Management and Governance

AWS Well-Architected Tool

View on GitHub

AWS Well-Architected Tool

A managed AWS service that guides architecture reviews against the AWS Well-Architected Framework using structured questions and lenses. It operates via the AWS Management Console and APIs to record workload reviews, produce risk summaries, and generate improvement plans. It normally sits at the account or organization level to assess and document the design and operational risks of workloads running in AWS.

🗂 Resource Category

Management and Governance • Security, Identity, and Compliance

🧠 Exam Memory Hook

Think: "Architecture review + improvement plan + governance = AWS Well-Architected Tool"


📖 Ownership

Classification: AWS Managed Service

AWS responsibilities: AWS operates, secures, maintains, and patches the underlying infrastructure and the managed Well-Architected service platform, including the control plane, console, APIs, and storage used by the service. AWS provides managed lenses and baseline risk definitions and applies platform-level security controls for the service environment. AWS does not operate, patch, or secure customer resources, application code, or guest operating systems running in customer accounts.

Customer responsibilities: The customer configures workloads and answers review questions, defines and applies custom lenses when required, configures IAM permissions and access to the tool, secures workload data stored by the service through account-level controls, monitors review results, and implements the recommended improvement actions in their AWS resources. The customer is responsible for documenting architecture decisions, tracking remediation, and integrating the tool with their governance and change processes.

Patching responsibilities: AWS patches AWS-owned physical infrastructure and the managed service platform used by the Well-Architected Tool, including control plane components and service runtime. AWS is responsible for hypervisor and physical host patching where applicable. Customer-managed guest operating systems, application runtimes, libraries, dependencies, and customer-deployed applications remain the customer's responsibility to patch and maintain. The Well-Architected Tool itself does not require customers to patch a runtime inside their accounts; any patching for compute resources assessed by the tool is performed by the customer.


🏗 Typical Architecture

💡 Top 5 Features

  • Guided question-based architecture reviews mapped to the Well-Architected Framework pillars and lenses.
  • Support for AWS-managed lenses and the ability to create and apply custom lenses for specialised workloads.
  • Workload risk summaries and an improvement plan that lists identified operational issues and suggested remediations.
  • Integration with AWS Organizations to perform and view reviews across accounts when configured.
  • Console and API access to create workloads, run reviews, export reports, and track remediation progress.

✅ Top 5 Use Cases

  • Performing structured architecture reviews for new applications to identify operational and security risks before production.
  • Centralising periodic governance reviews across multiple accounts using AWS Organizations to enforce architectural standards.
  • Documenting and prioritising remediation work by generating improvement plans linked to specific workload risks.
  • Applying custom lenses to evaluate specialised workloads such as serverless, containers, or regulated systems against tailored best practices.
  • Supporting architecture sign-off and audit readiness by producing review records and recommendations for compliance teams.

🏗 Architecture Placement

The AWS Well-Architected Tool is a managed control-plane service accessed via the console or APIs at the account level and can be organisation-aware when integrated with AWS Organizations. Cloud and platform teams initiate reviews and supply workload context; the tool evaluates answers and produces risk summaries and improvement plans that teams use to change their AWS resources. It normally connects conceptually to AWS Config, CloudWatch, or Systems Manager for richer context when those services are used, but it does not directly modify customer resources.

🎯 Commonly Used With

- AWS Identity and Access Management
- AWS Organizations
- AWS Config
- AWS Systems Manager
- Amazon CloudWatch

🌍 5 Real-World Examples

  • A banking platform team runs Well-Architected reviews for a payments workload to identify and prioritise reliability and security improvements before a major release, aiding operational readiness.
  • A healthcare provider applies a custom lens in reviews for a patient-data analytics workload to capture domain-specific best practices and produce an actionable improvement plan.
  • A retail company integrates AWS Organizations with the tool to standardise architecture reviews across development accounts and track remediation across teams.
  • A telecommunications provider uses the tool to document architectural decisions and generate reports used by compliance and audit teams during procurement of a new service.
  • A government technology team conducts periodic Well-Architected reviews to maintain documentation of risks and track remediation activities for critical applications.

🎓 AWS Exam Clues

  • Used when a question requires formal architecture reviews against the AWS Well-Architected Framework and documented improvement plans.
  • Select when the requirement mentions lenses, workload reviews, or organisation-wide governance and tracking of architecture risks.
  • Not appropriate if the goal is automated remediation; the tool provides recommendations but remediation is implemented separately.
  • Choose when custom lenses or domain-specific best practices need to be applied during reviews for specialised workloads.
  • Relevant when the scenario describes centralised review reporting across multiple accounts using AWS Organizations.

📝 Quick Revision

A managed service for running structured architecture reviews against the Well-Architected Framework and producing improvement plans. Use it for governance, periodic reviews, and documenting risks; remember it recommends changes but does not perform remediation, and customers must secure IAM, implement fixes, and patch their resources.

🏷 Keywords

Well-ArchitectedLensesWorkloadImprovementPlanReviewQuestionsRiskSummaryCustomLensesAWSOrganizationsIntegrationGovernanceArchitectureReviewOperationalExcellenceSecurityPillar