Build2 publishers2 min readPublished
AWS's Well-Architected Agent reviews live accounts across 65+ services against goals teams declare
AWS opened a preview of Well-Architected Agent, a service that reads live accounts across 65+ services and ranks fixes against goals each team declares. The review becomes a job run against the real environment, and every fix comes back as code or commands for the team to apply.
The Engineer · Build desk

What happened
- An agent profile sets the accounts or Regions to monitor, the pillars to focus on, and a goal for each of cost, performance, resilience and security.
- Teams can review a workload before deployment by uploading a .zip of a Terraform, CloudFormation or CDK project and choosing a Well-Architected lens.
- Optional application context, built from accounts, Regions, services and resource tags, narrows the scope and, AWS says, makes recommendations more relevant.
- Each recommendation opens to the agent's reasoning, its impact and trade-offs, and a recommended fix.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure The agent becomes a new principal reading configuration, metrics and topology for every account in scope, so the security team has to sign off on the IAM role's reach before the architects get a review.
- capability A review meeting can start from a list already ordered by the team's own goals, with the cross-pillar trade-off stated on each item.
- constraint With first results up to a day after setup, the live review fits a periodic cadence; catching a problem before it ships depends on the IaC upload path.
- decision Teams whose infrastructure lives in Terraform or CDK have to take the IaC output over console and CLI fixes, or the change lands outside the files that define the resource.
The review starts with access. The customer provisions IAM roles, and the agent uses them to read resource configurations, utilization metrics and application topology [5]. The agent profile also records the permissions required, next to the accounts and pillars in scope [4]. Whoever owns those roles decides how much of the estate the agent can see.
With that access, the agent correlates the three data sets and checks them against Well-Architected best practices across 65+ AWS services [2]. AWS contrasts this with "generic checklists" [14]. Joining utilization to configuration lets a finding name a single resource. AWS says those findings carry a specific dollar impact where applicable, plus step-by-step remediation [9]. Above that, the agent consolidates findings across the resources of one application, then proposes architectural patterns with the IaC changes needed to reach them [9].
The declared goals come in at the ranking step. The agent orders recommendations by impact and effort against the objectives the team states [3], and it surfaces trade-offs between pillars [11]. The post does not say how impact and effort are weighted against each other. I'd expect vague goals to produce a vague ranking.
Timing decides where this fits. Resource and application recommendations arrive within 24 hours of creating the profile [6]. A day's wait suits a monthly or quarterly review better than a pre-merge check.
AWS's post says the agent "evaluates your environment as an experienced cloud architect would" [12]. An experienced architect would also ask for read access before saying anything, so the comparison at least holds for setup. For the claim to hold on a given account, the agent's findings there would have to match what a human reviewer finds. Its ranking would also have to follow the trade-offs that team actually accepts. The post describes the agent's behaviour but does not report a comparison of that kind.
Remediation comes in three forms: console walk-throughs, updated IaC for architecture-level recommendations, and AWS CLI commands [10]. For an estate defined in Terraform or CDK, I'd take the IaC output and treat the other two as reference. A console or CLI fix changes the live resource and leaves the code that defines it unchanged. The service is in public preview [1].
What to watch
- Pricing and any per-account or per-resource charges when the agent leaves preview, since cost will set how wide teams draw the profile scope.
- Whether the pre-deployment IaC review gets an API or CLI entry point that a CI pipeline can call, beyond the console zip upload.
- Any published comparison of the agent's findings against a human Well-Architected review of the same workload.