Amazon Bedrock agents whose invocation series shows zero calls for 30 days
What does ZopNight detect here?
ZopNight flags an Amazon Bedrock agent only when it holds a CloudWatch invocation series for that agent and the series shows zero calls across a 30-day lookback. When no series exists for the agent, ZopNight stays silent. The finding carries a $0 saving and asks for a cleanup review, since spend is tracked against the models the agent calls.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1607 |
| Category | advisory |
| Severity | medium |
| Metric | Invocations |
| Threshold | zero invocations |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | bedrock:ListAgents · bedrock:ListAgentAliases · cloudwatch:ListMetrics · cloudwatch:GetMetricStatistics |
Where it applies
An agent nobody calls is configuration waiting to go stale
A Bedrock agent bundles instructions, action groups, knowledge base links and one or more aliases that applications call. When the application that used it is retired, the agent is left behind with permissions and integrations that nobody reviews. It rarely shows up on a bill by itself, which is exactly why it survives: ZopNight records the spend against the models and capacity the agent invokes, not against the agent object.
AWS publishes agent runtime metrics in the AWS/Bedrock/Agents namespace. The
agent metrics reference
lists InvocationCount with an Operation dimension (for example InvokeAgent), and a finer set
grouped by AgentAliasArn and ModelId. There is no per-agent-ID dimension, so traffic has to be
read per alias.
Reading agent traffic from CloudWatch
List the agents in a Region, then the aliases for any agent you want to check:
aws bedrock-agent list-agents \ --query 'agentSummaries[].[agentId,agentName,agentStatus,updatedAt]' --output table
aws bedrock-agent list-agent-aliases --agent-id AGENT_ID \ --query 'agentAliasSummaries[].[agentAliasId,agentAliasName]'Then see which alias ARNs have published InvocationCount datapoints. list-metrics only returns
metrics that reported data in the past two weeks, so an alias missing here has been quiet at least
that long; use get-metric-statistics for a longer view:
aws cloudwatch list-metrics --namespace AWS/Bedrock/Agents \ --metric-name InvocationCountWhat ZopNight needs to see before it speaks
The check reads the Invocations series ZopNight holds for the agent. It fires only when that
series exists and contains no activity. Activity is judged across the whole series ZopNight has, not just
the latest 30 days, so an agent that was busy last quarter and quiet this month is not treated as
idle. The finding text reports the number of days the evidence actually covers.
Why this finding is often missing
Because Bedrock reports agent calls by alias ARN rather than by agent, ZopNight currently has no series it can attribute to a given agent. A missing series is never read as “zero calls”. In that situation the rule raises nothing at all, on the view that recommending deletion from absent data would be worse than saying nothing. Expect this rule to stay quiet on every account for now; its silence does not prove an agent is in use.
A cleanup review with no price attached
The finding shows current cost, optimized cost and saving all as $0. Any money tied to the agent lives in the model invocations, and in capacity such as a Bedrock Provisioned Throughput Idle purchase, which is reviewed separately.
Retiring an unused agent
- Search application code, Lambda functions and API gateways for the agent ID and alias IDs.
- Record any provisioned throughput, custom model or knowledge base the agent uses, so each can be reviewed on its own.
- Delete the agent, for example with
aws bedrock-agent delete-agent --agent-id AGENT_ID. - Decommission downstream pieces, such as action group Lambda functions, that have no other consumer.