# Bedrock Managed Agents (preview) — go / no-go checklist

Written against the public preview announced **September 29, 2026**. Sources: [What's New](https://aws.amazon.com/about-aws/whats-new/2026/09/bedrock-managed-agents-preview/), [user guide](https://docs.aws.amazon.com/bedrock/latest/userguide/bedrock-managed-agents-openai.html), [preview limitations](https://docs.aws.amazon.com/bedrock/latest/userguide/bedrock-managed-agents-openai-quotas-limitations.html), [security](https://docs.aws.amazon.com/bedrock/latest/userguide/bedrock-managed-agents-openai-security.html). Preview APIs can change — re-check before each run.

Score each gate. Any **No** on a hard gate means stay on your current agent stack for this workload.

## Hard gates

| # | Gate | How to check | Yes / No |
|---|------|--------------|----------|
| 1 | The workload can run in **us-east-1, us-east-2, or us-west-2** | Data-residency review; the preview has no cross-Region inference profiles | |
| 2 | Your chosen OpenAI model works with BMA **in that Region and account** | `python3 bma_client.py GET /v1/models`, then create one test session. Catalog presence alone does not prove BMA support | |
| 3 | Input is **text only** | The documented session input is text. No image or file upload in the session API | |
| 4 | You do **not** need subagents or code mode | Both are unsupported in the preview | |
| 5 | You do **not** need a customer-managed KMS key on service-held session data | The preview does not expose one | |
| 6 | Every tool with an external effect enforces its **own** authorization and human review | Approval must live in your app or tool code. The session config is not the control | |
| 7 | The execution environment is **isolated** | Dedicated workspace, restricted OS user, only the files, secrets, and network routes the task needs | |

## Soft gates (fix before a real pilot)

| # | Gate | Notes |
|---|------|-------|
| 8 | Long-term memory has an owner | No built-in long-term memory. Pick a datastore and authorize it separately |
| 9 | Retry logic checks state before resubmitting | After a network timeout, read session items first — the service may already have accepted the message |
| 10 | Success is judged from items, not from `idle` | Check command exit codes and MCP call results for each `turn_id` |
| 11 | MCP servers expose only needed tools | Set `allowed_tools`; forward only required env vars; no secrets in `env` |
| 12 | Cleanup has a named owner | Deleting a session does not delete workspace files, S3 outputs, or the AgentCore stack. The example stack's NAT gateway bills hourly while idle |
| 13 | Three separate identities exist | Caller (client role), session role (assumed by `bedrock-mantle.amazonaws.com`), execution identity (host user or AgentCore Runtime role) |

## Decision

- **7/7 hard gates Yes** → run a two-week pilot in a sandbox account on one text-in, file-out task.
- **Any hard gate No** → stay on AgentCore Runtime with your own framework (Strands, LangGraph) for this workload, and re-check at GA.
