Skip to main content
discount · aws

Bedrock Provisioned Throughput with fewer than 1,000 calls a day

rule IDs covered
1
severity
medium

What does ZopNight detect here?

Amazon Bedrock bills Provisioned Throughput by the hour for as long as it exists, whether or not it gets traffic. ZopNight looks for provisioned models that get some calls but average fewer than 1,000 `Invocations` a day over 30 days, where on-demand pricing may cost less. The rule stays silent until on-demand token rates are available to price that comparison.

Signal and threshold

How ZopNight evaluates Bedrock Provisioned Throughput with fewer than 1,000 calls a day.
Field Value
Rule IDsRC-1603
Categorydiscount
Severitymedium
MetricInvocations
Thresholdunder 1,000 invocations per day
Evaluation window30d
SourceZopNight
Permissions usedbedrock:ListProvisionedModelThroughputs · bedrock:GetProvisionedModelThroughput · cloudwatch:GetMetricStatistics

Paying by the hour for capacity a few calls use

Provisioned Throughput reserves model capacity measured in model units (MUs), and you are billed hourly for it. The price depends on the model, the number of MUs and the commitment: no commitment, which you can delete at any time, or 1 or 6 months, which you cannot delete until the term ends. Billing continues until the Provisioned Throughput is deleted.

On-demand invocation charges per input and output token instead, as listed on Amazon Bedrock pricing. A reserved block that serves a trickle of requests can cost far more than the same tokens would on demand.

Measuring provisioned traffic yourself

List what is provisioned, then read its daily invocation totals from CloudWatch. Bedrock publishes runtime metrics in the AWS/Bedrock namespace with a ModelId dimension:

Terminal window
aws bedrock list-provisioned-model-throughputs \
--query 'provisionedModelSummaries[].[provisionedModelName,provisionedModelArn,modelUnits,commitmentDuration]' \
--output table
aws cloudwatch get-metric-statistics --namespace AWS/Bedrock \
--metric-name Invocations --dimensions Name=ModelId,Value=PROVISIONED_MODEL_ARN \
--statistics Sum --period 86400 \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z

Add InputTokenCount and OutputTokenCount the same way to estimate what that volume would cost at on-demand token prices.

Signals the rule looks for

  1. ZopNight holds a 30-day Invocations series for the provisioned model.
  2. The series shows real activity. A provisioned model with no calls at all is handled by Bedrock Provisioned Throughput Idle.
  3. Average daily invocations fall below 1,000.
  4. A monthly cost is known for the Provisioned Throughput.

Why no finding appears today

Even when all four signals line up, the rule currently produces nothing. A saving here is the Provisioned Throughput’s monthly cost minus the projected on-demand cost of the same input and output tokens, and ZopNight does not yet have the on-demand per-token rates needed for the second half. It will not show a guessed figure or a $0 placeholder instead, so the page describes the check as it will run once those rates are available.

How the saving will be calculated

Terminal window
saving = Provisioned Throughput monthly cost
- (input tokens x on-demand input rate + output tokens x on-demand output rate)

A finding will appear only when that difference is positive.

Moving light traffic to on-demand

  1. Confirm the traffic is light all month, not just between launches.
  2. Estimate the on-demand bill from the token counts above.
  3. Check the model can be called on demand in your Region; some custom models are served only through Provisioned Throughput.
  4. Point callers at the on-demand model ID, then delete the Provisioned Throughput after any commitment term ends: aws bedrock delete-provisioned-model-throughput --provisioned-model-id PROVISIONED_MODEL_ARN.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·