Cloud & Infrastructure · AWS

AWS Well-Architected Agent Explained: Pricing, Permissions, Limits and What It Can Actually Do

AWS has put an AI layer on top of cloud architecture review and optimization. The public preview can inspect live AWS environments, rank recommendations against business goals, review Infrastructure as Code and propose implementation-ready fixes—but access is tied to paid Support, cross-account IAM roles matter, and AWS’s launch documentation does not yet agree on every refresh-timing detail.

Digital Pulse Brief Editorial Desk  •  Published October 2, 2026  •  Research-based analysis; no hands-on DPB testing claimed

AWS cloud architecture service icons from the official AWS Architecture Icons collection
Image credit: Amazon Web Services (AWS) — official AWS Architecture Icons asset.

Quick answer: AWS Well-Architected Agent is useful, but the preview needs careful governance

What it is: AWS Well-Architected Agent (AWS WA Agent) is a public-preview service announced on October 1, 2026 that analyzes AWS resources, application context and Infrastructure as Code to produce prioritized recommendations across cost, security, resilience and performance.

Who can access it: AWS documentation says Business Support+ or higher is required. Developer and legacy Business Support customers do not have access.

How it works: a profile defines accounts, Regions, goals and applications; customer-managed IAM roles give the agent read access; AWS then generates resource-, application- and architecture-level recommendations.

What it can propose: console walkthroughs, AWS CLI commands, SSM runbooks and updated IaC can be attached to recommendations where applicable. That is not the same as permission to make every change automatically.

Important preview caveat: AWS explicitly warns that generative-AI recommendations may contain errors or incomplete information. Application-level recommendations are also labeled beta.

One documentation issue to watch: the launch post says resource and application recommendations arrive within 24 hours after profile creation; the getting-started guide says within 48 hours; separate pages describe both roughly-daily generation and weekly refresh cycles. Teams should not build time-critical operational processes around one exact cadence until AWS reconciles those pages.

What AWS Well-Architected Agent changes

AWS has long offered two adjacent ways to review cloud environments: AWS Well-Architected Tool for structured workload reviews and AWS Trusted Advisor for checks and recommendations. The new agent is positioned as a next-generation layer that combines live environmental signals with application context, business goals and generative-AI reasoning.

According to the October 1 AWS launch post, the service correlates utilization metrics, resource configuration and application topology against Well-Architected best practices across more than 65 AWS services. AWS says recommendations can be ranked by impact and effort relative to goals such as reducing cost, improving resilience or tightening security.

The useful shift is from a flat list of findings to contextual prioritization. A rightsizing suggestion may be technically valid but wrong for a latency-sensitive application. A multi-AZ design can improve resilience while increasing cost. AWS WA Agent is designed to show those cross-pillar trade-offs instead of treating every recommendation as isolated.

That does not make the agent an autonomous cloud architect. AWS’s own documentation says users remain responsible for evaluating recommendations in their specific context and applying appropriate oversight.

How the agent works from profile to remediation

  1. Create an agent profile. The profile defines which AWS accounts and Regions are in scope, which optimization pillars matter, and what business goals the team wants to prioritize.
  2. Configure IAM access. AWS WA Agent uses customer-managed roles. An execution role in the profile account chains into access roles in the workload accounts so the service can discover resource metadata and configuration.
  3. Add application context. AWS asks for application information such as accounts, Regions, tags, services, criticality and architecture context. The getting-started guide says at least one application context is required for scheduled recommendations.
  4. Ingest optimization signals. AWS documentation says the agent can build on signals from Trusted Advisor, Compute Optimizer, Security Hub CSPM, Resilience Hub, Cost Optimization Hub, Cost Explorer and the Well-Architected Tool.
  5. Generate and prioritize findings. Recommendations are scored against the goals in the profile and presented with impact, effort, trade-offs and remediation guidance.
  6. Review before implementation. Depending on the recommendation, AWS can provide console steps, CLI commands, SSM automation or updated IaC. The team decides what to apply and should validate every change through its normal engineering and change-control process.

For foundational context on IaaS, PaaS, SaaS and serverless responsibilities, DPB’s cloud computing explainer provides a useful baseline before evaluating an automated architecture service.

Three recommendation levels—and why architecture reviews are different

TypeWhat it evaluatesTypical outputKey caveat
ResourceA specific EC2 instance, Lambda function, RDS database or other supported resourceConfiguration, cost or optimization fix with implementation guidanceScheduled; not an on-demand scan
ApplicationRelationships across resources in an applicationContextual recommendations that account for component interactionAWS labels this format beta
ArchitectureTerraform, CloudFormation or AWS CDK project files before deploymentDesign findings and updated IaC aligned to selected Well-Architected guidanceGenerated on demand; separate from scheduled refreshes

Source: AWS Well-Architected Agent user guide and recommendation documentation, checked October 2, 2026.

Architecture review is particularly interesting for platform teams because it moves part of the Well-Architected conversation earlier in the lifecycle. Instead of waiting for a deployed resource to become visible to optimization services, a team can submit IaC and evaluate the design before production. The resulting code still needs review: an automatically generated template can be syntactically plausible and still conflict with an organization’s networking, compliance, cost or deployment conventions.

The permission model is a feature—and a governance responsibility

A service that evaluates multiple accounts needs visibility into those accounts. AWS WA Agent deliberately uses customer-managed IAM roles rather than service-linked roles, according to the AWS access-model documentation. That gives customers control over permissions, but it also means the role chain becomes part of the organization’s security design.

The profile account contains an execution role. Each workload account needs an access role that the execution role can assume. AWS’s setup guide currently recommends attaching the WellArchitectedAgentResourceScanning managed policy to workload access roles so the agent can read resource metadata and configuration.

Teams should treat this like any other cross-account observability or governance integration: confirm the exact trust relationship, restrict who can create or pass the execution role, review managed-policy changes over time, and remove access for accounts that leave the profile. AWS’s broader Well-Architected security guidance also emphasizes least privilege and analysis of cross-account access.

This is especially important if the agent is added to a large AWS Organization. One profile can cover many accounts, so a convenient central view can also create a wide trust surface if roles are created carelessly. DPB’s report on cloud service-principal compromise and destructive permissions covers a different platform, but the defensive principle is the same: machine identities need tight scope, monitoring and lifecycle control.

Pricing and eligibility: the agent is not a free replacement for Well-Architected Tool

AWS’s current documentation does not present a separate per-scan or per-recommendation price for AWS WA Agent. Instead, access is gated by the AWS Support plan. The getting-started guide requires Business Support+ or higher.

Support tierWA Agent accessCurrent minimum shown by AWSProfiles / applications
Developer / legacy BusinessNoNot applicable for WA Agent access—
Business Support+Yes$29/month per account minimum, or tiered percentage of monthly AWS charges, whichever is greater2 profiles / 7 applications per profile
Enterprise SupportYes$5,000/month minimum or percentage-based pricing10 profiles / 30 applications per profile
Unified OperationsYes$50,000/month minimum or percentage-based pricing10 profiles / 30 applications per profile

Sources: AWS Support pricing and AWS WA Agent quotas/entitlements, checked October 2, 2026. Enterprise On-Ramp is still listed as eligible during 2026 but AWS says that plan is being discontinued on January 1, 2027.

By contrast, AWS says the existing Well-Architected Tool itself is available at no charge. That distinction matters for smaller teams: the new agent may reduce review effort, but its practical cost begins with the Support tier required to unlock it.

Important limits to know before a multi-account rollout

LimitCurrent documented valueWhy it matters
Accounts per profile100Large organizations may need multiple profiles and governance boundaries.
Goals per profile10Business priorities need to be explicit rather than an unlimited wish list.
Profile hosting Regions3: N. Virginia, Ohio, OregonThe profile is hosted in the US even though resources can be scanned in all commercial AWS Regions.
Scannable RegionsAll commercial AWS RegionsA profile can evaluate geographically distributed commercial workloads.

AWS publishes additional limits for architecture reviews, recommendation generation and uploaded IaC. Teams planning CI/CD integration should read the live quota page rather than copying fixed limits into permanent automation, because preview quotas can change.

AWS Well-Architected Agent vs Trusted Advisor vs Well-Architected Tool

CapabilityWA AgentTrusted AdvisorWA Tool
Core purposeGoal-aware AI optimization and remediationOperational checks and findingsStructured architecture review and documentation
Live environment contextYes, through configured roles and integrated signalsYes, for its checksPrimarily review workflow rather than continuous AI analysis
Business-goal prioritizationYesNot the same goal-driven layerReview choices and lenses guide assessment
IaC reviewTerraform, CloudFormation, CDK architecture analysisNot its primary modelManual review workflow; custom lenses supported
Ready-to-implement remediationWhere applicable: SSM, CLI, console steps, updated IaCDepends on check/serviceImprovement guidance rather than the new agent’s generated packages
Can they coexist?Yes; WA Agent ingests existing optimization signalsYesYes

The new service should therefore be read as an orchestration and reasoning layer—not proof that AWS has replaced Trusted Advisor or the manual Well-Architected Tool. AWS explicitly says the agent builds on existing services and that the WA Tool remains available for manual reviews and custom lenses.

Why AWS’s timing documentation needs clarification

At launch, AWS’s News Blog says resource and application recommendations are generated within 24 hours after profile creation. The current getting-started guide says scheduled recommendations begin within 48 hours. The recommendation-management page says scheduled resource and application recommendations are generated roughly every 24 hours, while the dedicated refresh-cadence page and October 1 release notes describe weekly refreshes after the initial set.

Those statements can be reconciled if “generation,” “initial availability” and “refresh” refer to different stages, but the current wording is not clear enough to assume that. For a public preview, the safest operational interpretation is: expect asynchronous recommendations, do not depend on an exact SLA-like cadence, and check AWS’s live docs before building automation around freshness.

Checked against the AWS launch post, getting-started guide, recommendation page, refresh-cadence page and release notes on October 2, 2026.

The agent covers four optimization pillars, not the full six-pillar Framework

The AWS WA Agent concepts page lists four optimization pillars: cost optimization, security, resilience and performance. The broader AWS Well-Architected Framework has six pillars: operational excellence, security, reliability, performance efficiency, cost optimization and sustainability.

That difference is easy to miss. The agent’s four optimization categories map to major operational concerns, but teams should not conclude that a WA Agent profile replaces the complete Framework review—especially where operational excellence, sustainability, organization-specific controls or custom lenses matter.

This is another reason the manual Well-Architected Tool remains useful alongside the agent. AWS itself says both can be used simultaneously.

AWS reference architecture for accelerating Well-Architected reviews with generative AI
Image credit: Amazon Web Services (AWS). This 2025 reference architecture predates AWS Well-Architected Agent and illustrates an earlier generative-AI-assisted Well-Architected review pattern.

Who should try the preview now—and who should wait

Good early candidates: organizations already paying for an eligible AWS Support plan; platform teams managing many AWS accounts; FinOps/SRE/security groups with mature change control; and infrastructure teams using Terraform, CloudFormation or CDK that want an additional pre-deployment review layer.

Teams that should be more cautious: small AWS users who would need to upgrade Support primarily for this feature; highly regulated environments that have not yet approved the required cross-account role model; teams expecting instant remediation; and organizations without a reliable review/test pipeline for generated commands or IaC changes.

The value proposition improves when an organization already has the data sources the agent can use—Cost Explorer, Trusted Advisor, Compute Optimizer, Security Hub CSPM, Resilience Hub and related services—and when applications are tagged and documented well enough to provide useful context.

For infrastructure teams also working with shared AI/GPU workloads, DPB’s Microsoft TauGrid explainer illustrates a different platform-management problem: automation is most useful when ownership, scheduling and operational boundaries are explicit rather than implicit.

A safer rollout checklist for AWS teams

  1. Confirm Support eligibility and cost before creating an adoption project.
  2. Start with a small profile instead of immediately adding every production account.
  3. Review the execution/access role trust chain and restrict iam:PassRole and profile-management permissions to the people who genuinely need them.
  4. Enable and validate Cost Explorer granular data if resource-level cost attribution matters; AWS says otherwise the agent can fall back to public-price estimates.
  5. Add accurate application context, including criticality, tags, services and architecture notes. Poor context weakens goal-aware prioritization.
  6. Route generated SSM, CLI and IaC changes through normal code review/change management. Treat them as proposed remediations, not trusted ground truth.
  7. Measure recommendation quality: useful rate, false positives, accepted changes, realized cost/performance impact, and regressions after remediation.
  8. Re-check documentation during preview because entitlements, quotas, cadence and supported resources can change.

Frequently asked questions

Is AWS Well-Architected Agent free?

AWS does not currently list a separate usage price for the agent in the public documentation reviewed by DPB. However, access requires Business Support+ or a higher eligible Support plan, so it is not generally available to Basic, Developer or legacy Business Support users. Business Support+ currently has a $29-per-account monthly minimum or percentage-based pricing, whichever is greater.

Does AWS Well-Architected Agent automatically fix my infrastructure?

It can provide implementation-ready material such as SSM runbooks, CLI commands, console walkthroughs or updated IaC where applicable. AWS also warns that AI-generated recommendations can be incomplete or wrong. Teams remain responsible for reviewing and approving changes.

Which IaC formats can it review?

AWS’s launch material and documentation list Terraform, AWS CloudFormation and AWS CDK projects for architecture review.

Can it scan resources outside the three US profile Regions?

Yes. AWS says agent profiles are hosted in US East (N. Virginia), US East (Ohio) or US West (Oregon), while resources in all commercial AWS Regions can be included in analysis.

Does it replace the six-pillar Well-Architected Framework review?

No. The agent currently exposes four optimization pillars, while the full Well-Architected Framework has six pillars. AWS also says the existing Well-Architected Tool remains available and can be used alongside the agent.

Bottom line

AWS Well-Architected Agent is more substantial than a chatbot bolted onto Trusted Advisor. It combines environment discovery, application context, goal-aware prioritization, IaC review and remediation artifacts in one workflow. For teams already operating at AWS scale, that could reduce the manual triage required to turn dozens of optimization signals into an actionable engineering backlog.

The preview also deserves restraint. Access is tied to premium Support, application-level recommendations are beta, the IAM model spans customer-managed roles, generated fixes require engineering review, and AWS’s current documentation is inconsistent about recommendation timing. The right way to evaluate it is as a decision-support and remediation-assistance system inside an existing governance process—not as an autonomous authority over production infrastructure.

Digital Pulse Brief will update this article if AWS changes general availability, pricing/entitlements, refresh behavior, supported Regions or material quota limits.

How we researched this

This article was researched from AWS’s October 1 launch announcement, the live AWS Well-Architected Agent user guide, getting-started and IAM documentation, quota/entitlement documentation, AWS Support pricing, the Well-Architected Framework and related-services documentation. We compared overlapping AWS pages specifically because this is a public preview and found timing language that is not yet fully consistent.

Primary sources: AWS News Blog launch announcement; AWS WA Agent user guide; getting-started guide; IAM access model; related services; AWS Support pricing.

For DPB’s research, corrections and AI-assisted workflow principles, see our Editorial Standards. If you spot a material factual error, contact Digital Pulse Brief.

DIGITAL PULSE BRIEF NEWSLETTER

Get clear AI, technology and business insights in your inbox

Breaking developments, practical explainers, reviews and useful tech intelligence — without the noise.