# Registry approval is not permission to run

[Journal](/journal/)

August 31, 2026 · [evidence](/journal/#evidence)



AWS Agent Registry makes approved resources discoverable. Runtime access remains a separate decision backed by separate credentials.

![Software record cards pass through a catalog approval machine while a separate key and lock control the execution rail.](/_astro/registry-approval-is-not-permission-to-run.CIpa_0I0_gyQ8i.avif)

AWS says [registry approval controls discovery](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). AWS says [a caller needs separate credentials to run the resource](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). That division is explicit enough to test.

AWS [released Agent Registry for general use on August 31, 2026](https://aws.amazon.com/about-aws/whats-new/2026/08/aws-agent-registry-generally-available/). AWS describes it as [a private, governed catalog and discovery layer for agents, tools, skills, MCP servers, and custom resources](https://aws.amazon.com/about-aws/whats-new/2026/08/aws-agent-registry-generally-available/).

A registry is a controlled list of available software. Lifecycle means the states from submission through retirement. Neither definition gives a catalog record authority over the software it describes.

## Five states control the record

AWS documents [five record states: `DRAFT`, `PENDING_APPROVAL`, `APPROVED`, `REJECTED`, and `DEPRECATED`](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/).

AWS assigns each state change to a named role:

1.  AWS says [a publisher creates or updates a record in `DRAFT`, then submits it into `PENDING_APPROVAL`](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/).
2.  AWS says [an approver approves or rejects the pending record](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/).
3.  AWS says [a curator moves an unneeded record into `DEPRECATED`](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/).

AWS also says [`auto_approve` can move a submitted record directly into `APPROVED`](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). An automated route changes who performs the approval step. It does not expand what approval means.

## Approval changes discovery

AWS says [only records approved by an administrator or curator appear in the discovery view](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). AWS says [draft, rejected, and shadow resources remain outside that view](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). Approval therefore decides what discovery returns.

AWS documentation describes the same boundary. AWS says [consumers search or browse the approved-record catalog to find resources](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/registry.html). A result establishes that the organization made the record available for discovery.

AWS says [discovery returns endpoint addresses and authorization details](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). AWS still requires [the developer to request access and receive separate endpoint credentials](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). AWS says [the caller uses those credentials to make authenticated calls to the resource](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/).

That sequence leaves two records to inspect. A registry record shows why the resource appeared. An access record shows why this caller could run it.

## Keep both decisions visible

A discovery test should check AWS’s rule that [only approved records appear in discovery](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). An access test should check AWS’s requirement that [a caller needs separate endpoint credentials to make authenticated calls](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/). One passing test says nothing about the other decision.

AWS supplies the public evidence for this analysis. AWS is neither a Muniment customer nor an endorser.

## Sources

1.  [AWS: Manage agents, tools and skills at scale with AWS Agent Registry](https://aws.amazon.com/blogs/machine-learning/manage-agents-tools-and-skills-at-scale-with-aws-agent-registry/) aws.amazon.com
2.  [AWS: AWS Agent Registry is now generally available](https://aws.amazon.com/about-aws/whats-new/2026/08/aws-agent-registry-generally-available/) aws.amazon.com
3.  [AWS Agent Registry documentation](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/registry.html) docs.aws.amazon.com
