Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Amazon Bedrock AgentCore vs Workday Agent System of Record
Amazon Bedrock AgentCore
AWS platform for building, deploying, and operating AI agents
Workday Agent System of Record
Workday system of record to find, add, register, configure, monitor, and manage AI agents
Short answer
Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents, while Workday Agent System of Record (ASOR) lets a company find, register, configure, monitor, and manage AI agents in each Workday tenant.Source 1, Source 2, Source 3 AgentCore’s Gateway policies set which tools an agent may call; in ASOR, Workday security policies and groups govern access.Source 4, Source 5
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both keep a registry of agents, manage agent identities, control what agents can access, and keep audit records.Source 2, Source 4, Source 5, Source 6, Source 7, Source 8, Source 9, Source 10, Source 11 Both can base agent records on the A2A Agent Card specification.Source 10, Source 12, Source 13
- Where they differ
- AgentCore also hosts agents in a serverless Runtime, with any framework and model.Source 1 ASOR is set up per Workday tenant; for agents working with Workday, tools are Workday APIs.Source 2, Source 3
- Running both
- Neither vendor publicly documents using the two together. Workday announced AWS among the first partners in its Agent Partner Network in June 2025.Source 14
Amazon Bedrock AgentCore
Workday Agent System of Record
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Amazon Bedrock AgentCore
Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and foundation model.Source 1 Its modular services, usable together or independently, include a serverless Runtime for agents, Gateway, Identity, Policy, Observability, and AWS Agent Registry.Source 1, Source 4, Source 6, Source 7, Source 22, Source 23
Workday Agent System of Record
Workday Agent System of Record (ASOR) is a functional area of a Workday tenant for finding, registering, configuring, monitoring, and managing AI agents.Source 2, Source 3 Workday calls it the single source of truth for a company’s agents, whether Workday, the customer, or a partner built them.Source 21
The differences that matter
Building and hosting agents
Amazon Bedrock AgentCoreDevelopers write the agent loop with a framework such as Strands, LangGraph, or Google ADK and deploy it to Runtime, or use the managed Harness.Source 1, Source 24
Workday Agent System of RecordASOR takes an external agent’s definition through an API; Workday announced a low-code agent builder for its separate developer platform, Workday Build.Source 2, Source 25, Source 26
AgentCore works with models in or outside Amazon Bedrock.Source 27 Which models ASOR supports or includes is not publicly documented.
Who decides what an agent can reach
Amazon Bedrock AgentCorePolicies, in natural language or Cedar, set which tools an agent may call and when; Policy can check each request that passes through a Gateway.Source 4
Workday Agent System of RecordWorkday security policies and groups set each agent’s access; acting for a user, an agent gets only what both may do.Source 5, Source 9
Workday’s Agent Interaction Policy sets which users may use an agent’s delegate-mode skills.Source 28
Agents in other accounts and companies
Amazon Bedrock AgentCoreA registry can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization must accept an invitation.Source 16
Workday Agent System of RecordASOR manages partner-built agents in your tenant; a definition can carry an ID locating the agent in the partner’s system.Source 2, Source 3, Source 13
For ASOR, controls held by the partner company are not publicly documented. An AWS registry owner revokes another account’s access by removing it from the share.Source 16
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Amazon Bedrock AgentCore | Workday Agent System of Record | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | AWS’s platform for building, deploying, and operating agents with any framework and model, made of services usable together or independently.Source 1 | Set up in each Workday tenant to find, register, configure, monitor, and manage AI agents built by Workday, partners, or the customer.Source 2, Source 3 |
| Maturity | Generally available since October 2025.Source 20 Policy has been generally available since March 2026, and AWS Agent Registry since August 2026.Source 20 | Generally available since February 2026.Source 21 Workday first announced it in February 2025.Source 40 |
| Control | ||
| Agent registry and discovery | AWS Agent Registry catalogs agents, MCP servers, tools, and skills on AWS, on premises, or in other clouds.Source 1, Source 6 Consumers see only approved records.Source 41 | The Agent Management Hub lists Workday-built, partner-built, and self-built agents with status.Source 2 Some, such as HiredScore and Evisort agents, aren’t in ASOR.Source 2 |
| Identity and access control | Agent identities are workload identities.Source 7 Calls to hosted agents use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.Source 31, Source 32 | Each agent has a unique Workday identity, governed by security policies and groups.Source 5, Source 9 Acting for a user, an agent gets only what both may do.Source 9 |
| Ownership, policy, and revocation | Natural-language or Cedar policies set which tools an agent may call through a Gateway.Source 4 An approval workflow gates records; curators can deprecate them.Source 6, Source 10 | Admins set each agent’s skills and who can use it.Source 2 A deactivated agent is hidden from users and can be reactivated.Source 2 |
| Audit log and observability | CloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.Source 10, Source 35, Source 36 Policy logs its decisions.Source 4 | An audit trail report covers agent transactions; delegated actions record the agent and the user.Source 9, Source 11 Per-agent analytics reports cover Workday-built agents only.Source 2 |
| Connection | ||
| How agents connect | Agents can run in serverless Runtime, or elsewhere behind a Gateway that forwards to their endpoint URL.Source 1, Source 15 Outbound-only connections are not publicly documented. | Third-party agents must send Workday API calls through Agent Gateway, a single regional endpoint.Source 17 An external agent’s definition records its hosting URL.Source 13 |
| Agents across organizations | A registry can be shared with other AWS accounts through AWS RAM, and Runtime agents can be opened to principals in other accounts.Source 16, Source 34 | ASOR manages partner-built agents; a definition can carry an ID locating each one in the partner’s system.Source 2, Source 13 Partner-held controls are not publicly documented. |
| Protocol support | Runtime agents can serve HTTP, MCP, A2A, or AG-UI.Source 42 Gateway acts as an MCP server, and Registry validates agent records against the A2A schema.Source 10, Source 43 | API registration is based on the A2A Agent Card.Source 13 Outside assistants can call the Self-Service Agent over A2A, and tool search can filter by SOAP, REST, or MCP.Source 44, Source 45 |
| Frameworks, models, and clouds supported | Runtime works with custom frameworks and open-source ones such as CrewAI, LangGraph, and Strands Agents.Source 1 Registry can also list agents built on other providers.Source 27 | Registration records each agent’s platform, or OTHER.Source 13 Workday names Google Gemini Enterprise as an outside assistant able to call its Self-Service Agent.Source 44 |
| Operations | ||
| Deployment options and data residency | AWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.Source 1, Source 46 | Set up in each Workday tenant.Source 3 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.Source 17 Self-hosting: not publicly documented. |
| Compliance attestations | AWS lists AgentCore as FedRAMP (Class C and Class D) compliant.Source 37, Source 38 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.Source 20, Source 37 | Workday says its SOC 2 report covers Workday Enterprise Products, and ISO 42001 covers Workday Platform.Source 39 Coverage of ASOR is not publicly documented. |
| Support and SLA | AWS says the Amazon Bedrock SLA applies to AgentCore.Source 27 Basic Support is included for all AWS customers.Source 47 | Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.Source 48 An ASOR uptime SLA is not publicly documented. |
| Time and effort to get running | AWS’s quickstart uses the AgentCore CLI to scaffold, test, deploy, and invoke one agent.Source 24 It needs an AWS account and Node.js 20 or later.Source 24 | Enable the ASOR functional area and set its security policies.Source 3 Registering an external agent includes finding the IDs of the Workday APIs it will use.Source 18 |
| Pricing model and public prices | Consumption-based per feature, with no minimum fee.Source 19 AWS Agent Registry has a monthly free tier; a Policy authorization request costs $0.000025.Source 19 | No additional specific SKU for ASOR.Source 2 Workday-built agents in production need a Flex Credits policy opt-in.Source 2 A credit’s price is not publicly documented. |
| Building | ||
| Agent building tools | Write the agent loop in Python with a framework such as Strands, LangGraph, or Google ADK and deploy it to Runtime, or use the managed Harness.Source 1, Source 24 | You provide an external agent’s definition through an API.Source 2 Workday announced the low-code Flowise Agent Builder for its separate Workday Build in 2025.Source 25 |
| Model access | Model-agnostic, AWS says: models in or outside Amazon Bedrock, including OpenAI, Gemini, Claude, Nova, Llama, and Mistral.Source 27 | Workday’s AI agents use large language models.Source 2 Which models ASOR supports or includes is not publicly documented. |
| Integrations and ecosystem | Gateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import AWS Partner tools bought in AWS Marketplace.Source 22, Source 27 | In February 2026, Workday said more than 65 partners were connecting agents to ASOR.Source 21 Workday said partner agents reached Workday Marketplace in June 2025.Source 14 |
Which to choose
Choose Amazon Bedrock AgentCore if
- You want to build, deploy, and run agents on AWS, with frameworks such as LangGraph, CrewAI, or Strands Agents.Source 1
- You want model choice in or outside Amazon Bedrock: AWS names OpenAI, Gemini, Claude, Nova, Llama, and Mistral.Source 27
- You want one approved catalog of agents, MCP servers, and tools, whether they run on AWS, on premises, or in other clouds.Source 1, Source 6
- You want each tool call through a gateway checked against policies written in natural language or Cedar.Source 4
Choose Workday Agent System of Record if
- Your agents mostly work in Workday, and each should have a unique Workday identity under your existing security policies and groups.Source 2, Source 5, Source 9
- You want an agent acting for a user limited to what both may do, with audit entries naming both.Source 9
- You want Workday-built, partner-built, and self-built agents listed with their status in one Agent Management Hub.Source 2
- You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR itself.Source 2, Source 3
Questions buyers ask
Can Workday Agent System of Record manage agents built outside Workday?
Yes: the ASOR API defines and registers an external agent in one call, and the Agent Management Hub manages self-built and partner-built agents.Source 2, Source 18 Some agents, including those for HiredScore and Evisort, are not part of ASOR, and per-agent analytics reports cover Workday-built agents only.Source 2
How is each one priced?
AgentCore bills each feature by use; Runtime v1 CPU, for example, is $0.0895 per vCPU-hour.Source 19 ASOR needs no additional specific SKU.Source 2 Workday offers complimentary Flex Credits to explore agents in production and free non-production testing.Source 49 A credit’s price is not publicly documented.
Do they support MCP and A2A?
AgentCore Runtime can host MCP and A2A servers; Gateway supports four MCP versions for MCP targets.Source 42, Source 50 Workday bases external agent registration on the A2A Agent Card, lists MCP as a tool type, and outside assistants can call its Self-Service Agent over A2A.Source 13, Source 44, Source 45
Can either one connect agents across companies?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
55 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) Back:abcdefghijklmnopq
Source 2: About Workday Agents (Workday Administrator Guide) Back:abcdefghijklmnopqrstuvwxyz27282930
Source 3: Set Up Agent System of Record (Workday Administrator Guide) Back:abcdefghi
Source 4: Policy in Amazon Bedrock AgentCore: Control Agent Interactions Back:abcdefgh
Source 5: Setup Considerations: Agent Security (Workday Administrator Guide) Back:abcdef
Source 6: AWS Agent Registry: Discover and manage agents, tools, and resources Back:abcdef
Source 7: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity Back:abcdef
Source 9: Concept: Agent Security (Workday Administrator Guide) Back:abcdefghijkl
Source 10: Key capabilities - AWS Agent Registry Back:abcdef
Source 11: FAQ: Agent Security (Workday Administrator Guide) Back:abc
Source 12: Supported record types and descriptors - AWS Agent Registry Back to text
Source 13: ASOR API Documentation v1.2 (Workday/asor on GitHub) Back:abcdefgh
Source 14: Workday Announces New AI Agent Partner Network and Agent Gateway Back:ab
Source 15: HTTP passthrough targets - AgentCore Gateway Back:ab
Source 16: Sharing a registry across accounts with AWS RAM Back:abcdef
Source 17: Concept: Workday Agent Gateway (Workday Administrator Guide) Back:abcde
Source 18: Register External Agents (Workday Administrator Guide) Back:abc
Source 20: Release notes - Amazon Bedrock AgentCore Back:abcd
Source 21: The Workday Agent System of Record Is Now Generally Available Back:abcd
Source 22: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models Back:ab
Source 23: Observe your agent applications on Amazon Bedrock AgentCore Observability Back to text
Source 24: Get started with Amazon Bedrock AgentCore Back:abcd
Source 25: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Back:ab
Source 28: Concept: Agent Interaction Policy (Workday Administrator Guide) Back to text
Source 29: Connect to private resources in your VPC using VPC Lattice Back to text
Source 30: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore Back to text
Source 31: Authenticate and authorize with Inbound Auth and Outbound Auth Back:ab
Source 33: Concept: External Agent ASU Considerations (Workday Administrator Guide) Back to text
Source 34: Resource-based policies for Amazon Bedrock AgentCore Back:ab
Source 35: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail Back:ab
Source 36: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore Back:ab
Source 37: Compliance validation for Amazon Bedrock AgentCore Back:abc
Source 38: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services Back:ab
Source 40: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Back to text
Source 41: Concepts and terminology - AWS Agent Registry Back to text
Source 42: Understand the AgentCore Runtime service contract Back:ab
Source 43: Supported targets for Amazon Bedrock AgentCore gateways Back to text
Source 44: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Back:abc
Source 45: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Back:ab
Source 46: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations Back to text
Source 50: MCP servers targets - AgentCore Gateway Back to text