Agent report card
Can an agent use AWS Cloud through API resource management?
Grade B: Only part of the applicable terms is machine-readable.
AWS / active
Five-stage assessment
Where agent autonomy holds and where it breaks
First break: Evaluate
Evaluate
LimitedOnly part of the applicable terms is machine-readable.
An ARD declaration has not been established.
An agent can discover the product and funnel from the tested public entrypoints.
Eligibility can be decided from explicit public criteria.
Pricing or the absence of a charge is explicit and machine-readable.
Evidence and actions
ARD declaration unknown
missing: unknownAn ARD declaration has not been established.
Decidable eligibility
supported: freshEligibility can be decided from explicit public criteria.
AWS publishes clear Universal Service Terms and criteria governing account usage, eligibility verification, and compliance across its services.
Machine discovery
supported: freshAn agent can discover the product and funnel from the tested public entrypoints.
AWS Cloud Control API provides machine-discoverable standardized APIs and AWS CLI commands for CRUD-L operations on supported resources.
Readable pricing
supported: freshPricing or the absence of a charge is explicit and machine-readable.
AWS provides explicit public pricing models including pay-as-you-go, flat rate, and tiered pricing along with the AWS Pricing Calculator.
Structured terms limited
supported: freshOnly part of the applicable terms is machine-readable.
AWS service terms are provided as web-based text documentation rather than a fully machine-readable structured format.
What would improve this stage
- Publish complete applicable terms in a stable machine-readable document.
Sign up
ReadyA stable signup entrypoint is available.
Whether phone verification is required has not been established.
The tested signup flow exposes machine-operable controls.
No CAPTCHA was encountered on the tested signup path.
A scoped, revocable machine identity flow is documented, including explicit human authorization boundaries.
Evidence and actions
CAPTCHA-free signup
supported: freshNo CAPTCHA was encountered on the tested signup path.
The signup page rendered without a CAPTCHA blocking initial email and account name entry.
Machine-operable signup
supported: freshThe tested signup flow exposes machine-operable controls.
The signup form contains standard input fields for root email address and account name.
Phone-free signup unknown
supported: freshWhether phone verification is required has not been established.
The initial signup page capture does not show phone verification requirements, but subsequent steps are not established in the evidence.
Stable signup entrypoint
supported: freshA stable signup entrypoint is available.
The AWS Console Signup endpoint returned a valid response with stable signup metadata.
Supported identity flow
supported: freshA scoped, revocable machine identity flow is documented, including explicit human authorization boundaries.
AWS STS documentation details scoped, short-term, and revocable credential request flows for IAM roles and identities.
Pay
LimitedCheckout is only partly machine-operable or requires human intervention.
A supported payment rail has not been established.
The required price or no-charge status is explicit before commitment.
The tested funnel can complete without sales intervention.
Evidence and actions
Explicit price
supported: freshThe required price or no-charge status is explicit before commitment.
AWS provides explicit pay-as-you-go, flat-rate, and tiered pricing details publicly prior to account sign-up.
Machine-operable checkout limited
supported: freshCheckout is only partly machine-operable or requires human intervention.
The initial sign-up flow captures account registration details via standard web forms, but complete machine-operable automated checkout without human intervention is limited.
Sales-free purchase
supported: freshThe tested funnel can complete without sales intervention.
Users can independently register and sign up for AWS Cloud accounts via self-service online registration without required sales intervention.
Supported payment rail unknown
supported: freshA supported payment rail has not been established.
The initial registration page presented does not explicitly state the specific supported payment rails for checkout.
What would improve this stage
- Expose documented, labelled checkout controls or an agent-compatible commerce interface.
Provision
ReadySuccessful onboarding automatically activates usable access.
A bounded provisioning delay has not been established.
Usable credentials or delegated access are delivered through a documented flow.
Provisioning exposes machine-readable progress, terminal states, and reconciliation.
Evidence and actions
Automatic activation
supported: freshSuccessful onboarding automatically activates usable access.
Cloud Control API supports automatic activation for supported public AWS resource types, which are public and always activated by default in an AWS account.
Bounded provisioning delay unknown
supported: freshA bounded provisioning delay has not been established.
Documentation provides guidance on asynchronous resource requests and polling status, but does not publish a explicit maximum bounded provisioning delay.
Credential delivery
supported: freshUsable credentials or delegated access are delivered through a documented flow.
AWS Security Token Service (STS) provides temporary credential delivery via API calls such as AssumeRole, GetSessionToken, and GetFederationToken.
Machine-readable provisioning status
supported: freshProvisioning exposes machine-readable progress, terminal states, and reconciliation.
Cloud Control API provides machine-readable ProgressEvent objects containing tracking tokens and status states like IN_PROGRESS and SUCCESS.
Operate
LimitedRecovery is available only for some failure modes or requires human intervention.
An agent protocol interface has not been established.
A documented API or tool interface is available for operation.
Authentication is documented and usable within an agent authorization boundary.
Limits, structured errors, retry behavior, and idempotency semantics are documented where applicable.
Evidence and actions
Agent protocol interface unknown
missing: unknownAn agent protocol interface has not been established.
API or tool access
supported: freshA documented API or tool interface is available for operation.
AWS Cloud Control API provides a documented uniform API and CLI interface (such as CreateResource, DeleteResource, and GetResource) for managing cloud resources.
Delegated recovery limited
supported: freshRecovery is available only for some failure modes or requires human intervention.
AWS account creation troubleshooting provides reference guidance for common activation and verification issues, but directs several failure paths to external support and community resources.
Documented limits and errors
supported: freshLimits, structured errors, retry behavior, and idempotency semantics are documented where applicable.
Cloud Control API documents operational considerations, idempotency via client-token parameters, and non-rollback behavior on request failure.
Usable authentication
supported: freshAuthentication is documented and usable within an agent authorization boundary.
AWS STS provides programmatic methods such as AssumeRole, AssumeRoleWithWebIdentity, and GetSessionToken to obtain temporary credentials within an authorized agent boundary.
What would improve this stage
- Provide delegated credential rotation, revocation, retry, and recovery paths without requiring unrestricted human intervention.
What works
- Sign up: A stable signup entrypoint is available.
- Provision: Successful onboarding automatically activates usable access.
What blocks agents
- Evaluate: Only part of the applicable terms is machine-readable.
- Pay: Checkout is only partly machine-operable or requires human intervention.
- Operate: Recovery is available only for some failure modes or requires human intervention.
Improve the report
Correct it, rerun it, or improve the funnel
Every request carries the exact profile revision, projection, declaration, and Catalog release.
Method, policy, and immutable identifiers
Complete, fresh evidence for the core service lifecycle first applies hard stage severity, then grades the share of applicable evidenced signals that are constrained. Optional blocker probes affect the grade when established and remain visible as unknown when public evidence cannot establish them.
Any incomplete, contradictory, unsupported, or non-fresh required evidence produces an unrated profile. A failed Evaluate, Sign up, or Pay stage derives D; a failed Provision or Operate stage derives F; otherwise constrained-signal ratio derives A+ through C.
- Profile ID
- arp_01kzez1rxy9f1wce0r3p6yd35y
- Revision
- sha256:1732396e5c31f0ccf00e6081d81b624ffbfa3bf34b739a3ae4eca0b977ed426c
- Projection
- sha256:c6a27956aaf2372602b156a92e90760a77816f1060caf0c2bc6af1735f44f399
- Policy
- service-lifecycle-2026-08-08-calibrated: sha256:334e56852b5c38e178fcea839cfba680fb82dd96693842d933776baed21d63df
- Base Catalog release
- sha256:5082ec07047a2324648f569d234cc64342ce2707b2f3d77fde8fc06af517cee6