
Amazon Web Services · AWS Well-Architected Agent: AI Cloud Architecture Reviews with Ready-to-Apply Fixes
AWS Well-Architected Agent is an AI service from AWS Support that scans your AWS accounts and infrastructure-as-code projects and returns prioritized cost, security, resilience, and performance recommendations, each with remediation steps such as CLI commands, SDK code, or updated IaC. It suits cloud, platform, and FinOps teams on Business Support+ or higher plans who want continuous Well-Architected reviews instead of manual audits.
Best for
Cloud, platform, and FinOps teams running multi-account AWS environments on Business Support+ or higher plans who want ongoing, goal-ranked cost, security, resilience, and performance recommendations with remediation steps they can review and run
Not ideal for
Teams on Developer or Business support plans, multicloud or on-premises estates, organizations that want an agent to apply fixes autonomously, and teams whose data-residency rules rule out profile hosting in the three US Regions
Who it's for
Cloud architects, platform and DevOps engineers, security teams, and FinOps leads at AWS customers with Business Support+ or higher plans
Well-Architected Agent turns the familiar pile of Trusted Advisor and Security Hub findings into a shorter list ranked against goals you write in plain language, and each item comes with a fix you can review and run. That makes it most useful for multi-account AWS teams that already pay for Business Support+ or higher and struggle to prioritize optimization work, rather than for teams looking for an agent that changes infrastructure on its own. It is a preview with a beta application view, a 30-recommendation cap per run, and AI-written fixes that AWS itself says to verify. The sensible rollout is one profile with a few concrete goals, scoped to a non-production account first, with its remediation procedures checked through your normal change process.
Who should use it
AWS customers on Business Support+, Enterprise On-Ramp, Enterprise Support, or Unified Operations plans with multi-account environments, platform teams that want Well-Architected reviews on a schedule instead of once a year, and teams that keep infrastructure in Terraform or CDK and want reviews before deployment.
Who should skip it
Customers on Developer or Business support plans, teams running mainly on other clouds or on-premises, organizations that need profile data hosted outside the three US Regions, and teams that want an agent to apply changes autonomously.
Business Support+ (AWS Support plan)
From $29 per account
Billed monthly
Enterprise Support (AWS Support plan)
From $5,000
Billed monthly
Unified Operations (AWS Support plan)
From $50,000
Billed monthly
Note: AWS has not published a separate charge for Well-Architected Agent during the preview. It is delivered by AWS Support and available with Business Support+, Enterprise On-Ramp, Enterprise Support, or Unified Operations plans; the prices above are the AWS Support plan prices, not agent fees. Enterprise On-Ramp also allows 10 profiles and 30 applications per profile. Developer and Business plans have no access. Cost Explorer API requests and resource-level granular data, which the agent uses for accurate cost attribution, are billed separately.
API pricing
No separate API pricing published; API and AWS CLI access through the wellarchitected namespace for eligible AWS Support plan customers
Goal-driven cost reduction
A profile goal such as reducing EC2 spend by 20% ranks rightsizing and other cost findings by impact and effort, with dollar impact per resource where applicable. Enabling Cost Explorer resource-level data replaces estimates based on public pricing with your actual costs.
Pre-deployment IaC review
Uploading a Terraform or CDK project returns architecture recommendations and updated templates in the same language, catching gaps before they reach production.
Resilience hardening for critical databases
AWS's example recommendation adds multi-AZ failover to a critical database, with an SSM runbook and a cross-pillar view of the cost and performance effect before you commit.
AWS Well-Architected Agent and AWS DevOps Agent
AWS DevOps Agent responds to production incidents: it investigates alerts across observability, code, and ticketing tools, finds likely root causes, and recommends mitigations, billed per agent-second. AWS Well-Architected Agent works ahead of incidents, reviewing accounts and IaC on a schedule or on demand for cost, security, resilience, and performance gaps, as part of an eligible AWS Support plan. Teams can use Well-Architected Agent to reduce risks before they cause problems and DevOps Agent to investigate what still breaks.
AWS Well-Architected Agent and Kiro
Kiro is AWS's spec-driven agentic coding tool for writing and changing code in your repositories. Well-Architected Agent does not edit your repository. Its architecture reviews return updated Terraform or CDK templates and remediation steps that you apply yourself, so a coding agent such as Kiro can be where those changes are made and tested.
What is AWS Well-Architected Agent?
It is an AI-powered service from AWS Support that analyzes your AWS environment against Well-Architected best practices and returns prioritized recommendations for cost optimization, security, resilience, and performance. Recommendations are ranked against business goals you define and come with remediation steps. It launched in public preview on October 1, 2026.
How much does AWS Well-Architected Agent cost?
AWS has not published a separate price for the agent. It is delivered by AWS Support and available to customers on Business Support+, Enterprise On-Ramp, Enterprise Support, or Unified Operations plans. Business Support+ starts at $29 per month per account or a percentage of monthly AWS charges, whichever is greater. Enabling resource-level Cost Explorer data for more accurate cost findings has its own charges.
Does AWS Well-Architected Agent change my resources automatically?
Not for its AI-generated recommendations. Its IAM roles are read-only, and the console, CLI, SDK, and IaC remediation steps are advisory: you review and run them yourself. Recommendations derived from Trusted Advisor checks include pre-built Systems Manager runbooks that the agent can trigger with your consent or that you can schedule.
Does it replace AWS Trusted Advisor and the Well-Architected Tool?
AWS calls it the next-generation evolution of both. It ingests Trusted Advisor findings as baseline signals and runs inside the Well-Architected console. The Well-Architected Tool stays available for manual reviews with custom lenses, and AWS says both can be used at the same time.
Which infrastructure-as-code formats can it review?
The architecture review guide lists AWS CDK and Terraform projects, supplied as a .zip file of up to 25 MB or an S3 folder of up to 100 MB. The launch announcements and the concepts page also list CloudFormation templates. Updated templates come back in the same language as the input, and each profile can run five reviews per day.
Which AWS Regions does it support?
Agent profiles and recommendations are hosted in US East (N. Virginia), US East (Ohio), and US West (Oregon). From there, the agent can scan resources and onboard workloads in any commercial AWS Region.
AWS Well-Architected Agent vs AWS DevOps Agent: what is the difference?
AWS DevOps Agent is reactive: it investigates live incidents, finds likely root causes, and recommends mitigations. Well-Architected Agent is proactive: it reviews accounts and IaC on a schedule or on demand and recommends cost, security, resilience, and performance improvements. They cover different parts of operating on AWS.
AWS Well-Architected Agent entered public preview on October 1, 2026, and AWS describes it as the next-generation evolution of AWS Trusted Advisor and the AWS Well-Architected Tool. You open it from the Well-Architected console and create an agent profile: up to 100 AWS accounts, the Regions to scan, the pillars you care about (cost optimization, security, resilience, performance), and plain-text business goals such as reducing EC2 spend by 20%. The agent reads configurations, utilization metrics, and topology through read-only IAM roles you create in each account. It also builds on findings and signals from Trusted Advisor, Compute Optimizer, Security Hub CSPM, Resilience Hub, and Cost Optimization Hub, plus Cost Explorer data when you enable it. It then ranks recommendations by impact and effort against those goals. Recommendations come at three levels. Resource findings target one resource and show dollar impact where applicable. Application findings span related resources and are still in beta. Architecture findings come from on-demand reviews of Terraform or AWS CDK projects uploaded through Amazon S3, and the agent returns updated templates in the same language. Each recommendation lists cross-pillar effects and trade-offs, and Start remediation produces a resource-specific procedure for the console, the AWS CLI, or Python SDK code that you can download for a change ticket. The agent does not run its AI-generated fixes itself. Only recommendations derived from Trusted Advisor checks come with pre-built Systems Manager runbooks, which can run with your consent or on a schedule. What sets it apart from generic checklists is the goal-based ranking and the ready-made fix for each finding. The tradeoffs are access and scope. The agent is limited to customers on Business Support+, Enterprise On-Ramp, Enterprise Support, or Unified Operations plans. It covers AWS only, profiles can be hosted only in three US Regions, and output is capped at 30 recommendations per run and five architecture reviews per profile per day. AWS also warns that its AI-generated output may contain errors.
AWS launched Well-Architected Agent in public preview as the next-generation evolution of AWS Trusted Advisor and the Well-Architected Tool. It offers goal-ranked resource, application, and architecture recommendations, IaC reviews, and SSM runbook, CLI, and console remediation, for customers on Business Support+ or higher AWS Support plans, with profiles hosted in US East (N. Virginia), US East (Ohio), and US West (Oregon).
Are you the founder? Claim this listing →