This integration connects AI Control Tower’s AI Discovery capabilities with Amazon Bedrock, Amazon Bedrock Agentcore, Amazon Sagemaker, enabling automated discovery and governance of AI assets across enterprise Amazon environment
- Integration with Amazon which would allow discovery and inventory of Workflows with AI Agents, related models, prompts, and tool information across Amazon Bedrock, Amazon Bedrock Agentcore, Amazon Sagemaker.
- The AI Control Tower (AICT) imports the discovered artifacts into its AI inventory, where the AI steward and Product Owner can access and review them.
New
- Admins can now configure all AWS AI discovery services using a single credential page. The playbook presents one unified configuration page for Bedrock, SageMaker, and AgentCore, creating a single connection alias reused across all services. Discovery runs successfully for all services using the shared connection, and existing separate configurations remain supported. A new connection alias and template are created, acting as the parent for all connection aliases.
- Admins can enable automatic rotation of AWS access keys for AI SGC connections. When enabled, a scheduled job periodically rotates IAM access keys for Bedrock, SageMaker, AgentCore, and CloudWatch connections, updating credentials and tracking rotation status per connection.
- Admins can discover multiple explicit AWS accounts by specifying a comma-separated list of account IDs. The connection property now supports multiple account IDs, allowing discovery across all listed accounts without using Organizations ListAccounts. Each account is discovered individually, and accounts missing the required role are skipped and logged.
Changed
- The playbook connection form UI has been improved. Field hints and activity descriptions are updated for clarity, and service names are revised for consistency. The scheduled imports page now covers all connections.
- The connection property for standalone AWS account discovery has been renamed. The property is now called "Target Account IDs" and supports comma-separated values. Existing connections using the legacy property remain compatible and display the value in the updated form.
- The script execution step is moved to setup instructions KB in Review step of playbook. The script download is available through the setup instructions KB in prerequisites section and its execution process.
Discovery is for all customers including AI Native SKU.
Packaging Structure: Customers can install the AI Control Tower SKU, which auto-installs the Marker plugin for Service Graph Connector(sn_ai_sgc_disc) which in turn will Install Amazon SGC app
Installing Amazon SGC will Install SGC Central and AI Discovery.
Users will see the AI Connections tab in AICT only if the plugins com.sn_ai_disc and sn_sgc_central are installed.
AI Discovery plugin has below direct dependencies-
com.glide.hub.action_type.datastream
com.sn_ai_governance is this fine