Skip to content

Add user identity (enduser.id) attribute to OpenTelemetry #592

Description

@tarun-sinha

Feature Description

Currently, the OpenTelemetry (OTel) traces and spans generated during AgentCore invocation (InvokeAgentRuntime / gen_ai execution) capture telemetry metrics and session identifiers, but do not consistently populate user identity in the span attributes.

We request adding support to automatically populate user identity (or allow passing custom user identity metadata) onto OTel span attributes, following the OpenTelemetry Semantic Conventions for user attributes (enduser.id).


Use Case & Impact

  1. User-level Observability & Debugging: When troubleshooting agent execution failures or slow agent runs in observability platforms (e.g., Datadog, Grafana, Dynatrace, OpenSearch), SREs and developers need to trace issues back to specific end-users.
  2. Auditability & Compliance: Enterprise compliance standards often require linking LLM invocations and tool calls directly to the initiating user identity.
  3. Usage Attribution & Quotas: Facilitates per-user telemetry tracking, token usage analytics, and user-level rate limiting.

Proposed Solution

  • Standard Attribute: Set the span attribute enduser.id on root invocation spans and downstream tool/model execution spans according to the OpenTelemetry Semantic Conventions for User Attributes.
  • Configuration / Propagation:
    • Extract the user ID automatically from Inbound Authentication JWT tokens (e.g., Cognito sub or custom claim) if passed via AgentCore Identity/Auth headers.
    • Expose a mechanism in BedrockAgentCoreApp or request context context/metadata to explicitly inject user_id when initializing or handling incoming requests.

Example / Expected Behavior

When an agent invocation span is generated, the resulting OpenTelemetry span attributes should include:

{
  "gen_ai.system": "aws.bedrock",
  "enduser.id": "usr_987654321",
  "session.id": "session_12345"
}

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions