Memory hook: Protect the data path and the action path, then keep evidence of both.
Must remember
- Apply least-privilege IAM roles to models, tools, data stores and logs. Separate end-user identity from workload identity. Agent identity and policy features support controls, but the application still needs tenant isolation and scoped tool permissions.
- Use TLS in transit, suitable encryption at rest and controlled KMS key access. PrivateLink provides supported private connectivity; it does not replace identity authorisation. Macie helps discover sensitive S3 data. Secrets should not be included in prompts or source code.
- Prompt injection tries to turn untrusted text into instructions. It may arrive in a user message, retrieved page or tool result. Poisoning corrupts training or indexed data. Jailbreaking seeks to defeat safety behaviour. Validate inputs/outputs, restrict actions and treat retrieved content as data.
- Bedrock Guardrails can apply configured content, topic, sensitive-information and other supported controls. Grounding and output validation can help detect unsupported statements. Do not use model self-reported confidence as the sole authority for high-risk decisions.
- Track provenance, licences and lineage from source data through transformations, model versions and outputs. Define residency, retention and deletion requirements for prompts, logs, embeddings and memory as well as primary datasets.
- CloudTrail supplies supported API audit events; Config evaluates resource configuration; Inspector assesses supported workload vulnerabilities; Artifact supplies AWS compliance evidence; Trusted Advisor highlights supported recommendations. Choose evidence according to the question.
- Governance needs accountable owners, approval gates, review cadence, staff training and documented exceptions. Use a risk framework appropriate to the application and shared-responsibility model. Service compliance does not certify that your own data collection or use is lawful.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A retrieved document tells an agent to reveal secrets | Treat as injection; enforce permissions and tool constraints outside the model. |
| Need evidence of configuration compliance | Config plus the relevant audit process. |
| Need to prove where training material came from | Data lineage, provenance and licensing records. |
Traps
- A private network does not prevent an authorised application from leaking data.
- Encrypting vectors does not resolve the right to retain their source data.
- Logging every prompt without redaction can create a second sensitive-data store.
Active recall
1. Can an output filter replace tool authorisation?
No. Actions need explicit permission checks before execution.
2. Where else must deletion requirements be considered besides the source bucket?
Indexes, embeddings, caches, logs, backups and agent memory, according to their retention obligations.
3. Which audit source answers who called a supported AWS API?
CloudTrail, with the necessary events configured.
4. What should happen to an instruction embedded inside retrieved evidence?
It should remain untrusted content, not override application policy.
5. Does using an AWS-certified service automatically make the application compliant?
No. Customer data practices, configuration and governance still need assessment.