New integration gives security teams continuous visibility and real-time threat detection across agent interactions on AWS

Today, Harness announced a new integration with Amazon Bedrock AgentCore Gateway that helps enterprises discover and secure the AI agents, tools, and resources operating across their AWS environments.
The integration brings Harness’ AI posture management and AI firewall to agent interactions flowing through AgentCore Gateway. Security teams can now automatically build an inventory of their AI attack surface, detect prompt injection and sensitive-data leakage in real time, and investigate incidents with context spanning the originating client, the tools accessed, and the data involved.
This matters because enterprises are moving large numbers of agents from experiments into production. These agents are no longer limited to generating text. They can retrieve sensitive data, invoke tools, call services, interact with other agents, and complete business tasks autonomously. Autonomous agents create a fundamentally different security problem from protecting LLMs. An AI model can produce a bad answer. An AI agent can take a bad action.
Harness and AWS are giving security teams visibility at the critical point where an agent's decisions become actions.
When AI gains agency, security must follow the entire action path
Traditional applications largely follow execution paths defined by developers before deployment. A request reaches an endpoint, coded logic runs, and the application returns a response or performs an action.
Agents operate differently. An agent receives a goal, gathers context, decides what to do, selects a tool, observes the result, and adjusts its next step. Part of its execution path is assembled at runtime:
Goal → context → model decision → tool selection → data access → decision → tool selection → action
This means an unsafe outcome may not be visible in any one event. Each action can appear legitimate when inspected alone.
Consider a customer support agent that can read support tickets, retrieve customer records, and take the decision and action to issue refunds. An attacker embeds a malicious instruction inside a ticket. The agent retrieves that ticket as normal business context, treats the embedded text as an instruction, accesses the associated customer record, and attempts a refund to an account selected by the attacker.
The user may be authenticated. The agent may be authorized to use each tool. Every API call may be structurally valid. Yet the complete sequence is malicious.
Existing controls such as authentication, authorization, API validation, and infrastructure security remain essential. But they cannot, on their own, determine whether a permitted series of actions remains consistent with the agent's intended purpose.
The unit of security analysis must expand from a single request to the complete agent journey.
AgentCore Gateway creates a critical security control point
Amazon Bedrock AgentCore Gateway provides a fully managed way for developers to connect agents with tools and services. It sits at a consequential point in the agent architecture: between what an agent decides and the systems through which it acts.
The model may decide what it wants to do. The gateway is where that decision gains access to enterprise capabilities. That makes AgentCore Gateway a natural place to establish visibility across agent activity. Harness turns that visibility into security intelligence, helping teams answer three immediate questions: What AI assets are operating in our environment? How are they connected? Is an agent interaction being manipulated or exposing sensitive information?
Interactions at this action point can reveal the relationships security teams need to understand:
- Which client initiated the interaction
- Which AI agent or application was involved
- Which MCP server or tool the agent selected
- Which resource the tool accessed
- What data entered or left the interaction
- How one action related to the next
What the Harness integration delivers continuous, comprehensive visibility and protection
The new integration supports security teams from initial discovery through runtime threat detection.
Continuous AI discovery
Many enterprises cannot confidently secure their AI environment because they cannot first describe it. According to Harness research, nearly two-thirds of organizations have no visibility into where LLMs are being used across their environments.
Manual inventories cannot keep pace with production AI. New agents, prompts, tools, MCP servers, and resources can be introduced or changed faster than a periodic review process can track them.
Harness automatically discovers and continuously inventories the AI APIs, MCP servers, tools, prompts, and resources operating through Amazon Bedrock AgentCore Gateway. Security teams receive an always-current map of the AI attack surface without depending on manual tracking, tagging, or documentation.
This provides more than a list of models or projects. It shows the system around the agent: the interfaces it uses, the tools through which it acts, and the resources with which it interacts. That context is essential for understanding an agent's exposure and investigating its behavior.
Real-time AI threat detection
Harness instruments the chain of agent-to-tool interactions routed through AgentCore Gateway and applies behavioral AI to identify threats in real time. The integration initially focuses on two risks that demonstrate why agent activity must be evaluated as a connected journey.
- Prompt injection: Attackers can place malicious instructions in a user prompt, document, support ticket, webpage, tool result, or other content an agent encounters. The attacker’s goal is to make the agent treat untrusted content as an instruction and take an action the attacker could not perform directly. Finding suspicious text alone is not enough. Defenders need to connect its source with what the agent did next: the tool it selected, the resource it accessed, and the action it attempted.
- Sensitive-data leakage: An agent may be permitted to retrieve information and then expose it to an unintended user, tool, or output. The risk emerges from how data moves across the interaction - not merely from the retrieval or response viewed independently.
Harness detects these threats across agent interactions and surfaces incidents with trace-level context, including the originating client, the tool accessed, and the data involved. Security teams can investigate the path that produced the risk instead of reconstructing it from disconnected infrastructure and application logs.
Agent journeys are fundamentally extensions of API journeys
Harness brings an established foundation to this new security problem.
Harness already helps enterprises discover first- and third-party APIs, including shadow and zombie APIs. Its runtime security capabilities identify business-logic abuse, transaction fraud, and data leakage by analyzing application behavior across sessions. When new API threats are identified, Harness can communicate with AWS WAF to create or update rules for faster containment. The common principle is sequence-aware security.
Many attacks do not use malformed requests or obviously malicious endpoints. An attacker can use valid application functions in a permitted but abusive sequence. Detecting that behavior requires understanding the journey and its context, not merely evaluating one event at a time.
Agents make this need more urgent. Communication between agents, tools, MCPs and other assets happens through API calls, so having a strong API protection foundation is critical to protecting agents.
The agents dynamically choose among tools and data sources, generate their own multi-step paths, and act on behalf of users. The new integration extends Harness's behavioral intelligence from API journeys to agent journeys operating through AgentCore Gateway.
"Harness built its AI security capabilities to help secure AI workloads running on exactly this kind of infrastructure - the connectivity layer where enterprise AI runs in production," said Rahul Sood, GM of Application Security at Harness. "This integration gives security teams the depth of visibility they rely on for traditional APIs, now extended to agent interactions on AWS, so enterprises can move fast and confidently, with strong protection for their agentic operations."
Helping enterprises move agents into production securely
Enterprises create value from agents by connecting them to real systems. An agent without access to tools, data, or services may be easier to contain, but it is also far less useful.
The answer is not to prevent agents from acting. It is to preserve visibility and security as their access and autonomy grow.
Amazon Bedrock AgentCore Gateway gives builders a managed connectivity layer for agent-to-tool interactions. Harness gives security teams continuous discovery and behavioral runtime intelligence across those interactions. Together, the integration helps close the gap between teams building agents and teams responsible for protecting the enterprise.
Enterprises interested in securing their agentic AI workloads on AWS can contact their Harness account team or request a Harness AI Security demo.



