---
title: Amazon Bedrock Agent Core Control Policy
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > DDSQL Reference > Data Directory > Amazon Bedrock Agent Core Control
  Policy
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Amazon Bedrock Agent Core Control Policy

This table represents the Amazon Bedrock Agent Core Control Policy resource from Amazon Web Services.

```
aws.bedrock_agentcore_policy
```

## Fields

| Title            | ID   | Type          | Data Type                                                                                                                                                                                  | Description |
| ---------------- | ---- | ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------- |
| _key             | core | string        |
| account_id       | core | string        |
| created_at       | core | timestamp     | The timestamp when the policy was originally created. This is automatically set by the service and used for auditing and lifecycle management.                                             |
| definition       | core | json          | The Cedar policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.                              |
| description      | core | string        | A human-readable description of the policy's purpose and functionality. Limited to 4,096 characters, this helps administrators understand and manage the policy.                           |
| name             | core | string        | The customer-assigned immutable name for the policy. This human-readable identifier must be unique within the account and cannot exceed 48 characters.                                     |
| policy_arn       | core | string        | The Amazon Resource Name (ARN) of the policy. This globally unique identifier can be used for cross-service references and IAM policy statements.                                          |
| policy_engine_id | core | string        | The identifier of the policy engine that manages this policy. This establishes the policy engine context for policy evaluation and management.                                             |
| policy_id        | core | string        | The unique identifier for the policy. This system-generated identifier consists of the user name plus a 10-character generated suffix and serves as the primary key for policy operations. |
| status           | core | string        | The current status of the policy.                                                                                                                                                          |
| status_reasons   | core | array<string> | Additional information about the policy status. This provides details about any failures or the current state of the policy lifecycle.                                                     |
| tags             | core | hstore_csv    |
| updated_at       | core | timestamp     | The timestamp when the policy was last modified. This tracks the most recent changes to the policy configuration or metadata.                                                              |
