AWS opened a public preview of the Well-Architected Agent on October 1, a service it describes as the next-generation evolution of Trusted Advisor and the Well-Architected Tool. The framework it automates is roughly a decade old and, until now, applying it mostly meant working through reviews by hand in a console or paying a consultant or an AWS solutions architect to run them.
Setup is an agent profile: you name the accounts and regions to scan, choose which of the four pillars to weigh — cost optimization, performance, resilience and security — and write at least one business goal in plain text. Access is granted through two kinds of IAM role. An execution role lives in the account that holds the profile and can only assume other roles; an access role is created in each account to be analyzed and is meant to carry the managed policy WellArchitectedAgentResourceScanning, which grants read-only access to resource metadata and configuration. AWS states that neither role lets the agent change anything. Applying a fix is a separate step the customer takes.
Recommendations arrive at three levels: individual resources, such as a database without backups or an oversized instance; consolidated findings across many resources scoped to an application; and architecture-level patterns that come back as infrastructure-as-code edits. AWS says the first resource and application recommendations land within 24 hours of creating a profile, with the set refreshed weekly afterwards; the user guide is more conservative and states 48 hours. Only architecture reviews can be triggered on demand. Each recommendation carries an estimated dollar impact where one applies, an account of how it affects the other pillars, and a remediation package — an SSM runbook, prescriptive CLI scripts, a guided console walkthrough, or an updated IaC template.
The architecture review is the part aimed squarely at engineers. You point the agent at infrastructure code in Amazon S3 and it returns the templates with its changes applied, covering Terraform, AWS CDK and CloudFormation projects. The limits are specific: a .zip may be up to 25 MB, an S3 folder up to 100 MB with no single file above 1 MB, the bucket should sit in the same region as the profile, and each profile is capped at five architecture reviews a day.
Access is gated by support tier. The agent requires an AWS Support plan at the Business tier or higher — Business+, Enterprise On-Ramp, Enterprise, or Unified Operations — which puts it out of reach for Developer-tier accounts regardless of size. Business+ allows two profiles and seven applications per profile; Enterprise On-Ramp, Enterprise and Unified Operations allow ten profiles and thirty applications per profile. A single profile can analyze up to 100 AWS accounts and hold up to 10 active business goals, and one generation run produces at most 30 recommendations. Agent profiles are hosted in US East (N. Virginia), US East (Ohio) and US West (Oregon), and can onboard workloads from any AWS commercial region. AWS has not published separate pricing for the preview or a general-availability date.
The agent is a prioritization layer as much as a new scanner. Its inputs are findings enterprises may already receive: Trusted Advisor, Compute Optimizer, AWS Security Hub CSPM, Resilience Hub and Cost Optimization Hub. Cost figures come from Cost Explorer when it is enabled and are estimated from public AWS pricing when it is not. Recommendations can also be pulled into AI coding assistants through the AWS MCP Server and plugins.
The direction of travel matters more than the feature list. Cloud providers are shipping agents that operate on infrastructure rather than just answering questions about it, and AWS has bolted this one onto a review framework its enterprise customers already use for audits. Firms that sell Well-Architected reviews should expect part of that work to be automated. For everyone else, the sane posture is to treat the output as a pull request: scope the agent's access role to read-only, review the generated security-group, IAM and database changes in a staging account, and apply them through an existing pipeline with a rollback plan.
Comments (0)
Log in to join the discussion
Log InNo comments yet