AWS Solutions Architect Prover

AWS Solutions Architect Prover MCP Connector for Claude

A+

A Principal-level AWS Solutions Architect reviewing every cloud decision your AI makes. 20 years of production scars — service sprawl, $40K NAT Gateway bills, IAM breaches, multi-region theater — packaged into a review that runs in seconds. Get the AWS discipline you would pay $300K/year to hire, applied to every architecture your team ships.

1 tools Official Updated Oct 1, 2026 Official Vinkius Partner

What You Get

A Principal AWS Solutions Architect on demand. The kind of person AWS Enterprise Support sends to keynotes and to Fortune 500 CTO offices. The kind who has watched a customer burn $18K/month on unused NAT Gateways, prevented a startup from choosing EKS for their 3-person team, and shut down 27 breach attempts because IAM was scoped tight from Day 0.

This MCP puts that discipline behind every AWS architecture decision your team makes. Every time your AI generates a cloud design, it faces a senior review before you ship.

Why It Pays for Itself

AWS overspend is the industry default. Flexera's State of the Cloud report puts wasted cloud spend at 32%. This Prover catches the top 5 causes: NAT Gateway ($32/mo idle + $0.045/GB you forgot), cross-AZ transfer ($0.01/GB compounding at scale), egress ($0.09/GB every time data leaves), VPC endpoints you should have bought, and service sprawl (EKS when Fargate works).

IAM misconfiguration is the #1 root cause of AWS breaches. Every Resource: "*" blocked at design time is a breach prevented before your team pushes code.

Multi-region is theater when 99.95% is enough. The Prover refuses Aurora Global Database, DynamoDB Global Tables, and Route 53 failover unless the availability SLO or data residency requirement earns them. Multi-AZ meets 99.95%. Save the multi-region tax for workloads that actually need it.

Service sprawl is technical debt disguised as architecture. Kinesis + MSK + EventBridge + SQS + SNS in the same design is not resilience — it is indecision. The Prover forces one primitive per role, defended against rejected alternatives.

The Review Framework

The Senior SA runs your architecture through five gates. Skipping a gate is not allowed. The order is not negotiable.

Gate What the Senior SA Demands What You Get
1. Requirements Quantified RPS, p99 latency in ms, availability SLO in 9s, RTO/RPO in minutes, compliance scope. No marketing words. Design decisions tied to real numbers, not aspirations.
2. Blast Radius Mapped What fails at AZ, region, account, and service. Multi-region only when the SLO earns it. Availability that matches your SLO — no theater, no gaps.
3. Services Minimized Every service defended against a rejected alternative. Fargate over EKS unless you name why. SQS over Kinesis unless you name why. The smallest AWS surface area that meets the SLOs — lower cost, lower ops burden.
4. Real TCO Calculated NAT Gateway, cross-AZ, egress, VPC endpoints, PIOPS, support tier. Itemized. An AWS bill you can defend to your CFO before you deploy.
5. Security Designed In Least-privilege IAM (zero wildcards), KMS CMK with rotation, GuardDuty/Config/CloudTrail Day 0, Block Public Access on every bucket. Compliance posture ready for SOC2, PCI-DSS, or HIPAA audit from Day 1.

The Verdict

Gate 1 fails → REQUIREMENT_HALLUCINATION   (numbers missing)
Gate 2 fails → BLAST_RADIUS_IGNORANCE      (failure domains unmapped)
Gate 3 fails → SERVICE_SPRAWL               (services stacked, not chosen)
Gate 4 fails → COST_HALLUCINATION           (hidden AWS fees ignored)
Gate 5 fails → SECURITY_AFTERTHOUGHT        (IAM wildcards, deferred controls)
All pass     → WELL_ARCHITECTED             (ship it)

Every rejection names the exact gate that failed and the concrete fix. No vague feedback. No hand-waving.

Who This Is For

  • CTOs and Engineering VPs who cannot afford a $30K/month AWS surprise, and cannot hire a Principal SA for every team.
  • Cloud and Platform teams whose junior engineers ship AI-generated Terraform they cannot fully defend.
  • Startup founders who need Fargate + RDS discipline, not EKS + MSK resume theater.
  • Regulated industries (fintech, healthtech, gov) where IAM misconfiguration is not just a bug — it is a compliance finding.
  • Consultancies and MSPs who need every proposal to survive a senior AWS review before it reaches the customer.

What You Do Not Need

You do not need to configure AWS credentials. The Prover does not touch your AWS account, your bill, or your infrastructure. It reviews the architecture itself — the design, the reasoning, the tradeoffs — the way a Senior SA would in a whiteboard session. All the value, none of the access surface.

awswell-architectedsolutions-architectcloud-architecturecost-optimizationblast-radiusiamsecurity-by-designprincipal-architectaws-review

1 tools expose this connector's capabilities to your AI agent.

validate_aws_architecture

The order is non-negotiable — most AWS failures come from executing these steps out of sequence. You must: (1) QUANTIFY REQUIREMENTS — extract concrete numbers. RPS peak and sustained, p50/p95/p99 latency in ms, availability SLO as 9s (99.9%, 99.95%, 99.99%), RTO in minutes, RPO in minutes, data volume in GB and growth rate, user count, compliance scope (PCI-DSS, HIPAA, SOC2). "Scalable" and "high-performance" are marketing words, not requirements, (2) MAP BLAST RADIUS — name what fails at every AWS scope level. AZ failure: how does the workload survive one AZ going dark? Region failure: what is the multi-region strategy and does the SLO justify it? Account failure: is production isolated in a dedicated account for blast radius bounding? Service failure: what happens when SQS is throttled or KMS is unavailable? "AWS handles it" is not a map, (3) MINIMIZE SERVICES — the best AWS service is no AWS service. For every service in your architecture, name the AWS alternative you REJECTED and the concrete reason. Fargate over EKS (control plane cost, ops burden), SQS over Kinesis (no replay > 24h need), Aurora over DynamoDB (relational needs). Reject Kafka on MSK unless you can name the ordering guarantee, throughput, or ecosystem tool that SQS cannot provide, (4) CALCULATE REAL TCO — itemize the AWS invoice. Compute + storage + NAT Gateway ($32/mo + $0.045/GB) + cross-AZ transfer ($0.01/GB) + egress ($0.09/GB) + VPC endpoints ($22/mo per endpoint per AZ) + PIOPS + CloudWatch + support tier + ops burden in engineer-hours. "Serverless is cheap" is a slogan. At sustained load, Lambda + API Gateway + DynamoDB frequently exceeds Fargate + ALB + Aurora by 2-3x, (5) DESIGN SECURITY IN — Day 0, not Day 90. IAM roles for compute (never access keys), policies scoped to specific ARNs (never `Resource: "*"`), aws:PrincipalTag and aws:ResourceTag condition keys, KMS CMK per data domain with rotation, S3 Block Public Access on every bucket, VPC endpoints for AWS service traffic, GuardDuty + Config + CloudTrail + Security Hub enabled on Day 0, Secrets Manager with automatic rotation, compliance conformance packs where scoped. If rejected, you violated the Algorithm sequence.Send ALL parameters in ONE call — the analyses above plus YOUR OWN verdict: every PIVOT boolean, verdict and clarification. The engine cross-checks the pivots against the verdict and rejects incomplete or self-contradictory calls. Structured reflection tool that forces execution of the 5-Step AWS Well-Architected Algorithm before validating any AWS cloud architecture decision. The algorithm must be executed IN ORDER — skipping steps is the most common failure. Catches Requirement Hallucination (accepting vague terms like "scalable", "high performance", "cloud-native" without extracting concrete SLIs, SLOs, RTO, or RPO — a senior architect never chooses a service before quantifying the numbers), Blast Radius Ignorance (proposing multi-region for a 200-user internal tool or single-AZ for a payment system — multi-AZ meets 99.95%, multi-region needs a business case like data residency or 99.99%+ SLO. "AWS handles it" is not a failure domain analysis), Service Sprawl (stacking Kinesis + MSK + EventBridge + SQS + SNS in the same architecture because the LLM cannot decide — a senior architect picks ONE messaging primitive matching volume, ordering, retention, and consumer model; ONE compute abstraction ordered from least operational burden (App Runner, Fargate) to most (EKS)), Cost Hallucination (calling Lambda "cheap" while ignoring API Gateway $3.50/M requests, DynamoDB WCU/RCU, VPC endpoints $22/mo per AZ, NAT Gateway $32/mo + $0.045/GB, cross-AZ $0.01/GB, egress $0.09/GB, and support tier — the TCO is the invoice, not the compute bill), and Security Afterthought (writing `Resource: "*"`, using access keys instead of IAM roles, deferring MFA and encryption to "later" — Day 0 is when least-privilege IAM, KMS CMK rotation, VPC endpoints, GuardDuty, Config, and CloudTrail must exist, not Day 90). Call once per major AWS architectural decision

See how to talk to your AI agent using AWS Solutions Architect Prover.

New AWS reporting tool. Scalable, cloud-native. Stack: EKS + MSK + Kinesis + Aurora Global + Lambda. IAM: `s3:*` on `*`, lock down later.

Verdict: REQUIREMENT_HALLUCINATION + SERVICE_SPRAWL + SECURITY_AFTERTHOUGHT. 'Scalable' is not a requirement — give me RPS, p99, SLO. Aurora Global for internal reporting is theater; multi-AZ meets 99.9%. Collapse to Fargate + SQS + Aurora single-region: ships in 2 weeks, ~60% cheaper. `s3:*` on `*` is the #1 breach root cause — scope to bucket ARN, use IAM roles, GuardDuty on Day 0.

Payment reconciliation. 250 RPS, p99 < 400ms, 99.95%, RTO 30min, RPO 5min, PCI-DSS. Multi-AZ + async Aurora cross-region replica. Fargate (over EKS), Aurora Serverless v2 (over DynamoDB), SQS FIFO (over Kinesis). TCO $620/mo itemized. IAM roles, KMS CMK, GuardDuty/Config Day 0, zero wildcards.

Verdict: WELL_ARCHITECTED. All five gates pass. Requirements quantified, blast radius earns the SLO without doubling PCI scope, one primitive per role with rejected alternatives named, TCO defensible to the CFO, security is Day 0. Ship it.

Lambda + API Gateway + DynamoDB. 40M requests/month sustained. Serverless is cheap, skipping TCO.

Verdict: COST_HALLUCINATION. At 40M req/mo sustained: API Gateway $140 + DynamoDB $50 + VPC endpoints $132 + NAT $32 + logs $30 = ~$400+/mo. Two Fargate tasks + same DynamoDB = ~$120/mo. Under flat 24/7 load, serverless loses. Enumerate every line item before signing.

The senior SA persona targets the five most expensive AWS mistakes: idle NAT Gateways ($32/mo each, often 3-6 in a VPC), forgotten cross-AZ transfer at scale, egress that quietly ranges from $500 to $50,000/mo, VPC endpoints omitted so every S3 call goes through NAT, and EKS control planes chosen where Fargate would suffice ($73/mo per cluster). Teams that put this review in front of every design typically recover 20-40% of AWS spend inside 90 days. The savings scale with the size of the AWS footprint.

Related Connectors