
AWS introduces the public preview of the Well-Architected Agent, an AI-driven service that analyzes your AWS environment and delivers goal‑aligned, contextual recommendations with ready-to‑implement fixes for cost, security, performance, and resilience.
Introducing the AWS Well‑Architected Agent
The AWS Well‑Architected Agent is an AI‑driven service that inspects an AWS workload and produces actionable findings aligned to the Well‑Architected Framework pillars—cost, security, performance, and resilience. Unlike manual audits, the agent automatically gathers configuration data, utilization metrics, and application topology, then correlates these signals against best‑practice rules for more than 65 AWS services. The analysis mimics the reasoning of an experienced cloud architect, allowing engineers to focus on remediation rather than data collection.
Before any recommendation is issued, the agent requires two pieces of context:
- Business goals—engineers declare objectives for each pillar (e.g., reduce spend by 15 % or achieve sub‑second latency).
- Application metadata—the workload’s AWS accounts, regions, tags, and optionally an Infrastructure as Code (IaC) project (Terraform, CloudFormation, or CDK) are supplied.
With this context, the agent produces three recommendation tiers:
- Resource‑level findings that include a dollar impact estimate (when applicable) and step‑by‑step remediation.
- Consolidated findings that group related resources, highlighting cross‑resource trade‑offs.
- Architectural patterns that suggest IaC changes to align the overall design with Well‑Architected best practices.
Practical example: an Auto Scaling group running t3.large instances shows 30 % average CPU utilization over the past week. The agent flags this as a cost‑optimization opportunity, recommends downsizing to t3.medium, and provides the exact CloudFormation snippet to modify the instance type. A separate security finding may detect an S3 bucket with public read access; the agent supplies a bucket policy JSON that restricts access to the owning account.
Remediation can be performed via:
- Console walkthroughs with guided UI steps.
- Updated IaC templates that can be committed to version control.
- AWS CLI commands generated for immediate execution.
Engineers can retrieve recommendations through the Well‑Architected console or programmatically via the agent’s API, enabling integration with CI/CD pipelines and continuous compliance monitoring. The service updates findings periodically, ensuring that new optimization opportunities are surfaced as workloads evolve.
Core Features and How They Work
Goal‑aligned intelligence replaces flat findings with context‑aware recommendations that are prioritized against declared business objectives. The agent ingests application metadata—such as workload purpose, compliance regime (e.g., SOC 2, ISO 27001, NIST, OWASP), and cost targets—and then maps each potential improvement to the impact on those goals. By scoring recommendations on both effort and projected benefit, engineers can focus on changes that move the most needle for the chosen pillar.
For example, an e‑commerce service that declares a security‑first goal will see a recommendation to enable Amazon GuardDuty on its VPC before a lower‑priority suggestion to right‑size idle EC2 instances for cost savings.
The service delivers recommendations at three distinct scopes, each built on the same underlying analysis engine:
- Resource‑level: individual findings with estimated dollar impact and step‑by‑step remediation.
- Consolidated: grouped findings across multiple resources that affect a single application or pillar.
- Architectural: high‑level patterns that require Infrastructure as Code (IaC) changes to align the overall design with Well‑Architected best practices.
A practical illustration might include:
- A single S3 bucket flagged for public access (resource‑level).
- Ten under‑utilized RDS instances grouped into a “right‑size database” recommendation (consolidated).
- A suggestion to replace a monolithic Lambda deployment with a Step Functions workflow, delivered as a CloudFormation diff (architectural).
Remediation optionality lets teams choose the delivery mechanism that fits their CI/CD pipeline. The console walk‑through presents an interactive UI that guides the operator through each configuration change. Updated IaC provides a ready‑to‑apply diff for Terraform, CloudFormation, or CDK. CLI commands expose the same fixes via the AWS CLI for scripting.
- Console walkthrough – interactive, point‑and‑click steps.
- IaC update – generated code diff that can be committed to version control.
- CLI command – idempotent AWS CLI statements that can be embedded in automation scripts.
Example workflow: after selecting the architectural recommendation to enforce encryption at rest, the agent returns a CDK snippet that adds encryption: kms to the resource definition. The same recommendation can be applied by running aws s3api put-bucket-encryption … from a build script, or by following the console wizard that updates the bucket configuration in place.
Getting Started: Setting Up an Agent Profile
Before the Well‑Architected Agent can analyze a workload, you must define the scope in which it operates. This is done by creating an agent profile in the AWS Well‑Architected console. The profile tells the service which AWS accounts, regions, and resources it may read, which Well‑Architected pillars to evaluate, and what business goals should drive recommendation prioritization.
Step‑by‑step profile creation
- Open the Well‑Architected console and select Get started with Well‑Architected Agent.
- In the Agent profile wizard, choose one or more AWS accounts or specific AWS Regions that contain the workloads you want to monitor.
- Select the optimization pillars that align with your objectives. Available pillars are:
- Cost Optimization
- Performance Efficiency
- Reliability (Resilience)
- Security
- For each pillar, set a goal that reflects the desired outcome (e.g., “reduce monthly compute spend by 15 %” for Cost Optimization or “achieve NIST 800‑53‑level security controls” for Security). Goals are used by the agent to rank recommendations by impact and effort.
- Optionally add application context: provide a name, tags, and the services used by each application. This metadata improves recommendation relevance.
- Complete the wizard; the console creates the profile and begins scanning. Recommendations appear within 24 hours.
Provisioning the required IAM role
The agent needs read‑only access to resource configurations, utilization metrics, and topology information. Follow the IAM prerequisite to create a customer‑managed role with the following policy elements:
sts:AssumeRolepermission for the Well‑Architected Agent service principal.- Read‑only actions such as
ec2:Describe*,rds:Describe*,cloudwatch:GetMetricData, andelasticloadbalancing:Describe*for all services in the selected accounts/regions. - Permission to list tags (
resourcegroupstaggingapi:GetResources) so the agent can filter resources by the tags you supplied.
Attach the role to the agent profile in the console. Once the role is assumed, the agent can safely collect the data it needs without granting write privileges, preserving the principle of least privilege.
After the profile and IAM role are in place, you can upload an IaC artifact (Terraform, CloudFormation, or CDK) to conduct a pre‑deployment architecture review, or let the agent continuously monitor the live environment and surface prioritized, goal‑aligned recommendations.
Running Architecture Reviews and Accessing Recommendations
The AWS Well‑Architected Agent evaluates an infrastructure‑as‑code (IaC) project by first ingesting the source files, then enriching the analysis with explicit application context. This two‑step intake ensures that recommendations are scoped to the actual workload rather than generic resource patterns.
Uploading an IaC project
- Open the Well‑Architected console and select Conduct architecture review.
- Choose the IaC format (Terraform, CloudFormation, or CDK) and upload a
.zipcontaining the complete project directory or a repository reference. - Select the lens (e.g., Cost Optimization, Security) that aligns with the business goals you have declared in the agent profile.
Adding application context
After the upload, click Add application context and provide:
- AWS account IDs and Regions where the workload runs.
- Relevant tags, services, and resource identifiers to narrow the scope.
- Business‑level details such as compliance requirements (SOC 2, ISO 27001, NIST, OWASP) or performance SLAs.
This metadata allows the agent to correlate utilization metrics with the declared objectives and to prioritize findings accordingly.
Viewing prioritized recommendations
The console presents a ranked list of findings. Each entry shows:
- Impact score (e.g., estimated cost savings or risk reduction).
- Effort estimate (number of resources to modify, required code changes).
- Cross‑pillar trade‑offs, such as a security hardening that may increase latency.
Selecting a recommendation expands a detail pane that explains the underlying analysis, the affected resources, and the expected outcome.
Remediation options
For any recommendation you can choose one of three remediation paths:
- Console walk‑through: Step‑by‑step UI instructions that guide you through configuration changes directly in the AWS console.
- Updated IaC template: The agent generates the exact code modifications (e.g., a CDK construct update) that you copy into your repository and redeploy.
- CLI commands: A ready‑to‑run
awsCLI snippet that applies the change without leaving the terminal.
After applying the chosen fix, re‑run the review or use the built‑in verification step to confirm that the recommendation is resolved.
Continuous improvement
Because the agent refreshes its analysis periodically, new findings appear as the environment evolves. Integrating the API‑based recommendation feed into CI/CD pipelines enables automated detection and remediation, keeping the workload aligned with Well‑Architected best practices throughout its lifecycle.
Preview Availability, Support, and Best Practices
The preview of AWS Well‑Architected Agent is limited to three commercial Regions: US East (N. Virginia), US East (Ohio), and US West (Oregon). When you create an agent profile you must select one or more of these Regions; workloads in any other AWS Region can be onboarded, but the agent will only generate recommendations for resources that reside in the supported preview Regions.
Access to the service is gated by an AWS Support plan. The agent is delivered by AWS Support and is available only to customers who have an active AWS Support plan. During profile creation you grant the agent a customer‑managed IAM role that allows read‑only access to resource configurations, utilization metrics, and application topology. Without the required support subscription the console will block the “Get started with Well‑Architected Agent” workflow.
Because the recommendations are produced by generative AI, AWS requires customers to apply responsible‑AI safeguards. The documentation notes that the AI may produce errors or incomplete information, so teams must:
- Validate the technical accuracy of each recommendation against their own security and compliance baselines (e.g., SOC 2, ISO 27001, NIST 800‑53, OWASP ASVS).
- Document the decision‑making process for any remediation that alters production workloads.
- Implement a review gate—such as a pull‑request approval workflow—before applying IaC changes supplied by the agent.
Recommendations are refreshed on a periodic basis. After an agent profile is created, initial findings appear within 24 hours, and subsequent updates are delivered automatically as the underlying environment changes or as the AI model is improved. Teams should schedule a regular review cadence (for example, a weekly “Well‑Architected sync”) to capture new findings and track remediation progress.
Integration with the existing Well‑Architected Tool is straightforward. You can continue to run manual lens reviews in the console while the agent populates the same recommendation store. The agent’s findings appear alongside manual assessments, allowing you to:
- Compare AI‑generated insights with traditional checklist results.
- Leverage the API to pull recommendations into CI/CD pipelines, using the provided IaC snippets or CLI commands for automated remediation.
- Maintain a single source of truth for all Well‑Architected metrics across cost, performance, resilience, and security pillars.
By confining usage to the supported preview Regions, ensuring an AWS Support plan, applying responsible‑AI validation, and aligning periodic updates with existing Well‑Architected processes, enterprise engineering teams can safely evaluate the agent’s value before broader production adoption.
Looking for Custom Software or AI Solutions?
Appworks Technologies designs, builds, and scales production enterprise platforms, microservices, and AI agent workflows tailored to your business goals.
Editorial Policy & Research Methodology
Our findings are based on rigorous internal research, verified industry benchmarks, and direct technical implementation experience from our enterprise client projects. All statistics and technical claims are reviewed by senior engineers before publication to ensure accuracy, transparency, and helpfulness for our readers.
