Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Amazon Bedrock Managed Knowledge Base Dive Deep

Amazon Bedrock Managed Knowledge Base Dive Deep

Amazon Bedrock Managed Knowledge Base (BMKB) の Dive Deep Deck です。
BMKB は、機能が非常に多く、既存の Bedrock Knowledge Bases との差分 (PPTX対応, SharePoint からの取り込み, ACL awareness) も多いため、キャッチアップが非常に難しいです。

本資料では、 Bedrock Managed Knowledge Base の基礎や主要機能について解説しつつ、Enterprise で重要になる機能 (ユーザー毎の検索データの制御方法, MCP Tool 化時の注意点) についても解説しています。

Avatar for Renya Kujirada

Renya Kujirada

July 29, 2026

More Decks by Renya Kujirada

Other Decks in Technology

Transcript

  1. AI Agent Ready Data Platform Amazon Bedrock Managed Knowledge Base

    Dive Deep Renya Kujirada AI/ML Specialist Solutions Architect 2026/07/29 © 2026, Amazon Web © 2026, Services, Amazon Inc. or Web its Services, affiliates.Inc. All or rights its affiliates. reserved.All rights reserved.
  2. ⾃⼰紹介 鯨⽥ 連也 アマゾン ウェブ サービス ジャパン合同会社 スペシャリスト ソリューションアーキテクト, AI/ML

    前職 (NTT DATA) では、データサイエンティストとして、 深層学習モデル・AI Agent の開発に従事。 • 興味: AI Agent 開発, LLM 学習・推論 X: @recat_125 • 好きなサービス: Amazon Bedrock, Amazon SageMaker AI © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 2
  3. 発表の背景と⽬的 NYC Summit で公開された Bedrock Managed Knowledge Base は、機能が⾮常に多く、 既存の

    Bedrock Knowledge Bases との差分 (pptx対応, SharePoint からの取り込み, ACL awareness ,,,) も多いため、キャッチアップが難しい。 本発表では、 Bedrock Managed Knowledge Base の基礎や主要機能について解説し、 Enterprise で重要となる機能について Dive Deep する。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 3
  4. 発表のゴールとレベル • ゴール︓ Amazon Bedrock Managed Knowledge Base の基礎や各種機能を理解する •

    レベル︓L200 ~ L300 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 4
  5. アジェンダ • はじめに (NYC Summit でのアップデートの背景) • Amazon Bedrock Managed

    Knowledge Base (BMKB) の機能解説 • Dive Deep (ACL Awareness, MCP Tool) • まとめ © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 5
  6. Agent には適切なコンテキストが必要 Agent の基盤となる LLM の性能は⾶躍的に向上したが、アクセス可能なコンテキストが⽋落すると、 その真価を発揮できない。 社内サポートAgent リサーチAgent ⾦融アドバイザー

    社内⽂書へのアクセスが必要 学習データ以降の情報 (最新情報) へのアクセスが必要 リアルタイムな情報 (為替相場) へのアクセスが必要 Agent が社内・社外 (Web) の情報を取得可能な仕組みの整備が重要 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 7
  7. NYC Summit のアップデート (Agent のコンテキスト拡張) AgentCore に、組織内の知識 (Managed Knowledge Base)・Web

    の知識 (Web Search Tool) を Agent から検索できる機能が追加された。本発表では Managed Knowledge Base について Dive Deep する。 1 2 組織内の知識 Web の知識 Managed Knowledge Base Web Search Tool フルマネージドな RAG 最新の Web 情報を出典付きで取得 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 8
  8. NYC Summit のアップデート (Agent のコンテキスト拡張) AgentCore に、組織内の知識 (Managed Knowledge Base)・Web

    の知識 (Web Search Tool) を Agent から検索できる機能が追加された。本発表では Managed Knowledge Base について Dive Deep する。 1 2 組織内の知識 Web の知識 Managed Knowledge Base Web Search Tool フルマネージドな RAG 最新の Web 情報を出典付きで取得 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 9
  9. Bedrock Managed Knowledge Base (BMKB) の機能解説 © 2026, Amazon Web

    Services, Inc. or its affiliates. All rights reserved.
  10. エンタープライズにおける RAG 実現の困難さ RAG を実現する上で、検索精度だけでなく、コネクタ開発・パイプライン設計・インフラ運⽤・ セキュリティ・コストまで、数多くの意思決定と継続的な運⽤が必要。 どのコネクタを 構築・サポートすべき︖ ドキュメント種別ごとにどの パースとチャンキングの戦略

    を選ぶ︖ マルチテナンシーと アクセス制御はどう扱う︖ どのベクトルストアをプロビ ジョニングし、チューニング し、スケールさせる︖ プロトタイプから本番環境へ、 どう速く移⾏する︖ ⽉末のコストはいくらになる︖ © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 11
  11. Bedrock Managed Knowledge Base (BMKB) とは データソースを繋ぐだけで、ベクトルストアの構築からパース・埋め込み・インデックス化・検索・ リランキングなどをフルマネージドで実現可能な Bedrock Knowledge

    Bases の新タイプ。 Managed Knowledge Base データソース Amazon S3 パース SharePoint 等 チャンク 埋め込み インデッ クス化 ベクトルストア構築 検索 リランク Agent / アプリ 全てマネージドで実⾏ © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 12
  12. Managed Knowledge Base の主な機能 RAG パイプライン構築の容易性、⾼度な検索機能、本番環境に耐えうる機能 (MCP/o11y) を有する。 1 2

    3 シンプルなセットアップ 6種類のエンタープライズデータソースに直接接続。Smart Parsing 機能と マネージドなインフラを標準装備。 よりスマートな検索 Agentic Retrieval が複雑なマルチステップクエリを処理し、より⾼い精度な回答を 容易に⽣成。 本番環境対応 AgentCore とのネイティブ統合。オブザーバビリティとアクセス制御を初⽇から。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 13
  13. Managed Knowledge Base の主な機能 RAG パイプライン構築の容易性、⾼度な検索機能、本番環境に耐えうる機能 (MCP/o11y) を有する。 1 2

    3 シンプルなセットアップ 6種類のエンタープライズデータソースに直接接続。Smart Parsing 機能と マネージドなインフラを標準装備。 よりスマートな検索 Agentic Retrieval が複雑なマルチステップクエリを処理し、より⾼い精度な回答を 容易に⽣成。 本番環境対応 AgentCore とのネイティブ統合。オブザーバビリティとアクセス制御を初⽇から。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 14
  14. Native Connector 6 種類のネイティブコネクタを標準で搭載し、容易にエンタープライズデータに接続可能。 Amazon S3 IAM SharePoint Online Entra

    ID (App-Only) · OAuth2 Webクローラー 認証なし · Basic · Form · SAML Google Drive Service Account · OAuth2 カスタム KnowledgeBaseDocuments API Amazon Bedrock Knowledge Base ACL 対応 OneDrive Entra App ID · OAuth2 Confluence Cloud Basic · OAuth2 · Personal Token データ取り込みの設定ではなく、アプリケーション開発に時間を使う。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 16
  15. ACL awareness ユーザー毎に検索可能なドキュメントを制御する仕組み。データソース側のアクセス権限を BMKB への取り込み時に保持し、ユーザーが閲覧権限を持つ⽂書のみを検索の対象とすることが可能。 取り込み データコネクタ BMKB 取り込み •

    ドキュメント • ユーザー / グループ権限 ドキュメントチャンクの埋め込みにACL権限を付与 (ユーザー、グループ、フォルダ/ファイル単位) 検索 User 検索前フィルタリング リアルタイム ACL 検証 レスポンス ACLに基づき 関連チャンクを検出 データソース側の 最新の ACL を確認 ACLでフィルタされた データチャンクのみが返却 Doc A, B, C, D, E Doc A, B, C は許可 Doc D, E は不許可 Doc A, B, C • クエリ • ユーザーコンテキスト © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 取り込み時の ACL の陳腐化を考慮 (s3, Custom 以外対応) 17
  16. Smart Parsing PPTX, DOCX, XLSX, PDF などのドキュメントを、⾃動でパースしてチャンキング可能。 Advanced Indexing によりドキュメント中の図や、⾳声・動画ファイルも検索対象に。

    ドキュメント (PPTを含む) ⾳声 動画 テキストベース ドキュメント Smart Parsing パーサーの⾃動選択 ドキュメント種別ごとに最適な戦略を選択 出⼒をチャンキングに利⽤ ⾼精度な検索のためにデータをモデリング そのまま使える パースのためのプロンプト調整は不要 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 18
  17. 対応フォーマットと Advanced Indexing PDF や Office ⽂書などのテキスト系ドキュメントは標準で検索対象。Advanced Indexing を有効化 すると、⽂書中の図や、⾳声・動画ファイルまで検索対象が広がる。

    カテゴリ 拡張⼦ 標準インデックス Advanced Indexing ✓ テキスト ✓ ⽂書中の図・画像 ドキュメント .pdf / .doc / .docx / .ppt / .pptx テキスト系 .txt / .md / .html / .csv / .xls / .xlsx ✓ — ⾳声 .mp3 / .wav / .m4a / .flac / .ogg — ✓ 動画 .mp4 / .mov / .m4v — ✓ ※ Advanced Indexing は KB 作成時のオプション設定 (Content indexing) で有効化。最⼤ファイルサイズの上限も同時に設定可能。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 19
  18. Chunking / Embedding / Reranking RAG の精度を左右する Chunking, Embedding, Reranking

    は、全て AWS がマネージドで実⾏。 任意でチャンクサイズや利⽤するモデルを変更することも可能。 Managed Chunking Managed Embedding Managed Reranking 従来 : チャンクサイズの試⾏錯誤 従来 : 埋め込みモデルの⽐較検証 従来 : リランカーの追加・調整 任意で Bedrock の model を利⽤可能 任意で Bedrock の model を利⽤可能 任意でカスタマイズ可能 (固定サイズ/チャンキング無し) Managed の設定の場合、全て追加コストゼロ © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 20
  19. Managed Store Embeddings の保存先は AWS が管理するため、ストアの選定・プロビジョニング・監視が不要に なり、ワークロードに合わせて⾃動スケーリングも可能。 従来 : ベクトルストアを⾃前運⽤

    • ストアの選定 • プロビジョニング • スケーリング • 監視 アイドル時も固定費が発⽣ Managed Store(AWS 管理) $5 / GB / ⽉ 使った分だけの従量課⾦ 選定・プロビジョニング・監視が不要に インフラ運⽤者がいないチームでも RAG を実現可能 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. https://aws.amazon.com/bedrock/pricing/ 21
  20. Managed Knowledge Base の主な機能 RAG パイプライン構築の容易性、⾼度な検索機能、本番環境に耐えうる機能 (MCP/o11y) を有する。 1 2

    3 シンプルなセットアップ 6種類のエンタープライズデータソースに直接接続。Smart Parsing 機能と マネージドなインフラを標準装備。 よりスマートな検索 Agentic Retrieval が複雑なマルチステップクエリを処理し、より⾼い精度な回答を 容易に⽣成。 本番環境対応 AgentCore とのネイティブ統合。オブザーバビリティとアクセス制御を初⽇から。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 22
  21. 2 種類の検索 API 通常のハイブリッド検索を⾏う Retrieve API と、 Agent 型ワークフローによる⾼度な検索を⾏う AgenticRetrieveStream

    API を提供しており、検索クエリの複雑度に応じて使い分けが可能。 Retrieve API AgenticRetrieveStream API クエリ クエリ Agent 型ワークフロー Amazon Bedrock Knowledge Base 最⼤5つのKBを対象 レスポンス チャンク マネージドモデル または Bedrockモデル レスポンス⽣成 Chunk 1 Chunk 3 Chunk 1 Chunk 3 Chunk 2 Chunk 4 Chunk 2 Chunk 4 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. モデルのオーケストレーションと レスポンス⽣成を裏側で実⾏: または 関連チャンクをコンテキス トとしてモデルがクエリに 回答 24
  22. Retrieve API 単⼀ナレッジベースへのハイブリッド検索が可能。1 回の API 呼び出しで、ランク付けされた関連 チャンクを最⼩のレイテンシで返却する。 Retrieve API クエリ

    シンプルかつ⾼速 低レイテンシ シングルホップ検索、推論オーバーヘッドなし 単⼀ナレッジベース クエリごとに1つのKBを対象にし、焦点を絞った結果を取得 Amazon Bedrock Knowledge Base レスポンス Chunk 1 Chunk 3 Chunk 2 Chunk 4 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. シンプルな統合 1回のAPI呼び出しで、チャンク数とフィルタを設定可能 メタデータフィルタリング カスタムメタデータ属性で結果をフィルタ 25
  23. AgenticRetrieveStream API Agentic RAG をマネージドで実現する API 。 Agent 型ワークフローが複雑な (複数意図を持つ)

    クエリを分解し、複数のナレッジベースを横断検索し、最良の回答が⾒つかるまで反復する。 AgenticRetrieveStream API インテリジェントかつ徹底的 クエリ マルチステップ推論 複雑な質問を⾃動的にサブクエリへ分解 Agent 型ワークフロー モデルのオーケストレーションと レスポンス⽣成を裏側で実⾏: マネージドモデル または Bedrockモデル 最⼤5つのKBを対象 レスポンス⽣成 チャンク Chunk 1 Chunk 3 Chunk 2 Chunk 4 または 関連チャンクをコンテキス トとしてモデルがクエリに 回答 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 複数ナレッジベースの横断検索 1回の呼び出しで複数のナレッジベースを検索 反復的な改善 信頼度のしきい値を満たすまで再クエリ・再ランク レスポンス⽣成 チャンク、または取得コンテキストで⽣成した回答を返却 26
  24. AgenticRetrieveStream API の仕組み Planning を⾏いクエリをサブクエリに分解した後、複数の KB を横断して並列検索を⾏い、検索結果 を評価する。⼗分な情報が得られていない場合は検索を繰り返す。 クエリ Planning

    サブクエリに分解 直前に SpeculativeRetrieval (投機的検索) を⾏い、 Planning の材料にする 並列検索 複数 KB を並列・横断 検索結果 の評価 No — 検索を反復 (デフォルトでは最⼤5回まで) Yes • • 検索結果を返却 チャンク LLMによるレスポンス • generateResponse=False を 設定すと検索結果のみ返却 • 検索結果の重複は⾃動で削除 従来の RetrieveAndGenerate は Managed KB ⾮対応。この AgenticRetrieveStream が後継にあたる © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 27 https://aws.amazon.com/jp/blogs/machine-learning/agentic-retrieval-for-amazon-bedrock-managed-knowledge-base/ https://aws.amazon.com/jp/blogs/machine-learning/build-enterprise-search-for-agents-with-amazon-bedrock-managed-knowledge-base/
  25. Managed Knowledge Base の主な機能 RAG パイプライン構築の容易性、⾼度な検索機能、本番環境に耐えうる機能 (MCP/o11y) を有する。 1 2

    3 シンプルなセットアップ 6種類のエンタープライズデータソースに直接接続。Smart Parsing 機能と マネージドなインフラを標準装備。 よりスマートな検索 Agentic Retrieval が複雑なマルチステップクエリを処理し、より⾼い精度な回答を 容易に⽣成。 本番環境対応 AgentCore とのネイティブ統合。オブザーバビリティとアクセス制御を初⽇から。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 28
  26. AgentCore Gateway との Native 統合 AgentCore Gateway との統合により、MCP Server として

    Agent から容易に BMKB を利⽤可能。 1 ツールの取得と呼び出し Agent または MCP Client © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. AgentCore Gateway Knowledge Bases Target インバウンド認証 & アウトバウンド認証 2 連携 Amazon Bedrock Managed Knowledge Base(s) 30
  27. AgentCore Gateway との Native 統合 AgentCore Gateway との統合により、MCP Server として

    Agent から容易に BMKB を利⽤可能。 AgentCore Policy や AgentCore Observability と連携し、アクセス制御やトレースログ記録が可能。 AgentCore Gateway 1 ツールの取得と呼び出し Agent または MCP Client 4 連携 Knowledge Bases Target インバウンド認証 & アウトバウンド認証 2 定義済みポリシーに 照らして評価 3 Amazon Bedrock Managed Knowledge Base(s) オブ ザー バビ リテ 承認または拒否 ィ 誰が/いつ/何を (ABAC) AgentCore Policy Policy Engine オブザーバビリティ AgentCore Observability Policy A Policy B © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 31
  28. 従来の Bedrock Knowledge Bases との差異 Agent との親和性が⾼くなった。(AgentCore Gateway 統合、 AgenticRetrieveStream

    API) ベクトルストアの選定・運⽤が AWS 側に移り、料⾦はアイドル固定費ゼロの完全従量制に。 MANAGED KB SELF-MANAGED KB コネクター (ACL対応) ネイティブ6種 S3のみ ベクトルストア フルマネージド ユーザーが設定(OpenSearch、Aurora等) スケーリング ⾃動 ユーザーが容量を管理 ハイブリッド検索 常時有効(キーワード + セマンティック) ストアの設定に依存 検索API Retrieve + AgenticRetrieveStream Retrieve + RetrieveAndGenerate AgentCore Gateway ネイティブターゲットタイプ ⼿動で統合 バックアップと運⽤ AWSが管理 ユーザーが管理 料⾦ 使った分だけ⽀払い DBインフラコスト + 使⽤量 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 32
  29. Bedrock Managed Knowledge Base Dive Deep © 2026, Amazon Web

    Services, Inc. or its affiliates. All rights reserved. 33
  30. ACL awareness © 2026, Amazon Web Services, Inc. or its

    affiliates. All rights reserved. 34
  31. ユーザー毎に検索結果を制御する⽅法 (S3 source) 検索結果の絞り込み⽅法は 3 種類。「誰に⾒せるか」を制御する ACL (2種類) と、 「どの属性の⽂書を返すか」のメタデータフィルタリングが利⽤可能。

    ⽅法 定義場所 粒度 クエリ時の指定 ① global ACL ファイル 単⼀の JSON ファイル (aclConfiguration で S3 URI を指定) プレフィックス (フォルダ) 単位 userContext.userId (email) ② ⽂書毎のメタデータファイル (ACL) <ファイル名>.metadata.json の accessControlList ⽂書単位 userContext.userId (email) ③ メタデータフィルタリング <ファイル名>.metadata.json の metadataAttributes 属性値による 動的な絞り込み retrievalConfiguration. managedSearchConfiguration.filter (部署などのattribute) ※ ACL の利⽤にはデータソースの aclEnabled: true が必要 (作成後の変更は不可)。ACL 有効データソースは userContext なしのクエリに⼀切返らず、ACL 未定義 の⽂書は取り込み対象外。DENY は常に ALLOW より優先 (fail-closed 設計)。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 35
  32. ① global ACL ファイル (プレフィックス単位) S3 keyPrefix (フォルダ) 単位でアクセス許可するユーザーを⼀括定義。データソース接続時に aclEnabled:

    true と ACL ファイルの S3 URI を指定し、ACL ファイル本体に keyPrefix 毎の許可を列挙。 acl/global-acl.json [ CreateDataSource API の connectorParameters { { ] • • "keyPrefix": "s3://bucket/docs/finance/", "aclEntries": [ { "Name": "[email protected]", "Type": "USER", "Access": "ALLOW" } ] }, { "keyPrefix": "s3://bucket/docs/hr/", "aclEntries": [ { "Name": "[email protected]", "Type": "USER", "Access": "ALLOW" } ] } } "knowledgeBaseId": "<KB_ID>", "name": "...", "dataSourceConfiguration": { "type": "MANAGED_KNOWLEDGE_BASE_CONNECTOR", "managedKnowledgeBaseConnectorConfiguration": { "connectorParameters": { "type": "S3", "aclEnabled": true, "connectionConfiguration": { "bucketName": "your-bucket" }, "aclConfiguration": { "globalAccessControlListS3Uri": "s3://your-bucket/acl/global-acl.json" } }}} keyPrefix はフォルダまたは個別⽂書の絶対 S3 URI。重複時はマージされ、いずれかで ALLOW されれば許可 (具体的な⽅が優先、ではない) ACL ファイルはコンテンツと同⼀バケットに配置。ACL エントリのない⽂書は取り込まれない (ジョブは COMPLETE のまま部分失敗になる) © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 36
  33. ② ⽂書毎のメタデータファイル (⽂書単位) ⽂書と同じ S3 パスに <ファイル名>.metadata.json を置き、 accessControlList にて⽂書単位で許可

    ユーザーを定義。権限変更時の再インデックスが該当⽂書のみで済むためインデックス更新が早い。 dept-a-plan.txt.metadata.json { } "metadataAttributes": { "department": "d001", "year": 2026 }, "accessControlList": [ { "Name": "[email protected]", "Type": "USER", "Access": "ALLOW" }, { "Name": "[email protected]", "Type": "USER", "Access": "DENY" } ] © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. • エントリは Name (email) / Type (USER のみ) / Access (ALLOW・DENY)。DENY が常に優先 • aclEnabled: true のデータソースが前提。userContext なし のクエリには返らない • metadataAttributes には任意の属性も定義でき、 メタデータフィルタリング (次⾴) に利⽤ • global ACL と併存時は⽂書毎メタデータが優先。 37
  34. ③ メタデータフィルタリング ⽂書と同じ S3 パスの <ファイル名>.metadata.json の metadataAttributes に、⽂字列・数値の属性 を任意に定義。クエリ時の

    filter で属性による絞り込みが可能になる (指定⽅法は後述)。 dept-a-plan.txt.metadata.json { } "metadataAttributes": { "department": "d001", "year": 2026 }, "accessControlList": [ { "Name": "[email protected]", "Type": "USER", "Access": "ALLOW" } ] © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. • 属性は⽂字列・数値を任意に定義でき、⽂書単位のサイドカー で管理 (department や year など) • ACL (accessControlList) と同じ metadata.json に同居できるが、 機能としては独⽴ • 予約メタデータはアンダースコア接頭辞 (_source_uri, _data_source_id 等) 38
  35. 検索時の UserContext 指定⽅法 Retrieve / AgenticRetrieveStream API 共通で、トップレベルの userContext.userId にユーザーの

    email を渡すと ACL を適⽤可能。userContext が持つフィールドは userId の 1 つだけ。 Retrieve API { } AgenticRetrieveStream API { "knowledgeBaseId": "KB12345678", "retrievalQuery": { "text": "A部⾨の事業計画の管理コードは︖" }, "userContext": { "userId": "[email protected]" } } • • "messages": [ { "role": "user", "content": { "text": "..." } } ], "retrievers": [ { "description": "部⾨別の事業計画・⼈事・財務", "configuration": { "knowledgeBase": { "knowledgeBaseId": "KB12345678" } } } ], "agenticRetrieveConfiguration": { ... }, "userContext": { "userId": "[email protected]" } userContext なしでは ACL 有効データソースの⽂書は⼀切返らない (エラーではなく 0 件)。ACL 無効データソースは誰にでも返り、全社公開⽂書 ⽤として同⼀ KB 内で共存できる ACL awareness is not authorization: Bedrock は渡された userId を信頼してフィルタするだけ。検証済み ID を渡す責任は呼び出し側にある © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 39
  36. 検索時の filter 指定 retrievalConfiguration.managedSearchConfiguration.filter に演算⼦で条件を指定。userContext と 併⽤すると、ACL と属性フィルタが独⽴した 2 つのゲートとして

    AND で適⽤される。 クエリ時のフィルタ指定 (Retrieve) response = client.retrieve( knowledgeBaseId=kb_id, retrievalQuery={"text": "A部⾨の事業計画"}, retrievalConfiguration={ "managedSearchConfiguration": { "numberOfResults": 10, "filter": {"andAll": [ {"equals": {"key": "department", "value": "d001"}}, {"greaterThan": {"key": "year", "value": 2020}}, ]}, } }, userContext={"userId": "[email protected]"}, ) © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. • startsWith / stringContains は⾮対応。equals / andAll / in / greaterThan 等は利⽤可 • userContext と filter の両指定で ACL と属性フィルタ が AND 適⽤ (どちらか優先ではない) • AgenticRetrieveStream では retrievers[].configuration.knowledgeBase. retrievalOverrides.filter で KB 毎に指定する 40
  37. AgentCore Gateway との連携 (MCP Tool 化) © 2026, Amazon Web

    Services, Inc. or its affiliates. All rights reserved. 41
  38. MCP Tool 化した際の Tool Schema Knowledge Bases Target を作成すると 2

    つの検索 API に対応する MCP Tool が公開される。 既定の Tool の引数は検索クエリのみで、userContext 等は Tool Schema には現れない。 ツール名 機能 Tool の引数 管理者が指定 (必須) <ターゲット名>___Retrieve 単発のハイブリッド検索。関連 チャンク (retrievalResults) を返却 retrievalQuery.text (検索クエリ) • knowledgeBaseId (単⼀ KB) <ターゲット名> ___AgenticRetrieveStream 検索計画・複数回検索・引⽤付き のLLM の回答⽣成 messages (array) (各要素は role: user | assistant と content.text が必須) • • retrievers (最⼤ 5 つの KB) agenticRetrieveConfiguration (利⽤するLLM / Rerank Model ) ※ retrievers の description は内部プランナーがサブクエリのルーティング先 KB を選ぶ判断材料になるため、具体的な記述が必要。 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 42
  39. AgenticRetrieveStream Tool の messages 指定 messages は role (user |

    assistant) と content.text を持つメッセージの配列 (最⼩ 1 件)。 単発の質問なら user メッセージ 1 件、⽂脈が必要なら会話履歴ごと渡す。 単発の質問 (最⼩の呼び出し) { } 会話履歴を含む呼び出し (⽂脈を踏まえた検索) { "method": "tools/call", "params": { "name": "kb___AgenticRetrieveStream", "arguments": { "messages": [ { "role": "user", "content": { "text": "B部⾨の事業計画の 管理コードは︖" } } ] } } } • • "method": "tools/call", "params": { "name": "kb___AgenticRetrieveStream", "arguments": { "messages": [ { "role": "user", "content": { "text": "経費精算の規程は︖" } }, { "role": "assistant", "content": { "text": "経費精算は…(前回の回答)" } }, { "role": "user", "content": { "text": "宿泊費の上限は︖" } } ] } } role と content は必須。role は user | assistant の 2 値 (公式スキーマの enum)、content は { "text": string } 会話形式なのは内部プランナーが会話全体から検索計画を⽴てるため。履歴を含めると⽂脈を踏まえたサブクエリになる © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 43
  40. MCP Tool 経由で UserContext や検索数の指定⽅法 Gateway Target 作成時、parameterOverrides で visible:

    true にしたフィールドのみ、Tool の引数で 指定可能になる。 ターゲット設定 (管理者側: CreateGatewayTarget API) { Tool 呼び出し (MCP Client側: tools/call の arguments) { "name": "Retrieve", "parameterValues": { // 固定値 "knowledgeBaseId": "<KB_ID>", "retrievalConfiguration": { "managedSearchConfiguration": { "numberOfResults": 10 } } }, "parameterOverrides": [ // Agent に公開 { "path": "$.retrievalConfiguration .managedSearchConfiguration.numberOfResults", "visible": true }, { "path": "$.userContext", "visible": true } ] } "name": "kb___Retrieve", "arguments": { "retrievalQuery": { "text": "A部⾨の事業計画は︖" }, "retrievalConfiguration": { “managedSearchConfiguration”: { “numberOfResults”: 2 } }, // 指定 "userContext": { “userId”: “[email protected]” } // 指定 } } • • 検索クエリは既定で公開済み。parameterOverrides で追加公開できるのは検索数 / filter / userContext 等。knowledgeBaseId / retrievers は管理者固定のみ Gateway は認証ユーザーと userContext の整合を検証しない。LLM に委ねず Gateway Interceptor や Agent の Hook 等の信頼できるコードで強制上書きする © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 44
  41. まとめ Managed Knowledge Base は、データソースを繋ぐだけで動くフルマネージド RAG。 インフラの管理をマネージドに、ユーザー権限を考慮した⾼度な検索を Agent に組み込める。 機能の柱

    ポイント ① シンプルなセットアップ • • • • ② よりスマートな検索 • Retrieve API • AgenticRetrieveStream API ③ 本番環境対応 • AgentCore Gateway ネイティブ統合 (MCP ツール化) • AgentCore Policy / Observability 連携 Native Connector (6 種類) ACL awareness Smart Parsing / Advanced Indexing Managed Chunking / Embedding / Reranking / Store © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 46
  42. Thank you! Renya Kujirada X: @recat_125 © 2026, Amazon Web

    Services, Inc. or its affiliates. All rights reserved. © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  43. クォータ(制限) クォータ デフォルト値 アカウント・リージョンあたりの最⼤マネージドナレッジベース数 10000 ナレッジベースあたりの最⼤データソース数 200 ナレッジベースあたりの最⼤同時取り込みジョブ数 50 ナレッジベースあたりの最⼤⽣データストレージ

    10 TB Retrieve または AgenticRetrieveStream リクエストあたりの最⼤クエリ⼊⼒⽂字数(英⽂) 10000 Retrieve または AgenticRetrieveStream の毎分最⼤リクエスト数 300 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 51
  44. 埋め込みモデルの提供状況 バージニア 北部 オレゴン フランク フルト アイルランド シドニー マネージド埋め込みモデル ✅

    ✅ ✅ ✅ ✅ Amazon Nova Multimodal Embeddings 1.0 ✅ — — — — Titan Embeddings G1 - Text v1.2 ✅ ✅ ✅ — — Titan Text Embeddings V2 v2.0 ✅ ✅ ✅ ✅ ✅ Cohere Embed v4 ✅ ✅ ✅ ✅ ✅ Cohere Embed English v3 ✅ ✅ ✅ ✅ ✅ Cohere Embed Multilingual v3 ✅ ✅ ✅ ✅ ✅ モデル © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 52
  45. データ取り込みの料⾦ 取り込みパイプライン データコネクタ S3、Web、Confluenceなど → パース & チャンキング チャンキング、OCR、表 →

    埋め込み マネージドモデル(込み) → データストア マネージドインデックス ⽣データの取り込み1GBあたり⽉額$5 – 上記すべて込み オプション機能(利⽤時は各サービスの標準料⾦を別途適⽤。各料⾦ページ参照) Amazon Bedrock 埋め込みモデル © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 54
  46. Retrieve APIの料⾦ Retrieve API クエリ API 呼び出し1,000回あたり$1 追加コストなしで利⽤可能 ハイブリッド検索 Amazon

    Bedrock Knowledge Base レスポンス Chunk 1 Chunk 3 Chunk 2 Chunk 4 © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. マネージドリランカーモデル オプション機能(利⽤時は各サービスの標準料⾦を別途適⽤) Bedrock Reranker Bedrock Guardrails 55
  47. Agentic Retrieval APIの料⾦ Agentic Retrieval API クエリ エージェント型ワークフロー モデルのオーケストレーションと レスポンス⽣成を裏側で実⾏:

    マネージドモデル または Bedrockモデル 最⼤5つのKBを対象 マネージドモデル利⽤時 Amazon Bedrockモデル利⽤時 API 呼び出し 1,000回あたり$4 Bedrock LLMのパススルー料⾦ + + Retrieve API呼び出し 1,000回あたり$1 Retrieve API呼び出し 1,000回あたり$1 追加コストなしで利⽤可能 レスポンス⽣成 チャンク Chunk 1 Chunk 3 Chunk 2 Chunk 4 または 関連チャンクをコンテキス トとしてモデルがクエリに 回答 ハイブリッド検索 マネージドリランカーモデル オプション機能(利⽤時は各サービスの標準料⾦を別途適⽤) Bedrock Reranker Bedrock Guardrails © 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved. 56