AWS Cloud Financial Management

How AWS thinks about FinOps Automation and Trust

In the AI era, you blink and you might miss another announcement for agentic solutions. It is natural to feel caught between agent fatigue and fear of missing out. If you’re managing cloud and AI spend for your organization, you’re responsible for evaluating agentic FinOps solutions and decide whether to try it or pass. In this post, we will share our mental model for autonomous FinOps, tiers of automation you can follow, and the trust levers you can rely on.

Why now and why another agent

As part of our FinOps tooling evolution, we introduced the AWS FinOps Agent (currently in public preview) at FinOps X 2026. Another agent? Yes! But hear us out. Before the AWS FinOps Agent, we released several AI-powered features with the intent of simplifying your FinOps tasks. Amazon Q lets you ask cost related questions anywhere on the AWS console. AWS Compute Optimizer automation enables you to automatically implement recommendations, such as snapshotting and deleting unattached EBS volumes, or upgrading volume types. Your AI agent can connect to AWS Billing and Cost Management services through the Billing and Cost Management MCP server.

However, there is a learning curve to getting familiar with these tools and a proper workflow to get the right output your team needs. Your FinOps maturity stalls when your team is buried in tedious cost analysis. We know when it comes to managing your cloud and AI spend, time and insights are everything, along with the ability to bring more stakeholders into what is ultimately a “team sport”. That’s why we invested in the FinOps Agent to help you scale your FinOps practices with higher speed and broader reach. The agent has built-in workflows with specialized FinOps expertise for common FinOps tasks, so your FinOps team doesn’t have to spend time on prompt engineering. It knows which AWS services to call and in what order, and understands the proper workflow to investigate and pass the information to the right parties. It also considers your context files and keeps memories of your preferences. It is an always-on cost guardian that can autonomously and continuously tackle concurrent tasks and take actions without constant human direction.

Tiers of Automation

FinOps automation is still relatively new and given the sensitivity around cloud and AI cost management, it is understandable if you are hesitant to go all-in on autonomous FinOps activities right away. We recommend the following approach to dial up your comfort level of automation and have seen early adopters operating across these tiers.

  • Read-only insights in place of labor-intensive analysis: Start with cost analysis and summary tasks that previously required your team to cross reference metrics from multiple sources. For example, AWS FinOps Agent can investigate cost anomalies by correlating AWS Cost Anomaly Detection alerts with AWS CloudTrail events.
  • Simple, human-controlled mutation: Then test the waters with mutation by approving and observing how automation takes effect. For example, AWS Compute Optimizer’s one-click EBS idle cleanup with an approval workflow, or the one-click approval before AWS Budget Actions take effect, whether applying restrictive AWS Identity and Access Management (IAM) policies or Service control policies (SCPs) to prevent new provisioning, or target specific EC2 and RDS instances.
  • Preset rule-based automation: Set up recurring automated tasks with your own rules. For example, EBS automation in Compute Optimizer lets you set rules to exclude specific volumes by tag or region and automatically takes a snapshot before deletion for safety.
  • Autonomy with boundaries: When you are ready to delegate, you can still decide which tasks to automate (e.g., reporting, cost inquiry anomaly response), and which systems to integrate. For example, AWS FinOps Agent lets you choose your delivery channels (email, Slack, Jira) and scope access through IAM permissions, so the agent only acts within the boundaries you set.

 Trust Levers

“As we simplify and democratize Cloud Financial Management tooling through automation and agentic solutions, we want to make sure users across different roles and FinOps maturity can benefit. That’s why we invest in capabilities across all tiers of automation and ensure trust is earned through intentional design”

– Jerry Rapisarda, Director of Engineering, AWS Insights

As you become more comfortable with our autonomous FinOps features, we want to make sure we maintain the trust we’ve established with you over the years.

Tier What you can automate Trust lever in action
 1 Read-only insights cost reporting, anomaly investigation, cost optimization summary Transparency: see the reasoning
 2 Simple mutation Budget actions, idle resources cleanup Preview & simulate: approve before implementation
 3 Rule-based automation Recurring tasks with custom rules Permission control: scope what’s in and out
 4 Autonomy with boundaries Continuous monitoring, reporting, ticketing Risk management: built-in blast radius caps and roll back

The following are the tenets our engineering and product teams follow and the levers you can rely on to stay in control as automation scales.

  • Transparency: We share the reasoning behind analysis and recommendation. For example, you can forecast your cost and usage for up to 18 months with AWS Cost Explorer and get explanations on the trend and cost drivers that feed into the cost estimation. AWS Compute Optimizer shows projected performance risk alongside cost savings for rightsizing recommendations.
  • Preview and simulate before mutation: Before we launch a product, we go through testing and beta feedback, so we increase our confidence in the outcome. We know you want this too, so we let you preview your actions. For example, Savings Plans Purchase Analyzer allows you to simulate the impact on your cost, utilization, and coverage before you make the commitment. You can edit your Compute Optimizer rightsizing recommendation preferences for instance type, lookback period, CPU and memory utilization threshold, before adopting a recommendation.
  • Permission control: just as the Shared Responsibility Model we’ve been following where we manage the security of the cloud (the infrastructure that runs all the services), and you manage the security in the cloud (access, application, data), there are also guardrails built in our CFM services. In our service design, we make sure there is granular level permission control in place for each feature. AWS FinOps Agent uses IAM-scoped access, so you can define the accounts, services, and actions the agent can access. At the same time, you can grant the right level of access for your users, so they can only see the information they need when using the agent.
  • Risk management: what if something goes wrong despite careful setup? Yes, we’ve got your back. To ensure safe execution, we have built-in blast-radius controls and rollback capabilities. You maintain full control by establishing custom boundaries based on specific dimensions, such as AWS account, region, or maximum financial impact. Furthermore, automated actions are easily reversible. For instance, if the agent deletes an idle EBS volume, it can quickly restore it using a pre-automation backup snapshot.

Conclusion

What we shared today is shaped by conversations with customers, industry analysts, and our engineering leadership. We’re investing in making each rung of the automation ladder safer and easier to climb. We encourage you to enable the AWS FinOps Agent and other CFM services and share your feedback with us. It will allow us to evolve these capabilities and the built-in trust levers. Start with a read-only insight workflow today and see the value before you grant more mutation access.

TAGS:
Bowen Wang

Bowen Wang

Bowen is a Principal Product Marketing Manager for AWS Billing and Cost Management services. She focuses on enabling finance and business leaders to better understand the value of the cloud and ways to optimize their cloud financial management. In her previous career, she helped a tech start up enter the Chinese market.