# Bedrock Managed Agents, powered by OpenAI (preview) — starter files

Companion files for the FactualMinds post [Bedrock Managed Agents Preview (September 2026): What AWS Runs and What You Still Own](https://www.factualminds.com/blog/amazon-bedrock-managed-agents-openai-preview-2026/).

These files are **not** AWS's example bundle. Download that from the [BMA prerequisites page](https://docs.aws.amazon.com/bedrock/latest/userguide/bedrock-managed-agents-openai-prerequisites.html). These files help you review permissions, cost, and fit before you deploy it.

| File | What it is |
|------|------------|
| `iam/session-role-trust.json` | Trust policy for the session role. Only `bedrock-mantle.amazonaws.com` in your account can assume it. Replace `123456789012`. |
| `iam/session-role-inference.json` | Lets the session role call **one** model. `CreateInference` has no model ARN, so the `bedrock-mantle:Model` condition is the only fence. Change the model ID on purpose, not by widening to `*`. |
| `iam/client-policy.json` | Caller permissions: the seven preview session actions plus `iam:PassRole` for one named role, only to `bedrock-mantle.amazonaws.com`. Narrow `Resource` with the stack's generated `BmaAccessRole` policy once you have it. |
| `iam/exec-server-host-policy.json` | Extra actions a **self-hosted** exec server needs. AgentCore Runtime uses its own execution role instead. |
| `idle-cost-worksheet.csv` | Monthly cost lines for the AgentCore example stack, with the ones that bill while no turn runs flagged. Only published unit prices are filled in; add your quantities. |
| `preview-readiness-checklist.md` | Seven hard gates and six soft gates for deciding whether a workload fits the preview. |

## Create the session role (AWS CLI v2)

```bash
aws iam create-role \
  --role-name BedrockManagedAgentsPreviewInferenceServiceRole \
  --assume-role-policy-document file://iam/session-role-trust.json

aws iam put-role-policy \
  --role-name BedrockManagedAgentsPreviewInferenceServiceRole \
  --policy-name bma-inference-one-model \
  --policy-document file://iam/session-role-inference.json
```

Then point AWS's scripts at it: `export BMA_INFERENCE_ROLE_ARN=arn:aws:iam::<account-id>:role/BedrockManagedAgentsPreviewInferenceServiceRole` and run `./scripts/bma/0.create-session.sh` from the bundle's `self-hosted/` directory. A successful run writes the session ID and environment ID to `scripts/bma/.bma-session.env`.

IAM action names are the preview's `bedrock-mantle:*AgentSession*` names. AWS says preview APIs can change — review permissions again when you upgrade the bundle.
