---
title: "AWS open-sources TOLAP for agent-tool access control"
slug: "aws-open-sources-tolap-for-agent-tool-access-control"
published: "2026-09-29"
beat: "Tools"
tags: ["Tools"]
creator: "Agentry Newsroom"
editor: "Susanne Sperling, Editor — Human in the Loop"
tools: ["Claude (Anthropic)", "Perplexity Sonar"]
creativeWorkStatus: "verified"
dateReviewed: "2026-09-29"
aiActArticle50: "compliant"
humanView: "https://agentry.news/tools/aws-open-sources-tolap-for-agent-tool-access-control"
agentView: "https://agentry.news/agent/aws-open-sources-tolap-for-agent-tool-access-control"
---# AWS open-sources TOLAP for agent-tool access control

> AWS released TOLAP, a Tool-Object Level Access Protocol, on September 22, 2026, as an Apache-2.0 open-source framework that enforces row-level filtering and column masking inside AI agent tools before

*Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. [AI policy](/ai-policy).*

AWS released TOLAP—Tool-Object Level Access Protocol—on September 22, 2026, as open-source software under the Apache-2.0 license, establishing a versioned policy schema and enforcement layer for controlling what data AI agents can access through their tools [AWS](https://aws.amazon.com/blogs/opensource/introducing-tolap-object-level-access-control-for-ai-agent-tools/).

## What TOLAP Does

TOLAP operates upstream of model inference, filtering and masking data at the object level before it enters an agent's language model. This means policy enforcement happens inside the tool layer itself—preventing sensitive rows or columns from ever reaching the model, rather than relying on post-hoc filtering or user-facing access controls [AWS](https://aws.amazon.com/blogs/opensource/introducing-tolap-object-level-access-control-for-ai-agent-tools/).

The protocol includes a **versioned policy schema** that defines which objects (rows, columns, or granular fields) an agent or user can access, alongside **enforcement SDKs** for Python, .NET, and TypeScript. AWS also shipped a **reference policy server** paired with an authoring console, letting teams define and test policies before deployment [AWS](https://aws.amazon.com/blogs/opensource/introducing-tolap-object-level-access-control-for-ai-agent-tools/).

## Framework Integration at Scale

The release includes **fourteen integrations** with existing agent frameworks, reducing the engineering burden of bolting access control onto production systems. This breadth of support signals AWS's effort to make object-level permissions a native layer across the agent ecosystem, not a specialized add-on [AWS](https://aws.amazon.com/blogs/opensource/introducing-tolap-object-level-access-control-for-ai-agent-tools/).

For enterprises deploying autonomous agents in regulated industries—finance, healthcare, government—the ability to enforce column-level and row-level restrictions before model inference addresses a critical gap. Agents that access databases, APIs, or knowledge repositories now have a documented protocol to prevent unauthorized data leakage, even if the agent's instructions are compromised or manipulated.

## Developer-First Release

As an Apache-2.0 project with open SDKs and a reference implementation, TOLAP lowers the barrier to adoption. Developers can integrate policy enforcement into existing frameworks without waiting for vendor-specific implementations or negotiating custom integrations. The authoring console provides a non-code interface for security teams to define and audit policies independently of agent development cycles.

The September 22 release reflects a broader industry shift toward treating agent access control as infrastructure—placing it at the tool layer rather than leaving it to guardrails, post-processing, or model-level constraints that are harder to guarantee and audit.