AWS has introduced managed entitlements for Amazon Bedrock models, enabling organizations to centrally manage access to third-party models such as Anthropic Claude and Cohere across multiple AWS accounts. This solution eliminates the need for AWS Marketplace permissions in workload accounts, streamlining model access while maintaining centralized governance. The feature is designed for organizations managing AI workloads across dozens or hundreds of accounts, where granting broad permissions could lead to governance issues. According to AWS, managed entitlements complement other Amazon Bedrock capabilities like model evaluation and guardrails, ensuring teams have access to the models they need without compromising control.

Managed entitlements work by allowing a central account to subscribe to a model through AWS Marketplace, then distributing access to member accounts using AWS License Manager. No AWS Marketplace permissions are required in the member accounts, which simplifies the process. The workflow involves four main steps: subscribing to a model, verifying license creation, creating grants for specific accounts, and activating the grants. Once activated, member accounts can invoke the model without additional subscriptions. This approach ensures consistent pricing and centralized visibility into model access across the organization. AWS also highlights that managed entitlements apply only to third-party models distributed through AWS Marketplace, such as Anthropic Claude, AI21 Labs, Cohere, and Stability AI.

AWS emphasizes that managed entitlements are particularly useful for organizations with negotiated private offers and a need for consistent pricing across accounts. For example, if an organization has negotiated custom pricing with a model provider, the private offer can be extended to the management account, and access can be distributed via grants to ensure all member accounts use the agreed-upon terms. This feature also supports rapid organization-wide deployment, allowing a single grant to be distributed to an entire AWS Organizations structure, ensuring immediate access for all accounts. The solution aims to reduce operational overhead and simplify the management of AI model access in multi-account environments.

Source: awsml