· via dev.to (home feed)
AWS launches Well-Architected Agent preview to automate architecture reviews
AWS's public-preview Well-Architected Agent scans accounts across four pillars, ranks recommendations against user-written goals, and returns fixes as console steps, CLI commands or infrastructure code.

What launched
On October 1, 2026, AWS opened the Well-Architected Agent to public preview, according to a dev.to write-up by Matias Martinez. The service continuously scans AWS accounts and produces cost, security, resilience, and performance recommendations ranked against goals that customers define themselves — for example, cutting unnecessary spend or making workloads recover gracefully from disruptions. AWS frames it as the step beyond Trusted Advisor and the Well-Architected Tool, delivered through AWS Support.
The agent's endpoints run in us-east-1, us-east-2, and us-west-2, though it can analyze resources in any commercial Region. Setup revolves around a profile: up to 100 target accounts, the Regions to scan, the pillars to focus on, and one written goal per pillar. The first recommendations are said to arrive within 24 hours.
How it works
The agent scans configuration across more than 65 services, along with utilization metrics and application topology, using read-only IAM roles. Access is built on role chaining: an execution role in the profile account — trusted by wellarchitected.amazonaws.com — assumes an access role in each target account. Those access roles attach the managed policy WellArchitectedAgentResourceScanning, and the profile ARN acts as an external ID to block confused-deputy attacks. Onboarding is opt-in per account, and deletion protection is switched on by default in the console.
An optional application-context step lets users register which applications exist, where they run, and which tags identify them. Martinez argues this is what elevates raw findings like a set of unmonitored queues into a meaningful statement such as an event pipeline lacking failure observability across all three of its Regions.
Recommendations and remediation
Findings arrive at three levels: resource-level (one resource or a small group), application-level (currently beta, spanning one app), and architecture-level (patterns and IaC changes). Each carries priority, effort, impact, an ROI estimate, affected resources, cross-pillar benefits, and explicit trade-offs — the last of which Martinez notes is the kind of judgment a good architect usually supplies verbally, made explicit here.
Examples AWS showed include a CloudFormation role granting Action: "" on Resource: "" when only seven service namespaces were needed; 15 dead-letter queues across three Regions with no alarms and a 48-minute median time to detect; and ECS Fargate tasks running roughly twice as large as needed based on 30-day p95 CPU and memory data.
Remediation can take the form of console walkthroughs, updated IaC templates, or CLI calls, with the API also listing SDK, SSM runbooks, MCP, and an AUTO_REMEDIATION type. In everything AWS has demonstrated so far, the agent does not modify resources by itself. The IaC path can hand back a CDK helper ready to paste into a stack, split into phases.
Pre-deployment IaC review
Users can upload a zipped Terraform, CloudFormation, or CDK project to S3 and receive findings before anything deploys, using the Well-Architected Framework lens; binary and media files are excluded. Per the dev.to article, the consultancy Classmethod tested this on launch day: the review took roughly 30 minutes and flagged, among other things, a Lambda function hard-coded to MemorySize: 256 with no alarms or tuning automation.
Limits and caveats
The preview console exposes four pillars — cost, security, resilience, performance — even though the API already lists operational excellence as a valid value. An active AWS Support plan is required, and no preview pricing has been published. AWS says the agent does not replace the Well-Architected Tool for manual reviews, is not a compliance auditor, and stamps every recommendation with a disclaimer that it is AI-generated and may be wrong or incomplete.
Martinez also flags an operational trap: applying CLI fixes directly in a GitOps setup, where Terraform or Argo CD will simply revert the resulting drift.
Why it matters
A Well-Architected review has traditionally meant a day or two of questionnaire answers and evidence-gathering across multiple consoles, producing a report that ages quickly. Moving that loop into a continuous, goal-ranked agent that reads dozens of services and returns ready-to-paste fixes turns architecture review from a scheduled event into a background process. The catches are real: it sits behind an AWS Support plan with unpublished pricing, its output is AI-generated and non-autonomous, and the preview is Region-limited. Teams running multi-account platforms on Terraform or CDK stand to gain most immediately from the pre-deploy IaC review path.
- #aws
- #cloud
- #infrastructure-as-code
- #devops
- #ai-agents