AWS Security AI Architecture: Managed MCP, Custom MCP, or Lambda + Bedrock?





Executive decision


There is no single “correct” architecture for AI-assisted AWS security work.

For Security Hub, GuardDuty, ECR, and cloud security reporting, there are three valid patterns:



AWS Managed MCP / AWS Agent Toolkit for live, read-only AWS...