AWS Turns Well-Architected Into an Agent: What the October 2026 Preview Actually Gets You
Sources
- Announcing AWS Well-Architected Agent (preview) — AWS News Blog, Channy Yun, Oct 1, 2026
- AWS Well-Architected Agent is now available in preview — AWS What's New, Oct 1, 2026
- What is AWS Well-Architected? — official docs (Agent vs. Tool comparison), updated Oct 1, 2026
- What is AWS Well-Architected Agent (preview)? — capabilities, availability, Business+ gate
- AWS Well-Architected Agent Quotas and limits — tier entitlements and default limits
- AWS Support pricing — Business+, Enterprise, Unified Operations rate cards
- WellArchitectedAgentResourceScanning AWS managed policy (v2) — the agent's actual read surface
- AWS Well-Architected Agentic AI Lens — publication date June 10, 2026
- AWS Well-Architected Digital Sovereignty Lens — last updated September 15, 2026
- The pillars of the framework — AWS Well-Architected Framework (2025-02-25 edition)
- AWS turns its best practice framework into an agent — The Register, Simon Sharwood, Oct 2, 2026
- AWS Built an AI Agent That Audits Your Cloud Setup — The AI Economy, Ken Yeung, Oct 1, 2026 (Jill Fariss interview)
On October 1, 2026, AWS stopped pretending the Well-Architected Framework was something you review twice a year. The new AWS Well-Architected Agent — public preview, announced by Channy Yun on the AWS News Blog — scans your deployed accounts and infrastructure-as-code, ranks findings against goals you declare, and ships remediation with each recommendation. AWS frames it as the agent that "evaluates your environment as an experienced cloud architect would." The Register's take was drier: an agent that "recommends cloudy reconfigs," gated behind a paid support plan.
This guide is a launch-week teardown, not a review. Nobody has run this agent in production for longer than a weekend, and we won't pretend otherwise. What we can do — and do here — is read the actual preview documentation: what the agent reads, what it costs to unlock, where its quotas bite, and which teams should ignore it entirely.
TL;DR
- The Agent is a continuous, goal-ranked audit of up to 100 AWS accounts per profile, refreshing recommendations weekly — versus the Well-Architected Tool, which remains a free, manual, question-driven review you run yourself at milestones.
- Access is paywalled behind AWS Support at Business+ or higher. Developer and Business tier customers are excluded outright. The cheapest theoretical door in is the Business+ floor: $29/month per account — $348/year — before any percentage-of-spend kicks in.
- Preview caps are real: 2 profiles and 7 applications on Business+ (10/30 on Enterprise tiers), 30 recommendations per generation run, 5 architecture reviews per day, 25 MB upload ceiling.
- The IAM surface is a read-only scanning policy — but it reads a lot: configurations, security settings, CloudTrail, Cost Explorer usage, across all commercial Regions.
- Two honest catches before you get excited: application-level recommendations are explicitly beta, and AWS's own docs carry an Important box telling you to "thoroughly review each recommendation before taking any action." That sentence is the product's real maturity statement.
- Skip it if you're on Developer/Business support, run fewer than a handful of accounts, or have data-residency constraints that make US-hosted profile regions a problem.
What actually shipped on October 1
Three things landed at once, and most coverage collapsed them into one:
- A new service surface — the Agent itself, in the Well-Architected console and the
wellarchitectedCLI namespace, with new API actions (CreateAgentProfile,CreateAgentGoal,CreateAgentContext,StartAgentRecommendationGeneration,PutAgentRecommendationFeedback,UpdateAgentRecommendationStatus). - A docs restructure — the user guide now opens with an explicit two-track choice: the AI Agent for continuous optimization, the Tool for structured manual reviews. The comparison table below is lifted from that restructure.
- The quiet repositioning of Trusted Advisor — the Agent "ingests findings from services such as AWS Trusted Advisor and adds personalization, goal-aligned prioritization, and automation-ready remediation." In other words, the flat checklist era of Trusted Advisor is now the input layer, not the product.
The announcement's three claimed differentiators are consistent across the blog and docs: goal-aligned intelligence (you declare business objectives; recommendations are ranked by impact and effort against them), three-level recommendations (individual resources with dollar impact, consolidated findings scoped to an application, and architecture-level patterns with IaC changes), and optionality in remediation (console walkthrough, updated IaC templates, or CLI commands). AWS also says the agent analyzes best practices "across 65+ AWS services" — note that The AI Economy's launch coverage says "more than 100"; we treat 65+ as the official figure and the discrepancy as a preview-era ambiguity worth pinning down before you write a compliance memo either way.
The 2026 state of the framework: what changed before the agent showed up
The Agent did not appear in a vacuum. The Framework's six pillars — operational excellence, security, reliability, performance efficiency, cost optimization, sustainability — are stable in the current framework edition (2025-02-25), and AWS stated in late 2024 that 100% of best practices had been refreshed at least once since October 2022. What actually moved in 2026 is the lens portfolio — the workload-specific extensions reviewers use — and then, suddenly, the review mechanism itself:
| Date | Well-Architected change | Why it matters |
|---|---|---|
| Nov 19, 2025 | Generative AI Lens (updated edition) | GenAI workloads got dedicated review guidance before the agent existed |
| Dec 30, 2025 | Life Sciences + Telecommunications lenses | Vertical lenses keep multiplying — the manual review burden keeps growing with them |
| Jan 27, 2026 | Financial Services Industry lens | Same pattern, regulated vertical |
| Feb 2, 2026 | Hybrid Networking + Microsoft workloads lenses | AWS reviewing workloads that run someone else's software — a tell about enterprise reality |
| Jun 10, 2026 | Agentic AI Lens | The framework's first lens for running agents in production — published four months before AWS shipped its own agent |
| Sep 15, 2026 | Digital Sovereignty Lens (updated) | "Sovereignty is a posture, not a product" — the docs' own line, and directly relevant to where the Agent hosts its profiles |
| Oct 1, 2026 | Well-Architected Agent preview | The review process itself becomes a continuously running AWS service |
Read that table as one arc: the lens catalog grew faster than any team's capacity to run manual reviews against it. The Agentic AI Lens alone asks teams to review agent systems "reliably, securely, and cost-effectively at scale" — exactly the kind of review that a human architect schedules twice a year and dreads. The Agent is AWS's answer to the review backlog its own lens strategy created. Jill Fariss, Amazon's VP for AWS Support, was blunt about the pain in her launch-week interview with The AI Economy: "Previously, teams had to manually stitch together findings from multiple disconnected tools, then triage hundreds of flat, undifferentiated alerts to figure out what actually mattered. Most of those alerts get missed or ignored because there's no prioritization."
How the agent works: profile, scan, recommend, remediate
The operating model is a four-step loop, and the console walkthrough and API quickstart describe the same flow:
flowchart TB
SETUP["You: create agent profile
accounts + Regions + pillars + goals"]
IAM["Your side: execution role in the scanning account
+ access roles in each workload account"]
SCAN["Agent scans: utilization metrics,
resource configurations, application topology
across all commercial Regions"]
TA["Ingests existing findings
from AWS Trusted Advisor"]
IAC["Optional: upload IaC project
Terraform / CloudFormation / CDK
for pre-deployment review"]
RECS["Recommendations at 3 levels:
resource (with dollar impact)
application (beta)
architecture (with IaC changes)"]
GOALS["Goals + trade-off analysis rank the list
10 goals per profile, 30 recs per run"]
REMED["You pick: console walkthrough,
updated IaC template, or CLI commands"]
WEEK["Scheduler re-runs generation
on a weekly cadence"]
SETUP --> IAM
IAM --> SCAN
TA --> RECS
SCAN --> RECS
IAC --> RECS
RECS --> GOALS
GOALS --> REMED
WEEK --> SCAN
Two timing numbers in the launch materials disagree with each other, and both matter operationally. The blog says recommendations appear "within 24 hours after profile creation"; the getting-started doc says "within 48 hours." Plan for the worse number. After that first run, scheduled recommendations refresh on a weekly cadence — this is continuous-ish, not a control loop. A misconfigured security group found on Monday may not surface in a scheduled recommendation until the next weekly generation; the architecture-review path (on-demand, against uploaded IaC) is your escape hatch, capped at 5 runs per profile per day.
The CLI surface is real and scriptable today — the preview docs publish working commands:
aws wellarchitected create-agent-profile \
--name "my-production-profile" \
--execution-role-arn "arn:aws:iam::111122223333:role/service-role/ExecutionRoleForWellArchitectedAgent" \
--pillars COST_OPTIMIZATION SECURITY RESILIENCE PERFORMANCE \
--aggregation-configuration '[{"accountId":"444455556666","accessRoleArn":"arn:aws:iam::444455556666:role/AccessRoleForWellArchitectedAgent","regions":["us-east-1","us-west-2"]}]'
aws wellarchitected create-agent-goal \
--profile-arn "arn:aws:wellarchitected:us-east-1:111122223333:agent-profile/my-production-profile" \
--title "Reduce EC2 spend by 20% by Q4 through rightsizing and Reserved Instance coverage" \
--pillars COST_OPTIMIZATION
Note what the API quickstart is careful to say: the API does not create IAM roles for you. The execution role and the per-account access roles are yours to provision and trust-chain before any scanning starts. That is the right design — but it means "agent" here means "analysis engine," not "autonomous actor." It reads, ranks, and writes remediation packages; it does not apply them.
The paywall: what the agent actually costs to unlock
There is no Agent line item on your bill. The price is your AWS Support plan, and the entitlements differ sharply by tier:
| Support tier | Agent access | Max profiles | Max applications per profile | Support plan price mechanics |
|---|---|---|---|---|
| Developer | No | — | — | — |
| Business | No | — | — | — |
| Business+ | Yes | 2 | 7 | $29/mo per account floor, or tiered % of AWS charges (9% up to $10K, 7% to $80K, 5% to $250K, 3% above) |
| Enterprise On-Ramp | Yes | 10 | 30 | Percentage of monthly AWS charges |
| Enterprise Support | Yes | 10 | 30 | $5K/mo floor, or tiered % (10% up to $150K, 7% to $500K, 5% to $1M, 3% above) |
| Unified Operations | Yes | 10 | 30 | $50K/mo floor, or tiered % (10% up to $1M, 6% to $5M, 5% above) |
Run the numbers on the support plans people actually hold (Decimal-verified against AWS's own worked pricing examples, 2026-10-02):
| Scenario | Monthly AWS charges | Support cost to unlock the Agent | Effective rate on spend |
|---|---|---|---|
| Business+ (AWS's own example) | $20,000 | $1,600/mo ($19,200/yr) | 8.0% |
| Business+ theoretical floor | Tiny | $29/mo ($348/yr) | — |
| Enterprise Support (AWS's own example) | $750,000 | $52,000/mo | 6.9% |
| Unified Operations (AWS's own example) | $1,500,000 | $130,000/mo | 8.7% |
Two things follow. First, for teams already on Business+ or above, the Agent is marginal-cost-free — you are paying for support anyway, and this is a genuine new entitlement in the same bucket. Second, for everyone else, the question "is the Agent worth it?" is really "is upgrading our support tier worth it?", which is a procurement question about response times and TAM access, not about architecture reviews. Do not let a shiny agent flip that decision by itself. And remember the denominator problem: the free Well-Architected Tool remains available at no cost in the console, and the Agent's own quotas page says Business+ customers get two profiles with seven applications each. The paid tier buys you the analysis engine, not unlimited scope.
What it reads: the managed policy tells the truth
The docs' security note is a single line — "provision customer-managed IAM roles the agent uses to read resource configurations, utilization metrics, and application topology" — but the WellArchitectedAgentResourceScanning managed policy (v2, created July 16, 2026, last edited September 30, 2026) is the ground truth, and it is broad. It grants read-only access to "AWS resource configurations, security settings, and operational data," including: IAM Access Analyzer enumeration, CloudTrail describe/get, CloudWatch metrics and alarm reads, Cost Explorer cost queries (ce:GetCostAndUsage, ce:GetCostAndUsageWithResources), and full Get/List sweeps across dozens of service namespaces — Bedrock included (bedrock:Get*, plus bedrock-agentcore and even aws-external-anthropic namespaces, a reminder that your Claude-on-Bedrock estate is part of the scannable surface now).
Everything is read-only. Nothing in the policy grants write or admin actions. But "read-only" at this breadth is still an audit-grade vantage point across up to 100 accounts, and the blast radius question is not "can it change things" (it can't) but "where does a correlated copy of my security posture and cost data live." Which brings us to the residency fact the announcement buries: agent profiles are hosted only in US East (N. Virginia), US East (Ohio), or US West (Oregon). From those hosting regions the agent scans all commercial Regions — but the profile itself, the thing that defines scope and holds the goal configuration, is a US-hosted artifact. If you spent September reading the updated Digital Sovereignty Lens (whose own preamble insists "sovereignty is a posture, not a product"), the tension writes itself. EU teams with residency commitments should get an explicit answer from their account team before pointing this at regulated accounts.
The quotas page also publishes an honest list of unsupported CloudFormation resource types — the agent will not retrieve configuration data for them. It is a long list, and it includes things platform teams care about: AppConfig deployments, Application Auto Scaling targets and policies, API Gateway method-level resources, AppSync associations, Keyspaces (Cassandra) keyspaces and types, Cost Anomaly monitors, Bedrock guardrail versions, CloudFormation module and publisher resources. If your estate leans on those resource types, the agent is structurally blind to them and its "everything is fine" moments there are actually "everything is invisible." That list, more than any launch blog sentence, defines the preview's current boundary.
Agent vs. Tool vs. doing it yourself
AWS's own docs now open with the two-track comparison, and it is worth taking at face value:
| Well-Architected Agent | Well-Architected Tool | Manual/partner review | |
|---|---|---|---|
| Approach | Automated, AI-powered analysis of deployed resources and IaC templates | Manual, guided self-review against the Framework | Human architect(s) + workshop days |
| Primary entity | Profile (accounts, Regions, pillars, goals) | Workload (documented components delivering business value) | Workload + org context |
| Output | Prioritized recommendations with trade-off analysis, automation scripts, updated IaC | High/medium-risk issues and an improvement plan from your answers | Findings, roadmap, and the political weight to fund it |
| Cadence | Weekly scheduled + on-demand IaC reviews (5/day) | Whenever you run it — AWS suggests design phase and pre-launch milestones | Quarterly-ish, if your budget survives |
| Cost | Included with Business+ support and above (the support plan is the cost) | No cost | Consulting day rates |
| Best at | Continuous optimization of a large deployed estate | Structured governance, milestones, custom lenses, the paper trail | Judgment calls the other two can't make |
The interesting line is the last one. The Agent's trade-off analysis — each recommendation "describes trade-offs that occur from implementing the recommendation, including pillar, risk level, and mitigation strategy" — is the feature that separates it from every flat checklist that came before, and it is the feature most likely to be mediocre in a preview. The Register's skeptical frame — its correspondent reports IT pros "express distrust" of machine recommendations they cannot validate, and that even vendors expect adoption to start with cautious verification and "the ability to quickly roll back changes" — is not Luddism; it is the correct initial posture. AWS itself put the beta label on the application-level findings and the review-everything warning on the whole output. On Hacker News, the launch thread drew two points and no comments in its first hours — the community has seen AI-assisted cloud review tools before, and is waiting for receipts.
When NOT to use it: the honest verdicts
- If you're on Developer or Business support — don't upgrade for this. The $29/mo floor sounds cheap; the tiered percentages behind it are not. AWS's own worked example has Business+ at $1,600/mo on a $20K estate. If support-plan economics weren't already justified by response times and TAM access, an architecture agent does not tip them.
- If your estate is small — a handful of accounts, one product — the free Tool plus a partner review once a year does the same job with human accountability attached. A 30-recommendations-per-run cap over seven applications is generous only if you have seven applications that matter.
- If you need true continuous control — this is weekly plus on-demand. It is not a policy engine and not a drift detector; if your problem is "stop the bad deploy," you want OPA/Kyverno in the pipeline, not a Monday-morning audit. We compared those trade-offs in our Kyverno vs. OPA Gatekeeper guide.
- If you're multi-cloud — the lens is AWS-only, and Microsoft and Google publish their own frameworks (Azure Well-Architected, Google Cloud's Well-Architected Framework). A GCP estate gets nothing from this agent; our three-cloud comparison covers the divergence.
- If data residency is a hard constraint — US-hosted profiles scanning your EU accounts is a conversation with your DPO before it is a console walkthrough. Get the answer in writing.
- If your estate leans on the unsupported resource list — AppConfig, AppSync, Keyspaces, Application Auto Scaling targets, and friends are invisible to the current preview. An agent that cannot see your autoscaling policies will happily recommend around them.
What to actually do this week
- If you're already on Business+: create one profile over your noisiest accounts, declare two goals (one cost, one resilience), and treat the first weekly run as a calibration exercise — how many of the 30 recommendations would your team have flagged anyway? That ratio is the real product evaluation.
- Wire the API into your workflow, not your browser:
ListAgentRecommendationson a schedule,PutAgentRecommendationFeedbackto close the loop, and the AWS MCP Server integration to pull recommendations into the coding tools your engineers already live in. The blog explicitly suggests this, and it is the least-hyped, most useful sentence in the announcement. - Use the IaC review path for new builds — 5 runs/day against a 25 MB upload is enough for a CI gate on medium-sized Terraform repos, and pre-deployment is where recommendations are cheapest to act on. That is the same shift-left logic we dissected in The Shift-Left Lie — with the difference that here the tooling, not the slogan, does the moving.
- Keep the Tool anyway — custom lenses, milestones, and the documented review paper trail remain the governance artifact auditors and leadership recognize. The Agent generates remediation packages; it does not generate organizational consensus.
The bottom line
The Well-Architected Agent is the most consequential thing to happen to the Framework since the Sustainability pillar, because it changes the unit of consumption from "a review you schedule" to "a service that runs." The preview's own documentation is refreshingly candid about what it is not: not autonomous, not exhaustive, not a replacement for judgment, and not available to most support tiers. The teams that win this week are the ones already paying Enterprise-level support bills with hundred-account estates and a goal stack to rank against; the teams that should wait are everyone else — including anyone who would upgrade a support plan to get an AI auditor. Sixty-five-plus services of read-only coverage, a weekly cadence, and a beta label on the feature that makes it different. That is a solid start, honestly labeled. Take the label seriously.
References & further reading
- Announcing AWS Well-Architected Agent (preview) — AWS News Blog, Channy Yun, Oct 1, 2026 — the primary announcement
- AWS Well-Architected Agent is now available in preview — AWS What's New, Oct 1, 2026
- What is AWS Well-Architected Agent (preview)? — capabilities, weekly cadence, Business+ gate, 100-account profiles
- AWS Well-Architected Agent Quotas and limits — tier entitlements table, 30 recs/run, unsupported resource types
- API quickstart — the real CLI commands for profiles and goals
- API actions — the full wellarchitected namespace split between Agent and Tool actions
- WellArchitectedAgentResourceScanning managed policy — the agent's actual read surface, v2
- AWS Support pricing — Business+, Enterprise, Unified Operations rate cards and worked examples
- The pillars of the framework — current framework edition (2025-02-25)
- AWS Well-Architected Agentic AI Lens — June 10, 2026
- Digital Sovereignty Lens — updated September 15, 2026
- AWS turns its best practice framework into an agent — The Register, Simon Sharwood, Oct 2, 2026
- AWS Built an AI Agent That Audits Your Cloud Setup and Writes the Fixes — The AI Economy, Ken Yeung, Oct 1, 2026, incl. the Jill Fariss interview
- Hacker News thread — launch-day reception (2 points, 0 comments at time of writing)