Skip to main content
idle · aws

No-commitment Bedrock Provisioned Throughput with zero invocations in 30 days

rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags Amazon Bedrock Provisioned Throughput purchased with no commitment term that recorded no `Invocations` in the `AWS/Bedrock` namespace over 30 days. Provisioned Throughput bills hourly per Model Unit whether or not it is used, and a no-commitment purchase can be deleted at any time, so the saving is the full monthly cost.

Signal and threshold

How ZopNight evaluates No-commitment Bedrock Provisioned Throughput with zero invocations in 30 days.
Field Value
Rule IDsRC-1601
Categoryidle
Severityhigh
MetricInvocations
Thresholdzero invocations, no commitment
Evaluation window30d
SourceZopNight
Permissions usedbedrock:ListProvisionedModelThroughputs · bedrock:GetProvisionedModelThroughput · cloudwatch:GetMetricStatistics

Provisioned Throughput is an hourly bill for reserved model capacity

Provisioned Throughput buys a fixed level of throughput for a model, measured in Model Units, at a fixed cost billed hourly. The hourly price depends on the model, the number of Model Units and the commitment term: no commitment, one month or six months, with longer terms discounted. For models you have customized, AWS requires Provisioned Throughput before the model can be used at all.

The bill runs whether requests arrive or not. A Provisioned Throughput created for a proof of concept, or left behind after an application moved to on-demand inference, keeps charging every hour for capacity nobody uses.

Listing Provisioned Throughput and checking for traffic

Terminal window
aws bedrock list-provisioned-model-throughputs --status-equals InService \
--query 'provisionedModelSummaries[].[provisionedModelName,modelUnits,commitmentDuration]'
aws cloudwatch get-metric-statistics --namespace AWS/Bedrock --metric-name Invocations \
--dimensions Name=ModelId,Value=<provisioned-model-arn> \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum

No datapoints at all over 30 days is the typical picture for an unused one.

What makes one idle in ZopNight’s eyes

  • The Invocations series for the Provisioned Throughput shows no activity over 30 days, or there is no series for it at all. For a Provisioned Throughput that ZopNight can see, a missing invocation series is read as zero activity.
  • No commitment term is set on the purchase.
  • ZopNight has a positive monthly cost for it.

Cases that are excluded

A Provisioned Throughput on a one-month or six-month commitment is never flagged here. AWS does not allow deleting a Model Unit commitment before its term ends, so the charge cannot be recovered early; the right time to act is before it renews, since AWS renews commitments automatically at the end of each term. If ZopNight could not fetch metrics for the account in this run, it raises nothing rather than declare every Provisioned Throughput idle. Throughput that is used but oversized belongs to Bedrock Provisioned Throughput Underutilized.

The full cost comes back on deletion

Terminal window
monthly cost = Model Units x hourly rate x 730
saving = monthly cost (nothing is left running after deletion)

Retiring idle Provisioned Throughput

  1. Confirm no application invokes the provisioned model ARN.
  2. If the model is a base model with on-demand access, point any remaining sporadic traffic at on-demand inference instead.
  3. Delete it: aws bedrock delete-provisioned-model-throughput --provisioned-model-id <provisioned-model-arn>
  4. For Model Unit purchases with a commitment, delete them as soon as the term ends: AWS renews the term automatically, and its cancel auto renew option applies only to Provisioned Throughput by Tokens.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·