Choose Amazon Bedrock Managed Knowledge Bases when its supported data sources, access controls and retrieval options fit your application and you want AWS to operate more of the retrieval infrastructure. Choose a customer-managed knowledge base when your team needs direct control over the vector store or ingestion pipeline. Neither choice guarantees better answer quality, lower latency or lower total cost: those depend on your corpus, workload and configuration.
What changes when AWS manages the knowledge base?
A retrieval-augmented generation (RAG) application prepares source documents as chunks, converts them into embeddings, and stores those representations alongside links to the source material. At query time, it retrieves relevant chunks and passes them to a language model as context. Amazon Bedrock Knowledge Bases automates parts of this path; the architecture decision is about how much of its underlying infrastructure and pipeline your team wants to operate.
As an Amazon Associate I earn from qualifying purchases.
For a managed knowledge base, AWS says Amazon Bedrock AgentCore manages storage, indexing and retrieval infrastructure. The creation flow still involves choices such as data source, parser and chunking settings, optional indexing for additional modalities, and optional ingestion-log delivery. AWS describes the default embedding model as service-managed; you can instead provide a Bedrock embedding model, and optionally configure a KMS key. For a customer-managed knowledge base, your team manages more of the RAG pipeline, including the vector store and ingestion, parsing, indexing and storage configuration. AWS lists OpenSearch Serverless, Aurora and Neptune as examples of customer-managed vector-store options. AWS’s managed knowledge base creation guide and Knowledge Bases overview describe these paths.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteCompare the two architectures against your needs
| Decision area | Managed knowledge base | Customer-managed knowledge base |
|---|---|---|
| Infrastructure operations | AWS manages storage, indexing and retrieval infrastructure. | Your team manages the vector store and more of the RAG pipeline. |
| Pipeline control | Use the managed service’s supported configuration and options. | More direct control over ingestion, parsing, indexing and storage configuration. |
| Data sources and access | Creation guide lists Amazon S3, Confluence, Custom, Google Drive, OneDrive, SharePoint and Web Crawler. Managed knowledge bases support document-level ACL filtering, except for Web Crawler. | Depends on the chosen pipeline and integrations; confirm they meet your connector and policy requirements. |
| Retrieval and orchestration | Can use Retrieve, RetrieveAndGenerate or AgenticRetrieveStream, depending on the workflow. | Supports a pipeline your team can manage and integrate according to its design. |
| Configuration responsibility | You still configure data access, IAM, connectors, ingestion behavior, API integration and application-side evaluation. | You own those application responsibilities as well as more of the infrastructure and pipeline decisions. |
AWS recommends Managed Knowledge Bases “For optimized retrieval accuracy and a managed experience.” Treat that as AWS’s product guidance, not as evidence that managed retrieval will outperform a customer-managed design on your data. A workload-specific benchmark is needed to establish quality, latency and cost for your application. See AWS’s Knowledge Bases overview.
#1 Best Overall
Check connector and permission fit first
The managed creation guide lists Amazon S3, Confluence, Custom, Google Drive, OneDrive, SharePoint and Web Crawler as data-source types. Confirm the connector is available in your target Region and that it can represent your actual source and update process. For applications that enforce document-level permissions, verify the ACL behavior against your policy model: AWS describes document-level ACL filtering for managed knowledge bases, with Web Crawler as the exception.
A managed setup also needs a supported connector and appropriate IAM permissions. The setup role needs iam:PassRole to pass the service role to Bedrock. Selecting a custom embedding or reranking model requires model access; using a customer-managed KMS key requires additional configuration and permissions. Validate least-privilege policies in your own account. AWS lists the setup requirements in its managed knowledge base prerequisites.
Rank #2
Choose the retrieval API that matches your control needs
The API choice affects how much of the retrieval-to-answer flow your application delegates to Bedrock:
Retrieve: returns relevant source chunks or images. Use it when your application wants retrieved material but will handle the rest of the RAG flow itself.RetrieveAndGenerate: combines retrieval with model invocation and can return citations to source chunks.AgenticRetrieveStream: decomposes complex queries, retrieves iteratively and returns trace events.
Reranking is another retrieval option. These APIs provide different levels of orchestration, not a substitute for evaluating whether the retrieved context and generated answers are suitable for your use case. AWS documents them in Retrieving information from data sources using Amazon Bedrock Knowledge Bases.
Plan for freshness and ingestion changes
Adding, editing or removing source material requires a sync. AWS describes sync as incremental: unchanged files are skipped, new files are ingested, changed content or metadata is re-parsed, re-chunked, re-embedded and re-indexed, and deleted documents are removed from the vector store. Set a sync cadence and monitor ingestion as part of your freshness design; a knowledge base is only as current as its completed updates. See Sync your data with your Amazon Bedrock knowledge base.
For the documented customer-managed ingestion configuration, AWS says parser and chunking customization are available, and the chunking strategy cannot be changed after connecting a data source. Its documented default is approximately 300 tokens while preserving sentence boundaries. This is specific to that customer-managed configuration; do not assume it applies to a distinct managed service configuration. Test representative documents before committing to ingestion settings. Details are in Customize ingestion for a data source.
Rank #4
Estimate managed-service charges and check quotas
Amazon Web Services’ pricing page, viewed October 7, 2026, lists the following Managed Knowledge Base charges. These are service list prices, not an all-in estimate for a RAG application; verify current pricing and Region applicability before making a decision.
| Managed Knowledge Base item | AWS-listed price |
|---|---|
| Raw data storage | $5.00 per GB per month |
| Standard Retrieve API calls | $1.00 per 1,000 calls |
| Managed parsing, embeddings generation and reranking | $0 |
| Agentic retrieval with managed planning | $4.00 per 1,000 Agentic Retrieve calls, plus $1.00 per 1,000 underlying Retrieve calls |
| Custom embedding or reranking models | Additional model-provider charges apply |
| Agentic Retrieval with a customer-selected LLM | Underlying Retrieve charge plus the model provider’s pricing for query planning |
Budget separately for generation model calls, data transfer, observability, gateway usage and any other AWS services your application uses. The service’s retrieval prices alone cannot establish which architecture has the lower total cost. Check the current Amazon Bedrock Pricing page against your expected indexed raw data, retrieval volume and optional services.
Best Value
AWS lists default managed knowledge base quotas of 10 TB raw data storage per knowledge base, 200 data sources per knowledge base and 600 Retrieve requests per minute per knowledge base; some quotas are adjustable. These are quota-planning limits, not a promise of workload performance. Check the current service quotas for managed knowledge bases for your account and Region.
Use this checklist to make the architecture decision
- Does the managed service support each required connector in your target Region?
- Does its document-level ACL behavior match your access policy, especially if you need Web Crawler?
- Are the managed parsing, chunking, embedding, storage and retrieval options sufficient, or do you need control over pipeline internals?
- Will
Retrieve,RetrieveAndGenerateorAgenticRetrieveStreamfit your orchestration and citation requirements? - Can your sync cadence meet freshness needs, and how will you detect ingestion failures or stale content?
- Do your expected raw-data volume, data-source count and request rate fit the quotas, or will you need adjustable limits?
- Does a cost estimate include storage, retrieval, generation, custom models and the other services in your application?
- Can your team meet the IAM, model-access and KMS prerequisites under its security policies?
Validate the choice with a focused proof of concept
- Use a representative sample of documents, including the formats, metadata and permission patterns that matter to the application.
- Run realistic queries through the retrieval and orchestration flow you expect to deploy. Inspect the retrieved source chunks, citations where applicable, and generated answers.
- Test additions, edits and deletions, then measure how sync affects freshness and ingestion operations.
- Measure end-to-end latency and answer quality under your workload rather than assuming either architecture is faster or more accurate.
- Estimate costs using expected indexed raw data, retrieval volume, generation calls and optional services; compare that estimate with the operational work your team would own in a customer-managed design.
If the managed connector, access and configuration options pass these checks, its reduced infrastructure ownership makes it a strong candidate. If a required control or pipeline customization is missing, the customer-managed path may better fit the architecture. The proof of concept determines whether either option meets your application’s requirements.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




