Amazon Web Services (AWS) on Thursday released a public preview of its Well-Architected Agent, an AI service designed to examine a customer’s cloud infrastructure, compare it against the company’s standards for how systems should be built, and return specific fixes. AWS described it as working like an experienced cloud architect, which is a notable framing given that cloud architects have long done the work it automates.
The Well-Architected Agent inspects a customer’s environment directly, reading utilization metrics, resource configurations, and application topology, and measures them against Well-Architected best practices spanning more than 100 AWS services. It then ranks what it finds by the customer’s stated business goals and provides the code needed to fix each issue.
Three things distinguish the Well-Architected Agent from the checklists and alert dashboards that came before it. It ranks findings by the business goals a customer declares rather than handing over an undifferentiated list. It works at three levels of scope: flagging a single misconfigured resource, grouping scattered alerts that turn out to be one recurring problem, and identifying when the underlying design itself departs from best practice. And it lets customers choose how to apply a fix, whether through the console, revised infrastructure-as-code, command-line instructions, or automation scripts.
Automating the Well-Architected Framework
As the name suggests, the agent is built around the Well-Architected Framework, AWS’s own definition of what a properly built system looks like on its platform. The company formally introduced it in 2015 with a whitepaper based on what its solutions architects learned while reviewing thousands of customer systems. It’s organized around six pillars: operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability. Teams measure a workload against it by working through a set of questions for each pillar, which produces a list of risks ranked by severity.
Although AWS was first to formalize this kind of guidance, it’s no longer alone. Microsoft published its own version in 2020, and Google did the same in 2025.
And while developers may follow the Well-Architected Framework’s suggestions, it’s vital to remember it’s not a one-and-done process. In fact, the framework recommends teams run the review process at every key milestone in the product lifecycle, early in the design phase, and also before the launch date. But that’s easier said than done because a review traditionally requires multi-hour sessions with engineers, time to produce a detailed report with findings, and more time to remediate what’s been discovered. The process can take weeks or even months.
“Previously, teams had to manually stitch together findings from multiple disconnected tools, then triage hundreds of flat, undifferentiated alerts to figure out what actually mattered,” Jill Fariss, Amazon’s vice president for AWS Support, told The AI Economy in an email. “Most of those alerts get missed or ignored because there’s no prioritization. And even when teams identify the right issue, they hit a second wall: the tool tells you what’s wrong but leaves you to figure out how to fix it. Worse, teams would make cost cuts that unknowingly triggered outages because nothing connected the trade-offs across pillars.”
Still, when it comes to growing adoption of the Well-Architected Framework, this AI agent isn’t the first tool in AWS’s arsenal. In 2018, the company launched the Well-Architected Tool, a cloud-based service in the AWS console that helps teams complete the framework’s questionnaire. AWS also offers the Well-Architected Lab, an educational training site where anyone can learn and apply the framework’s best practices.
How AWS’s Well-Architected Agent Works
To start, customers create an agent profile that defines what the Well-Architected Agent can see and what it can recommend. They then grant it the permissions it needs to read across the accounts and regions they’ve chosen. From there, the agent sorts findings across those resources and applications, confined to the pillars the customer selected—cost optimization, performance, resilience, and security—and ranks them against the goals the customer has stated.
What the agent won’t do is act on its own. Fariss said it runs on what she described as an advisory-first model, in which “humans are kept in the loop for significant decisions.” Each recommendation comes with a full implementation package, but an engineer or administrator must approve it before anything in the environment changes.
Though the Well-Architected agent uses AI to generate recommendations, AWS urges customers to double-check before making any fixes—it could contain errors or incomplete information. “You are responsible for evaluating the recommendation in your specific context and implementing appropriate oversight and safeguards,” Channy Yun, AWS’s principal developer advocate, wrote in a blog post. It’s certainly a flag worth noting and one that raises some questions: How closely do the Well-Architected Agent’s findings match what a human cloud architect would have reported? And how does a customer without one on staff know the difference?
Fariss shared that Amazon Bedrock powers the Well-Architected Agent. “We selected the models best suited for each part of the analysis pipeline based on accuracy, latency, and cost,” she said, though she didn’t mention specific LLMs. The agent also uses deterministic knowledge and signals curated by AWS services and internal experts. But perhaps more importantly, Fariss said, “the agent grounds its findings in deterministic signals that already exist from AWS systems like Trusted Advisor rather than reasoning in isolation. Every recommendation passes a claim-validation step and is code-verified against the live environment. Each one is traceable back to its source signal so [customers] and [their] auditors can see exactly what the agent found and why.”
When asked what makes AWS’s agent unique, Fariss replied that the Well-Architected Agent “evaluates across all four optimization pillars simultaneously, shows cross-pillar trade-offs before teams act, and prioritizes everything against the customer’s own declared business objectives.” She reiterated that the agent reasons at three levels, spans more than 65 AWS services, and is IaC-aware, “so teams can upload Terraform, CloudFormation, or CDK templates and get architecture-level code changes before issues hit production.”
“It delivers complete implementation guidance with every finding, not just a diagnosis,” Fariss concluded.
AWS’s Well-Architected Agent is now available in preview for those on the AWS Support plan in US East (N. Virginia), US East (Ohio), and US West (Oregon). It supports workloads in any AWS commercial region.
Discover more from Ken Yeung
Subscribe to get the latest posts sent to your email.
