Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Amazon Bedrock AgentCore vs Workday Agent System of Record

Amazon Bedrock AgentCore

AWS platform for building, deploying, and operating AI agents

Workday Agent System of Record

Workday system of record to find, add, register, configure, monitor, and manage AI agents

Short answer

Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents, while Workday Agent System of Record (ASOR) lets a company find, register, configure, monitor, and manage AI agents in each Workday tenant.⁠Source 1, Source 2, Source 3 AgentCore’s Gateway policies set which tools an agent may call; in ASOR, Workday security policies and groups govern access.⁠Source 4, Source 5

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both keep a registry of agents, manage agent identities, control what agents can access, and keep audit records.⁠Source 2, Source 4, Source 5, Source 6, Source 7, Source 8, Source 9, Source 10, Source 11 Both can base agent records on the A2A Agent Card specification.⁠Source 10, Source 12, Source 13
Where they differ
AgentCore also hosts agents in a serverless Runtime, with any framework and model.⁠Source 1 ASOR is set up per Workday tenant; for agents working with Workday, tools are Workday APIs.⁠Source 2, Source 3
Running both
Neither vendor publicly documents using the two together. Workday announced AWS among the first partners in its Agent Partner Network in June 2025.⁠Source 14
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Amazon Bedrock AgentCore

  • Build agents: OfferedHarness managed agent loop⁠Source 1
  • Host and run agents: OfferedAgentCore Runtime⁠Source 1
  • Identity and access: OfferedAgentCore Identity workload identities⁠Source 7
  • Registry and governance: OfferedAWS Agent Registry with approvals⁠Source 6
  • Traffic between agents, tools, and models: OfferedAgentCore Gateway⁠Source 15
  • Agents across organizations: OfferedRegistry shared through AWS RAM⁠Source 16

Workday Agent System of Record

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent System User per agent⁠Source 9
  • Registry and governance: OfferedAgent Registry in Management Hub⁠Source 2
  • Traffic between agents, tools, and models: OfferedAgent Gateway for Workday APIs⁠Source 17
  • Agents across organizations: Not publicly documented

At a glance

TopicAmazon Bedrock AgentCoreWorkday Agent System of Record
What it isAWS’s managed platform for building, deploying, and operating agents with any framework and foundation model.⁠Source 1A functional area you enable in each Workday tenant to find, register, configure, monitor, and manage AI agents.⁠Source 2, Source 3
Where agents runIn AgentCore’s serverless Runtime, or elsewhere: its Registry can also list agents on premises or in other clouds.⁠Source 1External agents are registered through the ASOR API with the URL where each one is hosted.⁠Source 13, Source 18
Agent identityWorkload identities in AgentCore Identity, for agents on Runtime, in self-hosted environments, or in hybrid deployments.⁠Source 7, Source 8A unique Workday identity per agent, using Agent System User accounts governed by Workday security policies and groups.⁠Source 5, Source 9
Pricing modelConsumption-based, billed per feature used, with no upfront commitment or minimum fee.⁠Source 19No additional specific SKU for ASOR.⁠Source 2 Registering Workday-built agents in production requires opting in to the Universal Main Service Agreement and the Flex Credits and Platform Entitlement Policy.⁠Source 2
Generally availableSince October 2025; AWS Agent Registry since August 2026.⁠Source 20Generally available since February 2026.⁠Source 21

What each one is

Amazon Bedrock AgentCore

Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and foundation model.⁠Source 1 Its modular services, usable together or independently, include a serverless Runtime for agents, Gateway, Identity, Policy, Observability, and AWS Agent Registry.⁠Source 1, Source 4, Source 6, Source 7, Source 22, Source 23

Workday Agent System of Record

Workday Agent System of Record (ASOR) is a functional area of a Workday tenant for finding, registering, configuring, monitoring, and managing AI agents.⁠Source 2, Source 3 Workday calls it the single source of truth for a company’s agents, whether Workday, the customer, or a partner built them.⁠Source 21

The differences that matter

  1. Building and hosting agents

    Amazon Bedrock AgentCore

    Developers write the agent loop with a framework such as Strands, LangGraph, or Google ADK and deploy it to Runtime, or use the managed Harness.⁠Source 1, Source 24

    Workday Agent System of Record

    ASOR takes an external agent’s definition through an API; Workday announced a low-code agent builder for its separate developer platform, Workday Build.⁠Source 2, Source 25, Source 26

    AgentCore works with models in or outside Amazon Bedrock.⁠Source 27 Which models ASOR supports or includes is not publicly documented.

  2. Who decides what an agent can reach

    Amazon Bedrock AgentCore

    Policies, in natural language or Cedar, set which tools an agent may call and when; Policy can check each request that passes through a Gateway.⁠Source 4

    Workday Agent System of Record

    Workday security policies and groups set each agent’s access; acting for a user, an agent gets only what both may do.⁠Source 5, Source 9

    Workday’s Agent Interaction Policy sets which users may use an agent’s delegate-mode skills.⁠Source 28

  3. Agents in other accounts and companies

    Amazon Bedrock AgentCore

    A registry can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization must accept an invitation.⁠Source 16

    Workday Agent System of Record

    ASOR manages partner-built agents in your tenant; a definition can carry an ID locating the agent in the partner’s system.⁠Source 2, Source 3, Source 13

    For ASOR, controls held by the partner company are not publicly documented. An AWS registry owner revokes another account’s access by removing it from the share.⁠Source 16

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicAmazon Bedrock AgentCoreWorkday Agent System of Record
Network exposureAgentCore can reach private MCP servers, APIs, and databases in your VPC without public exposure.⁠Source 29 VPC callers can use PrivateLink.⁠Source 30Third-party agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 17 Whether agents need inbound endpoints: not publicly documented.
IdentityAgent identities are workload identities.⁠Source 7 Hosted agents accept IAM SigV4 by default, or JWTs from any OAuth 2.0 provider.⁠Source 31, Source 32A unique Workday identity per agent.⁠Source 9 OAuth 2.0 or signed JWTs; third-party (self-built) agents’ tokens last 4 hours.⁠Source 2, Source 9, Source 33
Access changes and revocationExplicit deny policies can block Runtime, Gateway, and Memory access; removing an account from a registry share revokes its access.⁠Source 16, Source 34Deactivating hides an agent from users; Workday says it can take up to a minute to reach Agent Gateway requests.⁠Source 2, Source 17
Audit trailCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls; Policy logs its decisions.⁠Source 4, Source 10, Source 35, Source 36An audit trail report covers agent transactions; delegated actions record both the agent and the user.⁠Source 9, Source 11
ComplianceHIPAA eligible; AWS lists it as FedRAMP (Class C and Class D), SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 37, Source 38Workday says its SOC 2 report covers Workday Enterprise Products and ISO 42001 covers Workday Platform; neither names ASOR.⁠Source 39

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Amazon Bedrock AgentCore and Workday Agent System of Record compared on 18 criteria
Amazon Bedrock AgentCoreWorkday Agent System of Record
What it is
What it is and who it’s forAWS’s platform for building, deploying, and operating agents with any framework and model, made of services usable together or independently.⁠Source 1Set up in each Workday tenant to find, register, configure, monitor, and manage AI agents built by Workday, partners, or the customer.⁠Source 2, Source 3
MaturityGenerally available since October 2025.⁠Source 20 Policy has been generally available since March 2026, and AWS Agent Registry since August 2026.⁠Source 20Generally available since February 2026.⁠Source 21 Workday first announced it in February 2025.⁠Source 40
Control
Agent registry and discoveryAWS Agent Registry catalogs agents, MCP servers, tools, and skills on AWS, on premises, or in other clouds.⁠Source 1, Source 6 Consumers see only approved records.⁠Source 41The Agent Management Hub lists Workday-built, partner-built, and self-built agents with status.⁠Source 2 Some, such as HiredScore and Evisort agents, aren’t in ASOR.⁠Source 2
Identity and access controlAgent identities are workload identities.⁠Source 7 Calls to hosted agents use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.⁠Source 31, Source 32Each agent has a unique Workday identity, governed by security policies and groups.⁠Source 5, Source 9 Acting for a user, an agent gets only what both may do.⁠Source 9
Ownership, policy, and revocationNatural-language or Cedar policies set which tools an agent may call through a Gateway.⁠Source 4 An approval workflow gates records; curators can deprecate them.⁠Source 6, Source 10Admins set each agent’s skills and who can use it.⁠Source 2 A deactivated agent is hidden from users and can be reactivated.⁠Source 2
Audit log and observabilityCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.⁠Source 10, Source 35, Source 36 Policy logs its decisions.⁠Source 4An audit trail report covers agent transactions; delegated actions record the agent and the user.⁠Source 9, Source 11 Per-agent analytics reports cover Workday-built agents only.⁠Source 2
Connection
How agents connectAgents can run in serverless Runtime, or elsewhere behind a Gateway that forwards to their endpoint URL.⁠Source 1, Source 15 Outbound-only connections are not publicly documented.Third-party agents must send Workday API calls through Agent Gateway, a single regional endpoint.⁠Source 17 An external agent’s definition records its hosting URL.⁠Source 13
Agents across organizationsA registry can be shared with other AWS accounts through AWS RAM, and Runtime agents can be opened to principals in other accounts.⁠Source 16, Source 34ASOR manages partner-built agents; a definition can carry an ID locating each one in the partner’s system.⁠Source 2, Source 13 Partner-held controls are not publicly documented.
Protocol supportRuntime agents can serve HTTP, MCP, A2A, or AG-UI.⁠Source 42 Gateway acts as an MCP server, and Registry validates agent records against the A2A schema.⁠Source 10, Source 43API registration is based on the A2A Agent Card.⁠Source 13 Outside assistants can call the Self-Service Agent over A2A, and tool search can filter by SOAP, REST, or MCP.⁠Source 44, Source 45
Frameworks, models, and clouds supportedRuntime works with custom frameworks and open-source ones such as CrewAI, LangGraph, and Strands Agents.⁠Source 1 Registry can also list agents built on other providers.⁠Source 27Registration records each agent’s platform, or OTHER.⁠Source 13 Workday names Google Gemini Enterprise as an outside assistant able to call its Self-Service Agent.⁠Source 44
Operations
Deployment options and data residencyAWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.⁠Source 1, Source 46Set up in each Workday tenant.⁠Source 3 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.⁠Source 17 Self-hosting: not publicly documented.
Compliance attestationsAWS lists AgentCore as FedRAMP (Class C and Class D) compliant.⁠Source 37, Source 38 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 20, Source 37Workday says its SOC 2 report covers Workday Enterprise Products, and ISO 42001 covers Workday Platform.⁠Source 39 Coverage of ASOR is not publicly documented.
Support and SLAAWS says the Amazon Bedrock SLA applies to AgentCore.⁠Source 27 Basic Support is included for all AWS customers.⁠Source 47Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.⁠Source 48 An ASOR uptime SLA is not publicly documented.
Time and effort to get runningAWS’s quickstart uses the AgentCore CLI to scaffold, test, deploy, and invoke one agent.⁠Source 24 It needs an AWS account and Node.js 20 or later.⁠Source 24Enable the ASOR functional area and set its security policies.⁠Source 3 Registering an external agent includes finding the IDs of the Workday APIs it will use.⁠Source 18
Pricing model and public pricesConsumption-based per feature, with no minimum fee.⁠Source 19 AWS Agent Registry has a monthly free tier; a Policy authorization request costs $0.000025.⁠Source 19No additional specific SKU for ASOR.⁠Source 2 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 2 A credit’s price is not publicly documented.
Building
Agent building toolsWrite the agent loop in Python with a framework such as Strands, LangGraph, or Google ADK and deploy it to Runtime, or use the managed Harness.⁠Source 1, Source 24You provide an external agent’s definition through an API.⁠Source 2 Workday announced the low-code Flowise Agent Builder for its separate Workday Build in 2025.⁠Source 25
Model accessModel-agnostic, AWS says: models in or outside Amazon Bedrock, including OpenAI, Gemini, Claude, Nova, Llama, and Mistral.⁠Source 27Workday’s AI agents use large language models.⁠Source 2 Which models ASOR supports or includes is not publicly documented.
Integrations and ecosystemGateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import AWS Partner tools bought in AWS Marketplace.⁠Source 22, Source 27In February 2026, Workday said more than 65 partners were connecting agents to ASOR.⁠Source 21 Workday said partner agents reached Workday Marketplace in June 2025.⁠Source 14

Which to choose

Choose Amazon Bedrock AgentCore if

  • You want to build, deploy, and run agents on AWS, with frameworks such as LangGraph, CrewAI, or Strands Agents.⁠Source 1
  • You want model choice in or outside Amazon Bedrock: AWS names OpenAI, Gemini, Claude, Nova, Llama, and Mistral.⁠Source 27
  • You want one approved catalog of agents, MCP servers, and tools, whether they run on AWS, on premises, or in other clouds.⁠Source 1, Source 6
  • You want each tool call through a gateway checked against policies written in natural language or Cedar.⁠Source 4

Choose Workday Agent System of Record if

  • Your agents mostly work in Workday, and each should have a unique Workday identity under your existing security policies and groups.⁠Source 2, Source 5, Source 9
  • You want an agent acting for a user limited to what both may do, with audit entries naming both.⁠Source 9
  • You want Workday-built, partner-built, and self-built agents listed with their status in one Agent Management Hub.⁠Source 2
  • You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR itself.⁠Source 2, Source 3

Questions buyers ask

Can Workday Agent System of Record manage agents built outside Workday?

Yes: the ASOR API defines and registers an external agent in one call, and the Agent Management Hub manages self-built and partner-built agents.⁠Source 2, Source 18 Some agents, including those for HiredScore and Evisort, are not part of ASOR, and per-agent analytics reports cover Workday-built agents only.⁠Source 2

How is each one priced?

AgentCore bills each feature by use; Runtime v1 CPU, for example, is $0.0895 per vCPU-hour.⁠Source 19 ASOR needs no additional specific SKU.⁠Source 2 Workday offers complimentary Flex Credits to explore agents in production and free non-production testing.⁠Source 49 A credit’s price is not publicly documented.

Do they support MCP and A2A?

AgentCore Runtime can host MCP and A2A servers; Gateway supports four MCP versions for MCP targets.⁠Source 42, Source 50 Workday bases external agent registration on the A2A Agent Card, lists MCP as a tool type, and outside assistants can call its Self-Service Agent over A2A.⁠Source 13, Source 44, Source 45

Can either one connect agents across companies?

An AgentCore registry can be shared through AWS RAM with accounts outside your AWS Organization, which must accept an invitation.⁠Source 16 ASOR manages partner-built agents, which Workday calls second-party agents.⁠Source 2 Sharing agents between two Workday tenants is not publicly documented.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

55 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) AWS · checked Back:abcdefghijklmnopq

  2. Source 2: About Workday Agents (Workday Administrator Guide) Workday · checked Back:abcdefghijklmnopqrstuvwxyz27282930

  3. Source 3: Set Up Agent System of Record (Workday Administrator Guide) Workday · checked Back:abcdefghi

  4. Source 4: Policy in Amazon Bedrock AgentCore: Control Agent Interactions AWS · checked Back:abcdefgh

  5. Source 5: Setup Considerations: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdef

  6. Source 6: AWS Agent Registry: Discover and manage agents, tools, and resources AWS · checked Back:abcdef

  7. Source 7: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity AWS · checked Back:abcdef

  8. Source 8: Features of AgentCore Identity AWS · checked Back:ab

  9. Source 9: Concept: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefghijkl

  10. Source 10: Key capabilities - AWS Agent Registry AWS · checked Back:abcdef

  11. Source 11: FAQ: Agent Security (Workday Administrator Guide) Workday · checked Back:abc

  12. Source 12: Supported record types and descriptors - AWS Agent Registry AWS · checked Back to text

  13. Source 13: ASOR API Documentation v1.2 (Workday/asor on GitHub) Workday · checked Back:abcdefgh

  14. Source 14: Workday Announces New AI Agent Partner Network and Agent Gateway Workday · checked Back:ab

  15. Source 15: HTTP passthrough targets - AgentCore Gateway AWS · checked Back:ab

  16. Source 16: Sharing a registry across accounts with AWS RAM AWS · checked Back:abcdef

  17. Source 17: Concept: Workday Agent Gateway (Workday Administrator Guide) Workday · checked Back:abcde

  18. Source 18: Register External Agents (Workday Administrator Guide) Workday · checked Back:abc

  19. Source 19: Amazon Bedrock AgentCore Pricing AWS · checked Back:abcd

  20. Source 20: Release notes - Amazon Bedrock AgentCore AWS · checked Back:abcd

  21. Source 21: The Workday Agent System of Record Is Now Generally Available Workday · checked Back:abcd

  22. Source 22: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models AWS · checked Back:ab

  23. Source 23: Observe your agent applications on Amazon Bedrock AgentCore Observability AWS · checked Back to text

  24. Source 24: Get started with Amazon Bedrock AgentCore AWS · checked Back:abcd

  25. Source 25: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Workday · checked Back:ab

  26. Source 26: Workday Build | Workday US Workday · checked Back to text

  27. Source 27: Amazon Bedrock AgentCore FAQs AWS · checked Back:abcdef

  28. Source 28: Concept: Agent Interaction Policy (Workday Administrator Guide) Workday · checked Back to text

  29. Source 29: Connect to private resources in your VPC using VPC Lattice AWS · checked Back to text

  30. Source 30: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore AWS · checked Back to text

  31. Source 31: Authenticate and authorize with Inbound Auth and Outbound Auth AWS · checked Back:ab

  32. Source 32: Configure inbound JWT authorizer AWS · checked Back:ab

  33. Source 33: Concept: External Agent ASU Considerations (Workday Administrator Guide) Workday · checked Back to text

  34. Source 34: Resource-based policies for Amazon Bedrock AgentCore AWS · checked Back:ab

  35. Source 35: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail AWS · checked Back:ab

  36. Source 36: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore AWS · checked Back:ab

  37. Source 37: Compliance validation for Amazon Bedrock AgentCore AWS · checked Back:abc

  38. Source 38: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services AWS · checked Back:ab

  39. Source 39: Workday Compliance | Workday US Workday · checked Back:ab

  40. Source 40: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Workday · checked Back to text

  41. Source 41: Concepts and terminology - AWS Agent Registry AWS · checked Back to text

  42. Source 42: Understand the AgentCore Runtime service contract AWS · checked Back:ab

  43. Source 43: Supported targets for Amazon Bedrock AgentCore gateways AWS · checked Back to text

  44. Source 44: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Workday · checked Back:abc

  45. Source 45: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Workday · checked Back:ab

  46. Source 46: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations AWS · checked Back to text

  47. Source 47: Compare AWS Support plans AWS · checked Back to text

  48. Source 48: Workday Support | Workday US Workday · checked Back to text

  49. Source 49: Workday Flex Credits | Workday US Workday · checked Back to text

  50. Source 50: MCP servers targets - AgentCore Gateway AWS · checked Back to text

  51. Source 51: Why Blocks? Blocks.ai · checked Back to text

  52. Source 52: What is Blocks? Blocks.ai · checked Back to text

  53. Source 53: Your company's private network Blocks.ai · checked Back to text

  54. Source 54: Network requirements Blocks.ai · checked Back to text

  55. Source 55: Solutions: Agent sprawl Blocks.ai · checked Back to text