AWS Turns Well-Architected Into an Agent: What the October 2026 Preview Actually Gets You

Sources

On October 1, 2026, AWS stopped pretending the Well-Architected Framework was something you review twice a year. The new AWS Well-Architected Agent — public preview, announced by Channy Yun on the AWS News Blog — scans your deployed accounts and infrastructure-as-code, ranks findings against goals you declare, and ships remediation with each recommendation. AWS frames it as the agent that "evaluates your environment as an experienced cloud architect would." The Register's take was drier: an agent that "recommends cloudy reconfigs," gated behind a paid support plan.

This guide is a launch-week teardown, not a review. Nobody has run this agent in production for longer than a weekend, and we won't pretend otherwise. What we can do — and do here — is read the actual preview documentation: what the agent reads, what it costs to unlock, where its quotas bite, and which teams should ignore it entirely.

TL;DR

What actually shipped on October 1

Three things landed at once, and most coverage collapsed them into one:

  1. A new service surface — the Agent itself, in the Well-Architected console and the wellarchitected CLI namespace, with new API actions (CreateAgentProfile, CreateAgentGoal, CreateAgentContext, StartAgentRecommendationGeneration, PutAgentRecommendationFeedback, UpdateAgentRecommendationStatus).
  2. A docs restructure — the user guide now opens with an explicit two-track choice: the AI Agent for continuous optimization, the Tool for structured manual reviews. The comparison table below is lifted from that restructure.
  3. The quiet repositioning of Trusted Advisor — the Agent "ingests findings from services such as AWS Trusted Advisor and adds personalization, goal-aligned prioritization, and automation-ready remediation." In other words, the flat checklist era of Trusted Advisor is now the input layer, not the product.

The announcement's three claimed differentiators are consistent across the blog and docs: goal-aligned intelligence (you declare business objectives; recommendations are ranked by impact and effort against them), three-level recommendations (individual resources with dollar impact, consolidated findings scoped to an application, and architecture-level patterns with IaC changes), and optionality in remediation (console walkthrough, updated IaC templates, or CLI commands). AWS also says the agent analyzes best practices "across 65+ AWS services" — note that The AI Economy's launch coverage says "more than 100"; we treat 65+ as the official figure and the discrepancy as a preview-era ambiguity worth pinning down before you write a compliance memo either way.

The 2026 state of the framework: what changed before the agent showed up

The Agent did not appear in a vacuum. The Framework's six pillars — operational excellence, security, reliability, performance efficiency, cost optimization, sustainability — are stable in the current framework edition (2025-02-25), and AWS stated in late 2024 that 100% of best practices had been refreshed at least once since October 2022. What actually moved in 2026 is the lens portfolio — the workload-specific extensions reviewers use — and then, suddenly, the review mechanism itself:

DateWell-Architected changeWhy it matters
Nov 19, 2025Generative AI Lens (updated edition)GenAI workloads got dedicated review guidance before the agent existed
Dec 30, 2025Life Sciences + Telecommunications lensesVertical lenses keep multiplying — the manual review burden keeps growing with them
Jan 27, 2026Financial Services Industry lensSame pattern, regulated vertical
Feb 2, 2026Hybrid Networking + Microsoft workloads lensesAWS reviewing workloads that run someone else's software — a tell about enterprise reality
Jun 10, 2026Agentic AI LensThe framework's first lens for running agents in production — published four months before AWS shipped its own agent
Sep 15, 2026Digital Sovereignty Lens (updated)"Sovereignty is a posture, not a product" — the docs' own line, and directly relevant to where the Agent hosts its profiles
Oct 1, 2026Well-Architected Agent previewThe review process itself becomes a continuously running AWS service

Read that table as one arc: the lens catalog grew faster than any team's capacity to run manual reviews against it. The Agentic AI Lens alone asks teams to review agent systems "reliably, securely, and cost-effectively at scale" — exactly the kind of review that a human architect schedules twice a year and dreads. The Agent is AWS's answer to the review backlog its own lens strategy created. Jill Fariss, Amazon's VP for AWS Support, was blunt about the pain in her launch-week interview with The AI Economy: "Previously, teams had to manually stitch together findings from multiple disconnected tools, then triage hundreds of flat, undifferentiated alerts to figure out what actually mattered. Most of those alerts get missed or ignored because there's no prioritization."

How the agent works: profile, scan, recommend, remediate

The operating model is a four-step loop, and the console walkthrough and API quickstart describe the same flow:

flowchart TB
    SETUP["You: create agent profile
accounts + Regions + pillars + goals"] IAM["Your side: execution role in the scanning account
+ access roles in each workload account"] SCAN["Agent scans: utilization metrics,
resource configurations, application topology
across all commercial Regions"] TA["Ingests existing findings
from AWS Trusted Advisor"] IAC["Optional: upload IaC project
Terraform / CloudFormation / CDK
for pre-deployment review"] RECS["Recommendations at 3 levels:
resource (with dollar impact)
application (beta)
architecture (with IaC changes)"] GOALS["Goals + trade-off analysis rank the list
10 goals per profile, 30 recs per run"] REMED["You pick: console walkthrough,
updated IaC template, or CLI commands"] WEEK["Scheduler re-runs generation
on a weekly cadence"] SETUP --> IAM IAM --> SCAN TA --> RECS SCAN --> RECS IAC --> RECS RECS --> GOALS GOALS --> REMED WEEK --> SCAN

Two timing numbers in the launch materials disagree with each other, and both matter operationally. The blog says recommendations appear "within 24 hours after profile creation"; the getting-started doc says "within 48 hours." Plan for the worse number. After that first run, scheduled recommendations refresh on a weekly cadence — this is continuous-ish, not a control loop. A misconfigured security group found on Monday may not surface in a scheduled recommendation until the next weekly generation; the architecture-review path (on-demand, against uploaded IaC) is your escape hatch, capped at 5 runs per profile per day.

The CLI surface is real and scriptable today — the preview docs publish working commands:

aws wellarchitected create-agent-profile \
  --name "my-production-profile" \
  --execution-role-arn "arn:aws:iam::111122223333:role/service-role/ExecutionRoleForWellArchitectedAgent" \
  --pillars COST_OPTIMIZATION SECURITY RESILIENCE PERFORMANCE \
  --aggregation-configuration '[{"accountId":"444455556666","accessRoleArn":"arn:aws:iam::444455556666:role/AccessRoleForWellArchitectedAgent","regions":["us-east-1","us-west-2"]}]'

aws wellarchitected create-agent-goal \
  --profile-arn "arn:aws:wellarchitected:us-east-1:111122223333:agent-profile/my-production-profile" \
  --title "Reduce EC2 spend by 20% by Q4 through rightsizing and Reserved Instance coverage" \
  --pillars COST_OPTIMIZATION

Note what the API quickstart is careful to say: the API does not create IAM roles for you. The execution role and the per-account access roles are yours to provision and trust-chain before any scanning starts. That is the right design — but it means "agent" here means "analysis engine," not "autonomous actor." It reads, ranks, and writes remediation packages; it does not apply them.

The paywall: what the agent actually costs to unlock

There is no Agent line item on your bill. The price is your AWS Support plan, and the entitlements differ sharply by tier:

Support tierAgent accessMax profilesMax applications per profileSupport plan price mechanics
DeveloperNo———
BusinessNo———
Business+Yes27$29/mo per account floor, or tiered % of AWS charges (9% up to $10K, 7% to $80K, 5% to $250K, 3% above)
Enterprise On-RampYes1030Percentage of monthly AWS charges
Enterprise SupportYes1030$5K/mo floor, or tiered % (10% up to $150K, 7% to $500K, 5% to $1M, 3% above)
Unified OperationsYes1030$50K/mo floor, or tiered % (10% up to $1M, 6% to $5M, 5% above)

Run the numbers on the support plans people actually hold (Decimal-verified against AWS's own worked pricing examples, 2026-10-02):

ScenarioMonthly AWS chargesSupport cost to unlock the AgentEffective rate on spend
Business+ (AWS's own example)$20,000$1,600/mo ($19,200/yr)8.0%
Business+ theoretical floorTiny$29/mo ($348/yr)—
Enterprise Support (AWS's own example)$750,000$52,000/mo6.9%
Unified Operations (AWS's own example)$1,500,000$130,000/mo8.7%

Two things follow. First, for teams already on Business+ or above, the Agent is marginal-cost-free — you are paying for support anyway, and this is a genuine new entitlement in the same bucket. Second, for everyone else, the question "is the Agent worth it?" is really "is upgrading our support tier worth it?", which is a procurement question about response times and TAM access, not about architecture reviews. Do not let a shiny agent flip that decision by itself. And remember the denominator problem: the free Well-Architected Tool remains available at no cost in the console, and the Agent's own quotas page says Business+ customers get two profiles with seven applications each. The paid tier buys you the analysis engine, not unlimited scope.

What it reads: the managed policy tells the truth

The docs' security note is a single line — "provision customer-managed IAM roles the agent uses to read resource configurations, utilization metrics, and application topology" — but the WellArchitectedAgentResourceScanning managed policy (v2, created July 16, 2026, last edited September 30, 2026) is the ground truth, and it is broad. It grants read-only access to "AWS resource configurations, security settings, and operational data," including: IAM Access Analyzer enumeration, CloudTrail describe/get, CloudWatch metrics and alarm reads, Cost Explorer cost queries (ce:GetCostAndUsage, ce:GetCostAndUsageWithResources), and full Get/List sweeps across dozens of service namespaces — Bedrock included (bedrock:Get*, plus bedrock-agentcore and even aws-external-anthropic namespaces, a reminder that your Claude-on-Bedrock estate is part of the scannable surface now).

Everything is read-only. Nothing in the policy grants write or admin actions. But "read-only" at this breadth is still an audit-grade vantage point across up to 100 accounts, and the blast radius question is not "can it change things" (it can't) but "where does a correlated copy of my security posture and cost data live." Which brings us to the residency fact the announcement buries: agent profiles are hosted only in US East (N. Virginia), US East (Ohio), or US West (Oregon). From those hosting regions the agent scans all commercial Regions — but the profile itself, the thing that defines scope and holds the goal configuration, is a US-hosted artifact. If you spent September reading the updated Digital Sovereignty Lens (whose own preamble insists "sovereignty is a posture, not a product"), the tension writes itself. EU teams with residency commitments should get an explicit answer from their account team before pointing this at regulated accounts.

The quotas page also publishes an honest list of unsupported CloudFormation resource types — the agent will not retrieve configuration data for them. It is a long list, and it includes things platform teams care about: AppConfig deployments, Application Auto Scaling targets and policies, API Gateway method-level resources, AppSync associations, Keyspaces (Cassandra) keyspaces and types, Cost Anomaly monitors, Bedrock guardrail versions, CloudFormation module and publisher resources. If your estate leans on those resource types, the agent is structurally blind to them and its "everything is fine" moments there are actually "everything is invisible." That list, more than any launch blog sentence, defines the preview's current boundary.

Agent vs. Tool vs. doing it yourself

AWS's own docs now open with the two-track comparison, and it is worth taking at face value:

Well-Architected AgentWell-Architected ToolManual/partner review
ApproachAutomated, AI-powered analysis of deployed resources and IaC templatesManual, guided self-review against the FrameworkHuman architect(s) + workshop days
Primary entityProfile (accounts, Regions, pillars, goals)Workload (documented components delivering business value)Workload + org context
OutputPrioritized recommendations with trade-off analysis, automation scripts, updated IaCHigh/medium-risk issues and an improvement plan from your answersFindings, roadmap, and the political weight to fund it
CadenceWeekly scheduled + on-demand IaC reviews (5/day)Whenever you run it — AWS suggests design phase and pre-launch milestonesQuarterly-ish, if your budget survives
CostIncluded with Business+ support and above (the support plan is the cost)No costConsulting day rates
Best atContinuous optimization of a large deployed estateStructured governance, milestones, custom lenses, the paper trailJudgment calls the other two can't make

The interesting line is the last one. The Agent's trade-off analysis — each recommendation "describes trade-offs that occur from implementing the recommendation, including pillar, risk level, and mitigation strategy" — is the feature that separates it from every flat checklist that came before, and it is the feature most likely to be mediocre in a preview. The Register's skeptical frame — its correspondent reports IT pros "express distrust" of machine recommendations they cannot validate, and that even vendors expect adoption to start with cautious verification and "the ability to quickly roll back changes" — is not Luddism; it is the correct initial posture. AWS itself put the beta label on the application-level findings and the review-everything warning on the whole output. On Hacker News, the launch thread drew two points and no comments in its first hours — the community has seen AI-assisted cloud review tools before, and is waiting for receipts.

When NOT to use it: the honest verdicts

What to actually do this week

  1. If you're already on Business+: create one profile over your noisiest accounts, declare two goals (one cost, one resilience), and treat the first weekly run as a calibration exercise — how many of the 30 recommendations would your team have flagged anyway? That ratio is the real product evaluation.
  2. Wire the API into your workflow, not your browser: ListAgentRecommendations on a schedule, PutAgentRecommendationFeedback to close the loop, and the AWS MCP Server integration to pull recommendations into the coding tools your engineers already live in. The blog explicitly suggests this, and it is the least-hyped, most useful sentence in the announcement.
  3. Use the IaC review path for new builds — 5 runs/day against a 25 MB upload is enough for a CI gate on medium-sized Terraform repos, and pre-deployment is where recommendations are cheapest to act on. That is the same shift-left logic we dissected in The Shift-Left Lie — with the difference that here the tooling, not the slogan, does the moving.
  4. Keep the Tool anyway — custom lenses, milestones, and the documented review paper trail remain the governance artifact auditors and leadership recognize. The Agent generates remediation packages; it does not generate organizational consensus.

The bottom line

The Well-Architected Agent is the most consequential thing to happen to the Framework since the Sustainability pillar, because it changes the unit of consumption from "a review you schedule" to "a service that runs." The preview's own documentation is refreshingly candid about what it is not: not autonomous, not exhaustive, not a replacement for judgment, and not available to most support tiers. The teams that win this week are the ones already paying Enterprise-level support bills with hundred-account estates and a goal stack to rank against; the teams that should wait are everyone else — including anyone who would upgrade a support plan to get an AI auditor. Sixty-five-plus services of read-only coverage, a weekly cadence, and a beta label on the feature that makes it different. That is a solid start, honestly labeled. Take the label seriously.

References & further reading