What do we need to control or features we need permission boundary for:
- Short lived and Long lived API keys in bedrock
- so long lived API keys always create an IAM user, which means during the time of investigation, we could check those users in IAM and find out if any API key has been created or not.
- User or malicious actor can add these API keys to their local running claude agent or codex or anything that supports bedrock
- Playground
- user can communicate with higher cost LLM models, can send images, generate code or communicate in such a way that'd incur a huge cost on the organisation.
- The models from "Model catalogue" opens up in the play ground for communication as well.
- Knowledge base
- Build Agents
- Guardrails