Publicado el — Deja un comentario

IA en el trabajo: cómo los equipos de agentes humanos remodelarán su fuerza laboral

abril 25, 2025

IA en el trabajo: cómo los equipos de agentes humanos remodelarán su fuerza laboral

¿Qué sucede cuando los líderes pueden agregar inteligencia a su organización sin agregar personal?

Gráfico de barras con línea superpuesta, formas geométricas y documentos con gráficos.

Por: Jared Spataro, CMO de IA en el Trabajo de Microsoft.

Los agentes de IA ya se han comenzado a convertir en socios poderosos en el trabajo del conocimiento. Ahora, a medida que más empresas los adoptan, están preparados para remodelar la dinámica de trabajo. En esta nueva realidad, los líderes podrán, por primera vez, agregar inteligencia a su organización, que alguna vez fue un recurso escaso y costoso, sin aumentar el número de empleados. Pronto, todas las empresas operarán con equipos colaborativos de humanos y agentes.

Esta evolución requerirá que cada líder redefina la forma en que piensa sobre sus equipos. Los agentes serán un verdadero multiplicador de fuerza: todos, desde los pasantes hasta la alta dirección, se convertirán en «jefes de agentes» que supervisarán su propia constelación de agentes que impulsan los procesos comerciales. Un nuevo imperativo será encontrar la proporción óptima de humanos y agentes para cualquier tarea o proyecto en el que estén trabajando sus equipos.

El resultado: donde antes dependías de la inteligencia humana, puedes considerar de manera estratégica si un agente debe encargarse de la tarea, lo que desbloquea la escala como nunca.

Los equipos mejorados con IA superan a los tradicionales

En marzo, un notable estudio de campo realizado por Harvard y la Escuela Wharton de la Universidad de Pensilvania mostró cómo la IA puede aumentar el rendimiento de individuos y equipos. El experimento, descrito en un artículo titulado «The Cybernetic Teammate«, involucró a casi 800 empleados de P&G, la compañía global de bienes de consumo. A todos los empleados se les pidió que trabajaran en desafíos de innovación de productos, pero a algunos de ellos se les dio IA y a otros no.  

El estudio mostró que las personas con IA se desempeñaron tan bien como los equipos sin ella. Los equipos que utilizaron IA tenían, de manera significativa, más probabilidades de producir ideas de primer nivel que cualquier otro grupo. El mismo estudio mostró cómo la IA rompe los silos: sin IA, los profesionales de investigación y desarrollo sugirieron soluciones más técnicas, mientras que los profesionales comerciales también se apoyaron en su propia experiencia. Los usuarios de IA produjeron soluciones equilibradas, sin importar sus antecedentes. 

Estos beneficios abordan una realidad crítica. En tiempos de incertidumbre económica, los líderes se enfrentan a la presión de impulsar el crecimiento con la plantilla actual o reducida. Agregar agentes al equipo permitirá a los empleados transferir parte de su trabajo rutinario, para aliviar parte de la presión y permitiéndoles concentrarse en tareas de mayor valor.

Cómo es la colaboración entre humanos y agentes

La incorporación de agentes a la mezcla promete una nueva dinámica en la forma en que operan las personas, con efectos dominó para los equipos. Digamos que se enteran de que un cliente importante piensa en irse. Pueden recurrir a un agente para que se adentre en los datos y analice con rapidez lo que podría impulsar su decisión, en lugar de apartar a sus colegas humanos de lo que sea que trabajen para investigar.

Los agentes pueden investigar por ustedes, proporcionar experiencia que no tienen o codificar por ustedes. En la empresa del futuro, cada empleado (y cada equipo) gestionará un grupo de ellos, y el número exacto variará en función de sus objetivos y preferencias. He comenzado a ver que este patrón emerge en mi equipo. Alex Farach, un científico de datos e investigador, está inmerso en un gran proyecto y utiliza tres agentes para que lo ayuden. Un agente se conecta a Internet todos los días y recoge nuevas investigaciones relevantes, otro ayuda con el análisis estadístico y un tercero redacta informes detallados que lo ayudan a conectar los puntos.

El trío de agentes personalizados ayuda a Alex a ponerse al día más rápido con las últimas investigaciones y a dedicar menos tiempo a la codificación relacionada con el análisis de datos. Y no es solo Alex quien se vuelve más efectivo: esta colaboración entre humanos y agentes produce información y resultados que benefician a mi equipo en general.

Gestionar una nueva dinámica de equipo

Es pronto y la mayoría de los empleados no crean de forma proactiva equipos de agentes que les ayuden. Los gerentes no pueden contar con que los empleados individuales hagan este cambio por su cuenta. Deben ser intencionales y estratégicos a la hora de agregar mano de obra digital a sus equipos. Concéntrense en las áreas en las que los agentes pueden tener un impacto inmediato y sustancial en su negocio, creen esos agentes e impleméntenlos en su gente, junto con la capacitación que necesitan para trabajar con agentes y nuevos flujos de trabajo. Y, lo que es más importante, compartir los resultados para que los empleados de toda la organización puedan aprender.

En el futuro, tendrán que empezar a considerar una nueva métrica: la relación humano-agente. ¿Cuál es el equilibrio ideal para desbloquear la productividad? Esperamos que la proporción varíe según la tarea, el proceso y la industria, pero en cada contexto será fundamental encontrar la combinación adecuada de trabajo digital y juicio humano. Si se equivocan, podrían perderse todo el valor de la IA o añadir el agobio de la IA a los retos laborales de sus empleados. Alcancen el punto óptimo y desbloquean el tipo de rendimiento demostrado en el estudio de P&G.

El panorama general: el impacto organizacional

Si son una empresa nueva que  empieza desde cero, tienen la ventaja de diseñar sus procesos en torno a equipos de agentes humanos desde cero. Las empresas establecidas, por su parte, se enfrentan al reto de reinventar, en lugar de limitarse a adaptar, procesos enteros para aprovechar lo que ofrece la IA. Y los empleados necesitarán mejorar sus habilidades para aprovechar al máximo su asociación con los agentes. 

También tendrán que redefinir las funciones y responsabilidades. Es posible que necesiten nuevos roles para supervisar los recursos de agentes: seguimiento del rendimiento, liderazgo en la implementación y supervisión del equilibrio entre humanos y agentes. En un mercado laboral muy dinámico, los empleados y líderes que emergen como «jefes agentes» efectivos es probable que obtengan una ventaja.

Muchos líderes me dicen que se les pide que hagan más con menos. En un contexto económico difícil, los agentes pueden aliviar parte de la presión sobre los seres humanos. Al incorporar agentes, pueden apoyar a sus empleados y crear de manera simultánea una organización escalable y adaptable a un nivel infinito, y comenzar a construir la empresa del futuro.

Para obtener más información sobre la IA y el futuro del trabajo, suscríbanse a este boletín.

The post IA en el trabajo: cómo los equipos de agentes humanos remodelarán su fuerza laboral appeared first on Source LATAM.

 

​The post IA en el trabajo: cómo los equipos de agentes humanos remodelarán su fuerza laboral appeared first on Source LATAM.  

Publicado el — Deja un comentario

AWS Resource Explorer now supports AWS PrivateLink

AWS Resource Explorer now supports AWS PrivateLink in all commercial AWS Regions, allowing you to search for and discover your AWS resources within your Amazon Virtual Private Cloud (VPC) without traversing the public internet.

With AWS Resource Explorer you can search for and discover your AWS resources across AWS Regions and accounts in your organization, either using the AWS Resource Explorer console, the AWS Command Line Interface (AWS CLI), the AWS SDKs, or the unified search bar from wherever you are in the AWS Management Console.

For more information about the AWS Regions where AWS Resource Explorer is available, see the AWS Region table.

To turn on AWS Resource Explorer, visit the AWS Resource Explorer console. Read about getting started in our AWS Resource Explorer documentation, or explore the AWS Resource Explorer product page.
 

 

​AWS Resource Explorer now supports AWS PrivateLink in all commercial AWS Regions, allowing you to search for and discover your AWS resources within your Amazon Virtual Private Cloud (VPC) without traversing the public internet. With AWS Resource Explorer you can search for and discover your AWS resources across AWS Regions and accounts in your organization, either using the AWS Resource Explorer console, the AWS Command Line Interface (AWS CLI), the AWS SDKs, or the unified search bar from wherever you are in the AWS Management Console. For more information about the AWS Regions where AWS Resource Explorer is available, see the AWS Region table. To turn on AWS Resource Explorer, visit the AWS Resource Explorer console. Read about getting started in our AWS Resource Explorer documentation, or explore the AWS Resource Explorer product page.    

Publicado el — Deja un comentario

Amazon Q Developer operational investigations (preview) now available in additional regions

Starting today, Amazon Q Developer operational investigations is available in preview in 11 additional regions. With this launch, Amazon Q Developer operational investigations is now available in US East (N. Virginia), US East (Ohio), US West (Oregon), Europe (Ireland), Europe (Frankfurt), Europe (Stockholm), Europe (Spain), Asia Pacific (Tokyo), Asia Pacific (Hong Kong), Asia Pacific (Sydney), Asia Pacific (Singapore), and Asia Pacific (Mumbai).

Amazon Q Developer helps you accelerate operational investigations across your AWS environment in just a fraction of the time. With a deep understanding of your AWS cloud environment and resources, Amazon Q Developer looks for anomalies in your environment, surfaces related signals for you to explore, identifies potential root-cause hypotheses, and suggests next steps to help you remediate issues faster.

The new operational investigation capability within Amazon Q Developer is available at no additional cost during preview. To learn more, see getting started and best practices documentation.
 

 

​Starting today, Amazon Q Developer operational investigations is available in preview in 11 additional regions. With this launch, Amazon Q Developer operational investigations is now available in US East (N. Virginia), US East (Ohio), US West (Oregon), Europe (Ireland), Europe (Frankfurt), Europe (Stockholm), Europe (Spain), Asia Pacific (Tokyo), Asia Pacific (Hong Kong), Asia Pacific (Sydney), Asia Pacific (Singapore), and Asia Pacific (Mumbai). Amazon Q Developer helps you accelerate operational investigations across your AWS environment in just a fraction of the time. With a deep understanding of your AWS cloud environment and resources, Amazon Q Developer looks for anomalies in your environment, surfaces related signals for you to explore, identifies potential root-cause hypotheses, and suggests next steps to help you remediate issues faster. The new operational investigation capability within Amazon Q Developer is available at no additional cost during preview. To learn more, see getting started and best practices documentation.    

Publicado el — Deja un comentario

Amazon Bedrock Data Automation now supports modality controls, hyperlinks and larger documents

Amazon Bedrock Data Automation (BDA) now supports modality enablement, modality routing by file type, extraction of embedded hyperlinks when processing documents in Standard Output, and an increased overall document page limit of 3,000 pages. These new features give you more control over how your multimodal content is processed and improve BDA’s overall document extraction capabilities.

With Modality Enablement and Routing, you can configure which modalities (Document, Image, Audio, Video) should be enabled for a given project and manually specify the modality routing for specific file types. JPEG/JPG and PNG files can be processed as either Images or Documents based on your specific use case requirements. Similarly, MP4/M4V and MOV files can be processed as either video files or audio files, allowing you to choose the optimal processing path for your content.

Embedded Hyperlink Support enables BDA to detect and return embedded hyperlinks found in PDFs as part of the BDA standard output. This feature enhances the information extraction capabilities from documents, preserving valuable link references for applications such as knowledge bases, research tools, and content indexing systems.

Lastly, BDA now supports processing documents up to 3,000 pages per document, doubling the previous limit of 1,500 pages. This increased limit allows you to process larger documents without splitting them, simplifying workflows for enterprises dealing with long documents or document packets.

Amazon Bedrock Data Automation is generally available in the US West (Oregon) and US East (N. Virginia) AWS Regions.

To learn more, visit the Bedrock Data Automation page or view documentation.

 

​Amazon Bedrock Data Automation (BDA) now supports modality enablement, modality routing by file type, extraction of embedded hyperlinks when processing documents in Standard Output, and an increased overall document page limit of 3,000 pages. These new features give you more control over how your multimodal content is processed and improve BDA’s overall document extraction capabilities. With Modality Enablement and Routing, you can configure which modalities (Document, Image, Audio, Video) should be enabled for a given project and manually specify the modality routing for specific file types. JPEG/JPG and PNG files can be processed as either Images or Documents based on your specific use case requirements. Similarly, MP4/M4V and MOV files can be processed as either video files or audio files, allowing you to choose the optimal processing path for your content. Embedded Hyperlink Support enables BDA to detect and return embedded hyperlinks found in PDFs as part of the BDA standard output. This feature enhances the information extraction capabilities from documents, preserving valuable link references for applications such as knowledge bases, research tools, and content indexing systems. Lastly, BDA now supports processing documents up to 3,000 pages per document, doubling the previous limit of 1,500 pages. This increased limit allows you to process larger documents without splitting them, simplifying workflows for enterprises dealing with long documents or document packets. Amazon Bedrock Data Automation is generally available in the US West (Oregon) and US East (N. Virginia) AWS Regions. To learn more, visit the Bedrock Data Automation page or view documentation.  

Publicado el — Deja un comentario

Amazon EventBridge cross-account event delivery now in the AWS GovCloud (US) Regions

Starting today, in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions, you can now deliver events from an Amazon EventBridge Event Bus directly to AWS services in another account. Using multiple accounts can improve security and streamline business processes while reducing the overall cost and complexity of your architecture.

Amazon EventBridge Event Bus is a serverless event broker that enables you to create scalable event-driven applications by routing events between your own applications, third-party SaaS applications, and other AWS services. This launch allows you to directly target services in another account, without the need for additional infrastructure such as an intermediary EventBridge Event Bus or Lambda function, simplifying your architecture and reducing cost. For example, you can now route events from your EventBridge Event Bus directly to a different team’s SQS queue in a different account. The team receiving events does not need to learn about or maintain EventBridge resources and simply needs to grant IAM permissions to provide access to the queue. Events can be delivered cross-account to EventBridge targets that support resource-based IAM policies such as Amazon SQS, AWS Lambda, Amazon Kinesis Data Streams, Amazon SNS, and Amazon API Gateway.

In addition to the AWS GovCloud (US) Regions, direct delivery to cross-account targets is available in all commercial AWS Regions. To learn more, please read our blog post or visit our documentation. Pricing information is available on the EventBridge pricing page.
 

 

​Starting today, in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions, you can now deliver events from an Amazon EventBridge Event Bus directly to AWS services in another account. Using multiple accounts can improve security and streamline business processes while reducing the overall cost and complexity of your architecture. Amazon EventBridge Event Bus is a serverless event broker that enables you to create scalable event-driven applications by routing events between your own applications, third-party SaaS applications, and other AWS services. This launch allows you to directly target services in another account, without the need for additional infrastructure such as an intermediary EventBridge Event Bus or Lambda function, simplifying your architecture and reducing cost. For example, you can now route events from your EventBridge Event Bus directly to a different team’s SQS queue in a different account. The team receiving events does not need to learn about or maintain EventBridge resources and simply needs to grant IAM permissions to provide access to the queue. Events can be delivered cross-account to EventBridge targets that support resource-based IAM policies such as Amazon SQS, AWS Lambda, Amazon Kinesis Data Streams, Amazon SNS, and Amazon API Gateway. In addition to the AWS GovCloud (US) Regions, direct delivery to cross-account targets is available in all commercial AWS Regions. To learn more, please read our blog post or visit our documentation. Pricing information is available on the EventBridge pricing page.    

Publicado el — Deja un comentario

AWS Resource Groups now supports 160 more resource types

Today, AWS Resource Groups is adding support for an additional 160 resource types for tag-based Resource Groups. Customers can now use Resource Groups to group and manage resources from services such as AWS Code Catalyst and AWS Chatbot.

AWS Resource Groups enables you to model, manage and automate tasks on large numbers of AWS resources by using tags to logically group your resources. You can create logical collections of resources such as applications, projects, and cost centers, and manage them on dimensions such as cost, performance, and compliance in AWS services such as myApplications, AWS Systems Manager and Amazon CloudWatch.

Resource Groups expanded resource type coverage is available in all AWS Regions, including the AWS GovCloud (US) Regions. You can access AWS Resource Groups through the AWS Management Console, the AWS SDK APIs, and the AWS CLI.

For more information about grouping resources, see the AWS Resource Groups user guide and the list of supported resource types. To get started, visit AWS Resource Groups console.

 

​Today, AWS Resource Groups is adding support for an additional 160 resource types for tag-based Resource Groups. Customers can now use Resource Groups to group and manage resources from services such as AWS Code Catalyst and AWS Chatbot. AWS Resource Groups enables you to model, manage and automate tasks on large numbers of AWS resources by using tags to logically group your resources. You can create logical collections of resources such as applications, projects, and cost centers, and manage them on dimensions such as cost, performance, and compliance in AWS services such as myApplications, AWS Systems Manager and Amazon CloudWatch. Resource Groups expanded resource type coverage is available in all AWS Regions, including the AWS GovCloud (US) Regions. You can access AWS Resource Groups through the AWS Management Console, the AWS SDK APIs, and the AWS CLI. For more information about grouping resources, see the AWS Resource Groups user guide and the list of supported resource types. To get started, visit AWS Resource Groups console.  

Publicado el — Deja un comentario

Amazon Connect agent workspace expands capabilities for third-party applications, including contact-related actions

The Amazon Connect agent workspace now supports additional capabilities for third-party applications including the ability make outbound calls, accept, transfer, and clear contacts, and update agent status. These enhancements allow you to integrate applications that give agents more intuitive workflows. For example, agents can now initiate one-click outbound calls from a custom-built call history interface that presents their most recent customer interactions.

Third-party applications are available in the following AWS Regions: US East (N. Virginia), US-West (Oregon), Africa (Cape Town), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Canada (Central), Europe (Frankfurt), and Europe (London).

To learn more and get started, see our admin guide and developer guide.
 

 

​The Amazon Connect agent workspace now supports additional capabilities for third-party applications including the ability make outbound calls, accept, transfer, and clear contacts, and update agent status. These enhancements allow you to integrate applications that give agents more intuitive workflows. For example, agents can now initiate one-click outbound calls from a custom-built call history interface that presents their most recent customer interactions. Third-party applications are available in the following AWS Regions: US East (N. Virginia), US-West (Oregon), Africa (Cape Town), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Canada (Central), Europe (Frankfurt), and Europe (London). To learn more and get started, see our admin guide and developer guide.    

Publicado el — Deja un comentario

AWS AppSync Events now supports data source integrations for channel namespaces

Starting today, AWS AppSync Events, a fully managed service for serverless WebSocket APIs with full connection management, now supports data source integrations for channel namespaces. This new feature enables developers to associate AWS Lambda functions, Amazon DynamoDB tables, Amazon Aurora databases, and other data sources with channel namespace handlers to process published events and subscription requests. Developers can now connect directly to Lambda functions without writing code and leverage both request/response and event modes for synchronous and asynchronous operations.

With these new capabilities, developers can create sophisticated event processing workflows by transforming and filtering published events using Lambda functions, or save batches of events to DynamoDB using the new AppSyncJS batch utilities for DynamoDB. This integration enables complex interactive flows, making it easier for developers to build rich, real-time applications with features like data validation, event transformation, and persistent storage of events. By simplifying the architecture of real-time applications, this enhancement significantly reduces development time and operational overhead for front-end web and mobile development.

This feature is now available in all AWS Regions where AWS AppSync is offered, providing developers worldwide with access to these powerful new integration capabilities. Powertools for AWS Lambda new AppSync Events integration are also now available to easily write your Lambda functions.

To learn more about AWS AppSync Events and channel namespace integrations, visit the launch blog post, the AWS AppSync documentation, and the Powertools for Lambda documentation (TypeScript, Python, .NET). You can get started with these new features through the AWS AppSync console.

 

​Starting today, AWS AppSync Events, a fully managed service for serverless WebSocket APIs with full connection management, now supports data source integrations for channel namespaces. This new feature enables developers to associate AWS Lambda functions, Amazon DynamoDB tables, Amazon Aurora databases, and other data sources with channel namespace handlers to process published events and subscription requests. Developers can now connect directly to Lambda functions without writing code and leverage both request/response and event modes for synchronous and asynchronous operations. With these new capabilities, developers can create sophisticated event processing workflows by transforming and filtering published events using Lambda functions, or save batches of events to DynamoDB using the new AppSyncJS batch utilities for DynamoDB. This integration enables complex interactive flows, making it easier for developers to build rich, real-time applications with features like data validation, event transformation, and persistent storage of events. By simplifying the architecture of real-time applications, this enhancement significantly reduces development time and operational overhead for front-end web and mobile development. This feature is now available in all AWS Regions where AWS AppSync is offered, providing developers worldwide with access to these powerful new integration capabilities. Powertools for AWS Lambda new AppSync Events integration are also now available to easily write your Lambda functions. To learn more about AWS AppSync Events and channel namespace integrations, visit the launch blog post, the AWS AppSync documentation, and the Powertools for Lambda documentation (TypeScript, Python, .NET). You can get started with these new features through the AWS AppSync console.  

Publicado el — Deja un comentario

Amazon VPC Reachability Analyzer and Amazon VPC Network Access Analyzer are now available in Europe (Spain) Region

With this launch, VPC Reachability Analyzer and VPC Network Access Analyzer are now available in Europe (Spain) Region.

VPC Reachability Analyzer allows you to diagnose network reachability between a source resource and a destination resource in your virtual private clouds (VPCs) by analyzing your network configurations.For example, Reachability Analyzer can help you identify a missing route table entry in your VPC route table that could be blocking network reachability between an EC2 instance in Account A that is not able to connect to another EC2 instance in Account B in your AWS Organization.

VPC Network Access Analyzer allows you to identify unintended network access to your resources on AWS. Using Network Access Analyzer, you can verify whether network access for your VPC resources meets your security and compliance guidelines. For example, you can create a scope to verify that the VPCs used by your Finance team are separate, distinct, and unreachable from the VPCs used by your Development team.

For more information on features, visit documentation for VPC Reachability Analyzer and VPC Network Access Analyzer. For pricing details, refer to the Network Analysis tab on the Amazon VPC Pricing Page.
 

 

​With this launch, VPC Reachability Analyzer and VPC Network Access Analyzer are now available in Europe (Spain) Region. VPC Reachability Analyzer allows you to diagnose network reachability between a source resource and a destination resource in your virtual private clouds (VPCs) by analyzing your network configurations.For example, Reachability Analyzer can help you identify a missing route table entry in your VPC route table that could be blocking network reachability between an EC2 instance in Account A that is not able to connect to another EC2 instance in Account B in your AWS Organization. VPC Network Access Analyzer allows you to identify unintended network access to your resources on AWS. Using Network Access Analyzer, you can verify whether network access for your VPC resources meets your security and compliance guidelines. For example, you can create a scope to verify that the VPCs used by your Finance team are separate, distinct, and unreachable from the VPCs used by your Development team. For more information on features, visit documentation for VPC Reachability Analyzer and VPC Network Access Analyzer. For pricing details, refer to the Network Analysis tab on the Amazon VPC Pricing Page.    

Publicado el — Deja un comentario

Amazon SageMaker Lakehouse now supports attribute based access control

Amazon SageMaker Lakehouse now supports attribute-based access control (ABAC), using AWS Identity and Access Management (IAM) principal and session tags to simplify data access, grant creation, and maintenance. With ABAC, you can manage permissions using dynamic business attributes associated with user identities.

Previously, SageMaker Lakehouse granted access to lakehouse databases and tables by directly assigning permissions to specific principals such as IAM users and IAM roles, a process that could quickly become unwieldy as the number of users grew. ABAC now allows administrators to grant permissions on a resource with conditions that specify user attribute keys and values. This means that any IAM principal or IAM role with matching principal or session tag keys and values will automatically have access to the resource making the experience more efficient. You can use ABAC though the AWS Lake Formation console to provide access to IAM users and IAM roles for both in-account and cross-account scenarios. For instance, rather than creating individual policies for each developer, administrators can now simply assign them an IAM tag with a key such as “team” and value «developers» and provide access to all developers with a single permission grant. As new developers join with the matching tag and value, no additional policy modifications are required.

This feature is available in all AWS Regions where SageMaker Lakehouse is available. To get started, read the launch blog and read ABAC documentation.
 

 

​Amazon SageMaker Lakehouse now supports attribute-based access control (ABAC), using AWS Identity and Access Management (IAM) principal and session tags to simplify data access, grant creation, and maintenance. With ABAC, you can manage permissions using dynamic business attributes associated with user identities. Previously, SageMaker Lakehouse granted access to lakehouse databases and tables by directly assigning permissions to specific principals such as IAM users and IAM roles, a process that could quickly become unwieldy as the number of users grew. ABAC now allows administrators to grant permissions on a resource with conditions that specify user attribute keys and values. This means that any IAM principal or IAM role with matching principal or session tag keys and values will automatically have access to the resource making the experience more efficient. You can use ABAC though the AWS Lake Formation console to provide access to IAM users and IAM roles for both in-account and cross-account scenarios. For instance, rather than creating individual policies for each developer, administrators can now simply assign them an IAM tag with a key such as “team” and value «developers» and provide access to all developers with a single permission grant. As new developers join with the matching tag and value, no additional policy modifications are required. This feature is available in all AWS Regions where SageMaker Lakehouse is available. To get started, read the launch blog and read ABAC documentation.