Bedrock Provisioned Throughput with several model units serving under 100,000 output tokens a day
What does ZopNight detect here?
ZopNight flags Amazon Bedrock Provisioned Throughput with more than one model unit whose `OutputTokenCount` averages under 100,000 tokens a day over 30 days while `Invocations` shows real use. The saving is the no-commitment rate per model unit hour times the extra units times 730 hours, capped at the throughput's monthly cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1602 |
| Category | rightsizing |
| Severity | medium |
| Metric | OutputTokenCount |
| Threshold | < 100,000 output tokens per day |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | bedrock:ListProvisionedModelThroughputs · cloudwatch:GetMetricStatistics |
Model units are bought in whole blocks
A Provisioned Throughput is sized in model units, and each unit delivers a fixed throughput level for its model: a set number of input and output tokens it can process per minute. You pay for every unit every hour, whether the tokens arrive or not. A throughput bought with three or four units for an expected load that never came pays for capacity that sits unused all month.
Getting units is not instant either. AWS asks you to request model units through the AWS support center before buying, so teams tend to ask for more than they need and keep them.
Measuring output tokens against unit count
Bedrock publishes Invocations, InputTokenCount and OutputTokenCount to CloudWatch under the
AWS/Bedrock namespace,
all keyed by ModelId. Sum output tokens per day for each multi-unit throughput:
aws bedrock list-provisioned-model-throughputs \ --query 'provisionedModelSummaries[?modelUnits > `1`].[provisionedModelName,provisionedModelArn,modelUnits,commitmentDuration]' \ --output table
aws cloudwatch get-metric-statistics --namespace AWS/Bedrock \ --metric-name OutputTokenCount --dimensions Name=ModelId,Value=PROVISIONED_MODEL_ARN \ --statistics Sum --period 86400 \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00ZGates a throughput passes before it is flagged
- Both
InvocationsandOutputTokenCountseries exist for it, and invocations show activity in the 30-day window. - Output tokens summed over the window and divided by 30 come to more than zero but fewer than 100,000 a day. A model unit is rated in tokens per minute, so a daily total that low leaves most of even one unit idle.
- It has more than one model unit.
- It is on no-commitment terms, and a no-commitment rate per model unit hour is known for its model.
Throughputs left for other checks
A throughput with no invocations at all belongs to Bedrock Provisioned Throughput Idle. One already at a single unit cannot shrink further; whether it should move to on-demand is judged by Bedrock Provisioned Throughput Below Break-Even. Committed-term throughputs are skipped because their hourly price is not the one ZopNight holds.
Pricing the drop to one model unit
saving = rate per model unit hour x (current units - 1) x 730capped at the throughput's monthly costcost after change = monthly cost - savingThe target is always one unit, since the measured traffic sits far below what a single unit can serve.
Resizing an oversized throughput
- Check p95 invocation latency and peak tokens per minute, not only the daily total, to confirm one unit covers your burst.
- Buy a one-unit throughput for the same model with
aws bedrock create-provisioned-model-throughput --model-units 1. - Switch the application to the new provisioned model ARN.
- Delete the old throughput with
aws bedrock delete-provisioned-model-throughput.