedrock Organizations policies enforce Bedrock Guardrails across all accounts.

CATALOG
SHARE, DO NOT REBUILD

One org-wide Agent Registry (preview): teams publish agents, tools, and MCP servers; a curator approves; everyone discovers and reuses.

POLICY
LIMIT WHAT AGENTS DO

Cedar policies at the Gateway allow or deny each tool call; deploy the same policies to every account (IaC).

ACCESS
WHO MAY INVOKE

AgentCore resource-based policies give central, resource-level control over who can call a Runtime or endpoint, and under what conditions.

[ 4 ] ONE PANE OF GLASS, ACROSS ALL ACCOUNTS

A central monitoring account uses CloudWatch cross-account observability to pull traces, sessions, metrics, and logs from every workload account, so you watch all agents in one console (linked org-wide through AWS Organizations). Pair it with an organization CloudTrail for a complete audit trail and cost-allocation tags per team and tenant, so spend and behavior are visible and attributable across the whole estate.

Plain definitions: chapter 02. Hands-on cross-account setup: chapter 35. Registry: chapter 25. Policy: chapter 23.
SRC: AWS Organizations docs, AgentCore (cross-account observability, resource-based policies, Registry), AWS Security Blog + awslabs samples. Guidance. DRAWN 2026.06, REV 2026.07.26
◄ PREVIOUS · CH 33
Agent Security and Threat Model, Plain Language
NEXT · CH 35 ►
Governance at Org Scale, Practical
AWS AGENTCORE BLUEPRINTS · CONTENTS
Back to tocconsulting.fr Cover & Table of Contents
PART I · FOUNDATIONS
01AgentCore Overview, Plain LanguageCONCEPT02AgentCore, Key Terms in Plain LanguageCONCEPT03AgentCore, Common Mistakes ExplainedCONCEPT04Inside an AgentCore Agent, BlueprintCONCEPT05Harness, Practical 1, Strands PathPRACTICAL06Harness, Practical 2, Managed HarnessPRACTICAL
PART II · CORE SERVICES
07AgentCore Runtime, Plain LanguageCONCEPT08AgentCore Runtime, PracticalPRACTICAL09AgentCore Memory, Plain LanguageCONCEPT10AgentCore Memory, PracticalPRACTICAL11AgentCore Gateway, Plain LanguageCONCEPT12AgentCore Gateway, PracticalPRACTICAL13AgentCore Identity, Plain LanguageCONCEPT14AgentCore Identity, PracticalPRACTICAL
PART III · TOOLS AND OPERATIONS
15AgentCore Code Interpreter, Plain LanguageCONCEPT16AgentCore Code Interpreter, PracticalPRACTICAL17AgentCore Browser, Plain LanguageCONCEPT18AgentCore Browser, PracticalPRACTICAL19AgentCore Observability, Plain LanguageCONCEPT20AgentCore Observability, PracticalPRACTICAL21AgentCore Evaluations, Plain LanguageCONCEPT22AgentCore Evaluations, PracticalPRACTICAL
PART IV · GOVERNANCE AND TRANSACTIONS
23AgentCore Policy, Plain LanguageCONCEPT24AgentCore Policy, PracticalPRACTICAL25AgentCore Registry, Plain LanguageCONCEPT26AgentCore Registry, PracticalPRACTICAL27AgentCore Payments, Plain LanguageCONCEPT28AgentCore Payments, PracticalPRACTICAL
PART V · MULTI-AGENT AND ARCHITECTURE
29A2A and Multi-Agent, Plain LanguageCONCEPT30A2A and Multi-Agent, PracticalPRACTICAL31Architecture Patterns, Plain LanguageCONCEPT32Multi-Tenant Agents, Plain LanguageCONCEPT33Agent Security and Threat Model, Plain LanguageCONCEPT34Governance at Org Scale, Plain LanguageCONCEPT35Governance at Org Scale, PracticalPRACTICAL36Multi-Region and Distribution, Plain LanguageCONCEPT