The reason enterprises fail at agentic tools isn't that the tools are weak — it's that they either hand over the kingdom or lock everything away. The previous four parts give you the alternative:
| Layer | Failure mode it covers | What it buys you |
|---|---|---|
| 1. Identity (SSO, dedicated role, source identity) | Long-lived or shared credentials | Bound and attributable sessions with a short blast window |
2. UA tag (AWS_SDK_UA_APP_ID) |
Missing application telemetry | A best-effort, filterable trail alongside the principal identity |
| 3. SCP + RCP | Accidental over-grant and selected destructive actions | A ceiling even an admin session can't override |
| 4. Detect (CloudTrail + drift checks) | Unexplained or unmanaged changes | Attribution, alerting, and configuration mismatch detection |
The rollout order I'd actually use
- Stand up the sandbox first. A dedicated member account or OU, ideally with no production data. Get the agent out of shared accounts before you tune anything.
- Kill the long-lived keys. SSO everywhere, an agent role with source identity required in its trust policy, session duration capped. Verify the credential provider can refresh.
- Tag the fleet (part 2). Managed settings for Claude Code, managed config for Codex, OS-level fallback elsewhere. Confirm with one CloudTrail query that tagged calls are landing before you trust it.
- Attach the SCP (part 3) — after the sandbox baseline exists. Expect fallout, keep a log of every exception you grant, and remember each exception is an inheritance path too.
- Wire detection (part 4) before inviting users: the trail-to-Athena path, at least one dashboard query you've actually run, GuardDuty, and a budget alarm.
- Then open the doors to one squad with one tool and watch a quiet week of logs. Widen deliberately; the whole point of cheap layers is that you can afford to iterate.
What this does not solve
These layers bound what the agent can do to AWS. They do not control the rest of the machine. Filesystem isolation, network egress, MCP tool allow-listing, and deciding what may leave the host in a prompt still matter. AWS permissions cannot save a secret after the agent has already read it — and nothing here turns a poisoned context into a safe one. Layer 3 confines it; human approval on mutating actions is still the strongest control you have.
The honest summary of Layer 2 belongs here too: the UA tag is telemetry. The experiment in part 2 showed exactly how far a tag-conditioned control gets you — one environment variable away from being bypassed.
The point of all of this
None of it is heavy sandboxing. None of it requires a remote browser. It's a handful of cheap layers that let your agents actually be agents — read, diagnose, suggest, fix within bounds — while the account stays safe even when an individual engineer does something lazy.
You don't choose between "agents are useless" and "agents own my account". With the right cheap layers, you get agents that can help with autonomous troubleshooting and an account that caps the blast radius when they get it wrong.
The full series: [[[part 1 (threat model and identity)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-1-the-threat-model-and-the-identity-k40)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-1-the-threat-model-and-the-identity-k40)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-1-the-threat-model-and-the-identity-k40), [[[part 2 (the UA tag)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-2-label-every-agent-call-with-a-gac)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-2-label-every-agent-call-with-a-gac)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-2-label-every-agent-call-with-a-gac), [[[part 3 (the SCP backstop)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-3-the-scp-backstop-59k0)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-3-the-scp-backstop-59k0)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-3-the-scp-backstop-59k0), [[[part 4 (detection)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-4-detection-what-did-the-agent-3d3)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-4-detection-what-did-the-agent-3d3)](https://dev.to/aws-builders/your-aws-role-cant-tell-a-human-from-an-agent-anymore-part-4-detection-what-did-the-agent-3d3). The complete SCP policy referenced in part 3 is at gabrielkoo.com/devto/ai-agents-aws-sandbox/agent-sandbox-scp.json.
I'm an InfoSec + AI engineer (formerly DevSecOps) and AWS Community Builder based in Hong Kong — building secure, pragmatic agentic infrastructure. More writing on AWS security, AI tooling, and infra at gabrielkoo.com.

Top comments (0)