Skip to main content
advisory · aws

Bedrock application inference profiles with no invocations in 30 days

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a Bedrock application inference profile when CloudWatch records no `Invocations` for it over 30 days, treating a missing series as zero use. Application profiles have no standing charge, since pricing follows the model called, so the finding is a $0 advisory that recommends deleting the profile once no caller or cost-allocation tag depends on it.

Signal and threshold

How ZopNight evaluates Bedrock application inference profiles with no invocations in 30 days.
Field Value
Rule IDsRC-1633
Categoryadvisory
Severitylow
MetricInvocations
Thresholdzero invocations
Evaluation window30d
SourceZopNight
Permissions usedbedrock:ListInferenceProfiles · bedrock:GetInferenceProfile · cloudwatch:GetMetricStatistics

What an application inference profile is for

Bedrock has two kinds of inference profile. Cross Region profiles are defined by AWS; application inference profiles are ones you create to track usage and cost for a model, often by attaching cost-allocation tags. The inference profiles guide states that the price of using a profile is based on the price of the model in the Region you call it from, so the profile itself adds no line item. An unused one is harmless on the bill but misleading in cost reports: it suggests a tagged workload exists when it no longer does.

Listing profiles and checking their calls

Filter to the profiles your teams created:

Terminal window
aws bedrock list-inference-profiles --type-equals APPLICATION \
--query 'inferenceProfileSummaries[].[inferenceProfileName,inferenceProfileArn,status]'

Then look for runtime calls in the AWS/Bedrock namespace, using the profile’s identifier as the ModelId dimension value:

Terminal window
aws cloudwatch get-metric-statistics --namespace AWS/Bedrock \
--metric-name Invocations \
--dimensions Name=ModelId,Value=PROFILE_ID \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum

Conditions for a finding

ZopNight looks at 30 days of Invocations for the profile. CloudWatch only writes this count when calls happen, so a profile nobody uses has no series. ZopNight reads that absence as zero use, and also fires when a series exists with only zero values.

When the profile is not flagged

Any recorded invocation in the series ZopNight holds keeps the profile out of the results. If ZopNight holds no metrics for the account, it raises nothing rather than guessing, because it cannot distinguish an idle profile from a gap in monitoring access.

No saving, but cleaner attribution

Deleting the profile saves about $0, and the finding says so. Its value is keeping cost-allocation reports honest: every remaining application profile should correspond to a workload that still exists.

Removing an idle profile

  1. Confirm no application passes this profile ARN as its model ID in InvokeModel or Converse calls, and no knowledge base, flow or prompt uses it.
  2. Check whether any cost-allocation report or budget filters on the profile’s tags.
  3. Delete it with aws bedrock delete-inference-profile --inference-profile-identifier PROFILE_ARN.
  4. Re-create it when the workload returns; the tags can be applied again at creation.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·