Skip to main content
advisory · aws

Amazon Bedrock agents whose invocation series shows zero calls for 30 days

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Amazon Bedrock agent only when it holds a CloudWatch invocation series for that agent and the series shows zero calls across a 30-day lookback. When no series exists for the agent, ZopNight stays silent. The finding carries a $0 saving and asks for a cleanup review, since spend is tracked against the models the agent calls.

Signal and threshold

How ZopNight evaluates Amazon Bedrock agents whose invocation series shows zero calls for 30 days.
Field Value
Rule IDsRC-1607
Categoryadvisory
Severitymedium
MetricInvocations
Thresholdzero invocations
Evaluation window30d
SourceZopNight
Permissions usedbedrock:ListAgents · bedrock:ListAgentAliases · cloudwatch:ListMetrics · cloudwatch:GetMetricStatistics

An agent nobody calls is configuration waiting to go stale

A Bedrock agent bundles instructions, action groups, knowledge base links and one or more aliases that applications call. When the application that used it is retired, the agent is left behind with permissions and integrations that nobody reviews. It rarely shows up on a bill by itself, which is exactly why it survives: ZopNight records the spend against the models and capacity the agent invokes, not against the agent object.

AWS publishes agent runtime metrics in the AWS/Bedrock/Agents namespace. The agent metrics reference lists InvocationCount with an Operation dimension (for example InvokeAgent), and a finer set grouped by AgentAliasArn and ModelId. There is no per-agent-ID dimension, so traffic has to be read per alias.

Reading agent traffic from CloudWatch

List the agents in a Region, then the aliases for any agent you want to check:

Terminal window
aws bedrock-agent list-agents \
--query 'agentSummaries[].[agentId,agentName,agentStatus,updatedAt]' --output table
aws bedrock-agent list-agent-aliases --agent-id AGENT_ID \
--query 'agentAliasSummaries[].[agentAliasId,agentAliasName]'

Then see which alias ARNs have published InvocationCount datapoints. list-metrics only returns metrics that reported data in the past two weeks, so an alias missing here has been quiet at least that long; use get-metric-statistics for a longer view:

Terminal window
aws cloudwatch list-metrics --namespace AWS/Bedrock/Agents \
--metric-name InvocationCount

What ZopNight needs to see before it speaks

The check reads the Invocations series ZopNight holds for the agent. It fires only when that series exists and contains no activity. Activity is judged across the whole series ZopNight has, not just the latest 30 days, so an agent that was busy last quarter and quiet this month is not treated as idle. The finding text reports the number of days the evidence actually covers.

Why this finding is often missing

Because Bedrock reports agent calls by alias ARN rather than by agent, ZopNight currently has no series it can attribute to a given agent. A missing series is never read as “zero calls”. In that situation the rule raises nothing at all, on the view that recommending deletion from absent data would be worse than saying nothing. Expect this rule to stay quiet on every account for now; its silence does not prove an agent is in use.

A cleanup review with no price attached

The finding shows current cost, optimized cost and saving all as $0. Any money tied to the agent lives in the model invocations, and in capacity such as a Bedrock Provisioned Throughput Idle purchase, which is reviewed separately.

Retiring an unused agent

  1. Search application code, Lambda functions and API gateways for the agent ID and alias IDs.
  2. Record any provisioned throughput, custom model or knowledge base the agent uses, so each can be reviewed on its own.
  3. Delete the agent, for example with aws bedrock-agent delete-agent --agent-id AGENT_ID.
  4. Decommission downstream pieces, such as action group Lambda functions, that have no other consumer.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·