What happened
On Oct 6 the AWS Security Blog published a deployable pattern for agentic data access: Bedrock AgentCore carries the end-user's OIDC id_token on the transport layer (bypassing the FM entirely), a Lambda does a server-side token exchange against IAM Identity Center, and Lake Formation evaluates the real user's grants so the agent returns only rows/columns that person may see, with CloudTrail recording the human via onBehalfOf. Existing Lake Formation policies work unchanged; no rebuild of governance in app code.
Why it matters
This is a concrete answer to the biggest data-governance blocker for enterprise AI agents (bedrock issue: tools run under their own IAM role so the data layer sees the tool, not the person). Making user identity survivable through an FM's reasoning loop — and auditably so — is foundational for regulated buyers in finance/healthcare deploying lakehouse agents.
Applicability
Data platform owners and security engineers building agents on Bedrock AgentCore/Strands/LangGraph over Lake Formation-governed data should adopt this pattern before production; directly relevant to any OIDC IdP (Cognito, Okta).