Skip to main content
rightsizing · aws

Bedrock Provisioned Throughput with several model units serving under 100,000 output tokens a day

rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags Amazon Bedrock Provisioned Throughput with more than one model unit whose `OutputTokenCount` averages under 100,000 tokens a day over 30 days while `Invocations` shows real use. The saving is the no-commitment rate per model unit hour times the extra units times 730 hours, capped at the throughput's monthly cost.

Signal and threshold

How ZopNight evaluates Bedrock Provisioned Throughput with several model units serving under 100,000 output tokens a day.
Field Value
Rule IDsRC-1602
Categoryrightsizing
Severitymedium
MetricOutputTokenCount
Threshold< 100,000 output tokens per day
Evaluation window30d
SourceZopNight
Permissions usedbedrock:ListProvisionedModelThroughputs · cloudwatch:GetMetricStatistics

Model units are bought in whole blocks

A Provisioned Throughput is sized in model units, and each unit delivers a fixed throughput level for its model: a set number of input and output tokens it can process per minute. You pay for every unit every hour, whether the tokens arrive or not. A throughput bought with three or four units for an expected load that never came pays for capacity that sits unused all month.

Getting units is not instant either. AWS asks you to request model units through the AWS support center before buying, so teams tend to ask for more than they need and keep them.

Measuring output tokens against unit count

Bedrock publishes Invocations, InputTokenCount and OutputTokenCount to CloudWatch under the AWS/Bedrock namespace, all keyed by ModelId. Sum output tokens per day for each multi-unit throughput:

Terminal window
aws bedrock list-provisioned-model-throughputs \
--query 'provisionedModelSummaries[?modelUnits > `1`].[provisionedModelName,provisionedModelArn,modelUnits,commitmentDuration]' \
--output table
aws cloudwatch get-metric-statistics --namespace AWS/Bedrock \
--metric-name OutputTokenCount --dimensions Name=ModelId,Value=PROVISIONED_MODEL_ARN \
--statistics Sum --period 86400 \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z

Gates a throughput passes before it is flagged

  1. Both Invocations and OutputTokenCount series exist for it, and invocations show activity in the 30-day window.
  2. Output tokens summed over the window and divided by 30 come to more than zero but fewer than 100,000 a day. A model unit is rated in tokens per minute, so a daily total that low leaves most of even one unit idle.
  3. It has more than one model unit.
  4. It is on no-commitment terms, and a no-commitment rate per model unit hour is known for its model.

Throughputs left for other checks

A throughput with no invocations at all belongs to Bedrock Provisioned Throughput Idle. One already at a single unit cannot shrink further; whether it should move to on-demand is judged by Bedrock Provisioned Throughput Below Break-Even. Committed-term throughputs are skipped because their hourly price is not the one ZopNight holds.

Pricing the drop to one model unit

Terminal window
saving = rate per model unit hour x (current units - 1) x 730
capped at the throughput's monthly cost
cost after change = monthly cost - saving

The target is always one unit, since the measured traffic sits far below what a single unit can serve.

Resizing an oversized throughput

  1. Check p95 invocation latency and peak tokens per minute, not only the daily total, to confirm one unit covers your burst.
  2. Buy a one-unit throughput for the same model with aws bedrock create-provisioned-model-throughput --model-units 1.
  3. Switch the application to the new provisioned model ARN.
  4. Delete the old throughput with aws bedrock delete-provisioned-model-throughput.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·