AWS
Cloud & infrastructure
Read-only cross-account role surfacing Bedrock CloudTrail invocations and Lambda functions with bedrock or anthropic IAM policies attached.
What we’d pull
cloudtrail:LookupEventsBedrock invocation log entries.lambda:ListFunctionsLambdas attached to AI policies.
Surfaces this would light up
- AI estate (Bedrock usage attribution)
- Agent-deployed Lambda inventory