Amazon Bedrock Guardrails Supports Centrally Controlled Cross-Account Safeguards
Key point
Bedrock Guardrails centrally applies the same safeguards across an organization's accounts.
Details
Amazon Bedrock Guardrails has made cross-account safeguards generally available (GA). Now, by defining a single guardrail in an organization's management account, the same safety policy can be consistently enforced across member accounts and OUs in AWS Organizations.
There are two application methods: account-level and organization-level.
- Organization-level enforcement: By attaching a guardrail via a Bedrock policy in AWS Organizations, it is automatically applied to all Bedrock inference calls across the root, OUs, and individual accounts.
- Account-level enforcement: A guardrail is automatically applied to all Bedrock inference API calls in a specific AWS account.
- Model application scope can be selected via Include / Exclude, and system prompts and user prompts can be controlled via Comprehensive / Selective methods.
Before applying, a guardrail's version must be specified to make it immutable, and prerequisites such as resource-based policies for guardrails must also be satisfied. After configuration, actual requests can be sent via InvokeModel, InvokeModelWithResponseStream, Converse, and ConverseStream to verify whether the guardrail is applied and check the assessment information.
There are also clear operational precautions.
- Entering an incorrect guardrail ARN causes a policy violation, which can result in protection not being applied or model usage being blocked.
- Automated Reasoning checks are not supported for this feature.
- Application results can be checked and managed by OU, root, or individual account in the Targets tab of the AWS Organizations console.
This feature is available in all AWS commercial and GovCloud Regions where Bedrock Guardrails is offered, and charges are based on each guardrail's configured safeguards.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.