AWS Solutions Architect Prover MCP Connector for Claude
A+A Principal-level AWS Solutions Architect reviewing every cloud decision your AI makes. 20 years of production scars — service sprawl, $40K NAT Gateway bills, IAM breaches, multi-region theater — packaged into a review that runs in seconds. Get the AWS discipline you would pay $300K/year to hire, applied to every architecture your team ships.
What You Get
A Principal AWS Solutions Architect on demand. The kind of person AWS Enterprise Support sends to keynotes and to Fortune 500 CTO offices. The kind who has watched a customer burn $18K/month on unused NAT Gateways, prevented a startup from choosing EKS for their 3-person team, and shut down 27 breach attempts because IAM was scoped tight from Day 0.
This MCP puts that discipline behind every AWS architecture decision your team makes. Every time your AI generates a cloud design, it faces a senior review before you ship.
Why It Pays for Itself
AWS overspend is the industry default. Flexera's State of the Cloud report puts wasted cloud spend at 32%. This Prover catches the top 5 causes: NAT Gateway ($32/mo idle + $0.045/GB you forgot), cross-AZ transfer ($0.01/GB compounding at scale), egress ($0.09/GB every time data leaves), VPC endpoints you should have bought, and service sprawl (EKS when Fargate works).
IAM misconfiguration is the #1 root cause of AWS breaches. Every Resource: "*" blocked at design time is a breach prevented before your team pushes code.
Multi-region is theater when 99.95% is enough. The Prover refuses Aurora Global Database, DynamoDB Global Tables, and Route 53 failover unless the availability SLO or data residency requirement earns them. Multi-AZ meets 99.95%. Save the multi-region tax for workloads that actually need it.
Service sprawl is technical debt disguised as architecture. Kinesis + MSK + EventBridge + SQS + SNS in the same design is not resilience — it is indecision. The Prover forces one primitive per role, defended against rejected alternatives.
The Review Framework
The Senior SA runs your architecture through five gates. Skipping a gate is not allowed. The order is not negotiable.
| Gate | What the Senior SA Demands | What You Get |
|---|---|---|
| 1. Requirements Quantified | RPS, p99 latency in ms, availability SLO in 9s, RTO/RPO in minutes, compliance scope. No marketing words. | Design decisions tied to real numbers, not aspirations. |
| 2. Blast Radius Mapped | What fails at AZ, region, account, and service. Multi-region only when the SLO earns it. | Availability that matches your SLO — no theater, no gaps. |
| 3. Services Minimized | Every service defended against a rejected alternative. Fargate over EKS unless you name why. SQS over Kinesis unless you name why. | The smallest AWS surface area that meets the SLOs — lower cost, lower ops burden. |
| 4. Real TCO Calculated | NAT Gateway, cross-AZ, egress, VPC endpoints, PIOPS, support tier. Itemized. | An AWS bill you can defend to your CFO before you deploy. |
| 5. Security Designed In | Least-privilege IAM (zero wildcards), KMS CMK with rotation, GuardDuty/Config/CloudTrail Day 0, Block Public Access on every bucket. | Compliance posture ready for SOC2, PCI-DSS, or HIPAA audit from Day 1. |
The Verdict
Gate 1 fails → REQUIREMENT_HALLUCINATION (numbers missing)
Gate 2 fails → BLAST_RADIUS_IGNORANCE (failure domains unmapped)
Gate 3 fails → SERVICE_SPRAWL (services stacked, not chosen)
Gate 4 fails → COST_HALLUCINATION (hidden AWS fees ignored)
Gate 5 fails → SECURITY_AFTERTHOUGHT (IAM wildcards, deferred controls)
All pass → WELL_ARCHITECTED (ship it)
Every rejection names the exact gate that failed and the concrete fix. No vague feedback. No hand-waving.
Who This Is For
- CTOs and Engineering VPs who cannot afford a $30K/month AWS surprise, and cannot hire a Principal SA for every team.
- Cloud and Platform teams whose junior engineers ship AI-generated Terraform they cannot fully defend.
- Startup founders who need Fargate + RDS discipline, not EKS + MSK resume theater.
- Regulated industries (fintech, healthtech, gov) where IAM misconfiguration is not just a bug — it is a compliance finding.
- Consultancies and MSPs who need every proposal to survive a senior AWS review before it reaches the customer.
What You Do Not Need
You do not need to configure AWS credentials. The Prover does not touch your AWS account, your bill, or your infrastructure. It reviews the architecture itself — the design, the reasoning, the tradeoffs — the way a Senior SA would in a whiteboard session. All the value, none of the access surface.
Related Connectors
AWS MSK Partition & Throughput Calculator MCP
Deterministic sizing for AWS MSK clusters, calculating partitions, storage, and network limits.
AWS ElastiCache Cluster Calculator MCP
Deterministic sizing for AWS ElastiCache clusters including Redis and Memcached.
Lambda Resource Optimizer MCP
Deterministic AWS Lambda memory, CPU, and concurrency optimization engine.
Migration Strategy Prover MCP
An AI recommended a big-bang database migration over the weekend. No dependency map — 7 services read from that database. No rollback plan — 'just restore from backup.' No data validation — 2.3 million records with timezone-dependent timestamps. The migration ran Saturday at 2 AM. By 4 AM, 3 downstream services were returning stale data, the backup was 6 hours old, and 14,000 customer records had corrupted timestamps. Monday morning: 72-hour incident. This tool forces risk assessment, rollback definition, data integrity verification, cutover planning, and stakeholder alignment.