Skip to main content

AWS Well-Architected Agent Reviews Your Cloud, but Its Fixes Need Approval

3 min read

AWS Well-Architected Agent can scan cloud resources and generate remediation guidance. Its preview output still requires human review and controlled execution.

AWS Well-Architected Agent Reviews Your Cloud, but Its Fixes Need Approval

A cloud review agent can find more than a person can inspect manually. It can also generate a plausible fix that is wrong for the architecture, account, or change window.

AWS announced Well-Architected Agent in preview on October 1. The service evaluates resources against cost, security, performance, and resilience guidance. AWS says it covers more than 65 services and can work at resource, application, and architecture levels.

Who can use the preview?

The AWS documentation lists Business Support+, Enterprise On-Ramp, Enterprise Support and Unified Operations customers as eligible. Agent profiles are hosted in US East (N. Virginia), US East (Ohio) or US West (Oregon), while scans can examine resources across commercial AWS Regions.

That profile location matters for governance even when the reviewed resources live elsewhere. Before enrollment, document which account data, findings, and generated artifacts are processed in the selected profile region.

The review cycle is not instant.

AWS says a profile can include up to 100 accounts and refreshes findings weekly. Application-level analysis is described as beta, and profile results may take up to 24 hours. This is a periodic architecture review, not a substitute for real-time detection or an incident-response system.

Use the Agent to surface candidates for investigation. Keep monitoring, configuration rules, and security detections in place. A weekly refresh can miss an urgent misconfiguration that appeared minutes ago.

Generated fixes are change proposals.

The Agent can generate infrastructure-as-code changes, Systems Manager runbooks, command-line instructions, and console guidance. Each format can alter production. AWS also warns that generative AI output may contain errors. The safe interpretation is a draft change set, not an approved remediation.

Require a named owner to confirm the resource, dependency, blast radius, and rollback path. Run code through version control and policy checks. Runbooks should be executed in a lower environment where possible, and the person who approves a high-impact change should be separate from the automated system that proposed it.

A controlled operating procedure

  • Create the profile with the minimum accounts and regions needed for the review.
  • Assign owners for cost, security, performance, and resilience findings.
  • Triage findings against current architecture and business requirements.
  • Convert accepted remediation into a normal tracked change request.
  • Test generated code or commands before production execution.
  • Record the result, rollback evidence, and any false-positive pattern.

Our agent cost-control guide is relevant beyond model tokens: an optimization agent should be measured by accepted savings and avoided risk, not by the number of recommendations it produces. Well-Architected Agent can shorten the discovery step. Accountability for the change remains with the operator.

Leave a comment

Your email address will not be published. Required fields are marked *