Bedrock application inference profiles with no invocations in 30 days
What does ZopNight detect here?
ZopNight flags a Bedrock application inference profile when CloudWatch records no `Invocations` for it over 30 days, treating a missing series as zero use. Application profiles have no standing charge, since pricing follows the model called, so the finding is a $0 advisory that recommends deleting the profile once no caller or cost-allocation tag depends on it.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1633 |
| Category | advisory |
| Severity | low |
| Metric | Invocations |
| Threshold | zero invocations |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | bedrock:ListInferenceProfiles · bedrock:GetInferenceProfile · cloudwatch:GetMetricStatistics |
Where it applies
What an application inference profile is for
Bedrock has two kinds of inference profile. Cross Region profiles are defined by AWS; application inference profiles are ones you create to track usage and cost for a model, often by attaching cost-allocation tags. The inference profiles guide states that the price of using a profile is based on the price of the model in the Region you call it from, so the profile itself adds no line item. An unused one is harmless on the bill but misleading in cost reports: it suggests a tagged workload exists when it no longer does.
Listing profiles and checking their calls
Filter to the profiles your teams created:
aws bedrock list-inference-profiles --type-equals APPLICATION \ --query 'inferenceProfileSummaries[].[inferenceProfileName,inferenceProfileArn,status]'Then look for runtime calls in the AWS/Bedrock namespace, using the profile’s identifier as the
ModelId dimension value:
aws cloudwatch get-metric-statistics --namespace AWS/Bedrock \ --metric-name Invocations \ --dimensions Name=ModelId,Value=PROFILE_ID \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumConditions for a finding
ZopNight looks at 30 days of Invocations for the profile. CloudWatch only writes this count when
calls happen, so a profile nobody uses has no series. ZopNight reads that absence as zero use, and
also fires when a series exists with only zero values.
When the profile is not flagged
Any recorded invocation in the series ZopNight holds keeps the profile out of the results. If ZopNight holds no metrics for the account, it raises nothing rather than guessing, because it cannot distinguish an idle profile from a gap in monitoring access.
No saving, but cleaner attribution
Deleting the profile saves about $0, and the finding says so. Its value is keeping cost-allocation reports honest: every remaining application profile should correspond to a workload that still exists.
Removing an idle profile
- Confirm no application passes this profile ARN as its model ID in
InvokeModelorConversecalls, and no knowledge base, flow or prompt uses it. - Check whether any cost-allocation report or budget filters on the profile’s tags.
- Delete it with
aws bedrock delete-inference-profile --inference-profile-identifier PROFILE_ARN. - Re-create it when the workload returns; the tags can be applied again at creation.