Evidence
observed · not disputed
Coverage
complete · 16/16 graded0/5 barrier checks verified
Freshness
fresh
Last tested
Revision
sha256:2db2e5c73843…

Agent report card

Can an agent use AWS Cloud through API resource management?

Grade B+: Only some material eligibility conditions are decidable before commitment.

AWS / active

Agent ReadinessB+Limited

Five-stage assessment

Where agent autonomy holds and where it breaks

Five states · each from its own evidence · lifecycle order, not a journey
  1. EvaluateLimited
  2. Sign upReady
  3. PayReady
  4. ProvisionReady
  5. OperateLimited
  1. 01

    Evaluate

    Limited

    Only some material eligibility conditions are decidable before commitment.

    The exact service and stable evaluation or access entrypoints are publicly discoverable.

    Applicable terms are stable, readable, retrievable, and materially complete.

    Price or no-charge status, variables, currency, and material conditions are explicit.

    Evidence and actions6 signals

    Can an agent decide every material eligibility condition before commitment?

    supported: fresh

    Only some material eligibility conditions are decidable before commitment.

    AWS Service Terms disclose specific eligibility rules for certain regional and account offerings, such as AWS UK switching addendum eligibility and AWS GovCloud (US) registration and eligibility verification requirements.

    eligibility_decidability: Limited: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent estimate cost or confirm no-charge status before commitment?

    supported: fresh

    Price or no-charge status, variables, currency, and material conditions are explicit.

    AWS provides explicit pricing details and mechanisms before commitment, including the AWS Price List API catalog of products and prices and a pay-as-you-go pricing approach where users pay only for consumed services.

    pricing_decidability: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent find the exact service and its stable entrypoints?

    supported: fresh

    The exact service and stable evaluation or access entrypoints are publicly discoverable.

    AWS Cloud Control API provides a standardized set of APIs and AWS CLI commands (e.g., create-resource, delete-resource, get-resource, list-resources, update-resource) to discover and perform CRUD-L operations on supported AWS resources.

    service_discovery: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Are verified structured discovery artifacts available?

    missing: unknown

    Current admissible evidence does not resolve this finding.

    structured_evaluation_discovery: Unknown

    Can an agent retrieve and understand the applicable commitment terms?

    supported: fresh

    Applicable terms are stable, readable, retrievable, and materially complete.

    The applicable AWS Service Terms are retrievable, readable, and publicly accessible online.

    terms_access: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Does the vendor deliberately describe access for web agents?

    missing: unknown

    Current admissible evidence does not resolve this finding.

    verified_web_agent_access: Unknown

    What would improve this stage

    • State every material eligibility condition and required input explicitly.
  2. 02

    Sign up

    Ready

    A stable canonical route begins the required access bootstrap.

    Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.

    Evidence and actions5 signals

    Can an agent operate the access controls and safe handoffs deterministically?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The sign-up endpoint evidence contains metadata and a page title ('AWS Console - Signup'), but does not contain sufficient information to determine whether access controls and safe handoffs can be operated deterministically.

    access_control_operability: Unknown: tested 20 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Is there a stable route to begin obtaining service access?

    supported: fresh

    A stable canonical route begins the required access bootstrap.

    A stable canonical route to begin obtaining service access exists via the 'Sign up for AWS' page and AWS account registration instructions provided in the AWS Account Management User Guide.

    access_entrypoint_stability: Ready: tested 20 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can an agent obtain access without an unsupported CAPTCHA boundary?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    Current admissible evidence across all target surfaces does not explicitly state whether an unsupported CAPTCHA boundary is required or bypassed during access.

    captcha_compatible_access: Unknown: tested 20 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can an agent obtain scoped, revocable authority for this service?

    supported: fresh

    Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.

    AWS STS operations such as AssumeRole and AssumeRoleWithWebIdentity provide temporary, scoped, and revocable security credentials in exchange for valid credentials or web identity tokens.

    delegated_identity_access: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can required phone verification be completed through a supported boundary?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    Documentation states that a phone number is required for identity verification during sign-up to receive automated calls or SMS codes, but it does not specify an explicit, supported agent handoff mechanism.

    phone_verification_compatible: Unknown: tested 20 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

  3. 03

    Pay

    Ready

    Charge or no-charge status, currency, recurrence, and material conditions are disclosed.

    A documented direct purchase path reaches paid access without a vendor decision point.

    Evidence and actions4 signals

    Can an agent construct checkout, hand off approval safely, and resume?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The retained evidence describes adding payment methods and completing account sign-up, but it does not establish a deterministic API or flow for agent-constructed checkout, approval handoff, and resumption.

    checkout_operability: Unknown: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Is the exact commercial commitment disclosed before authorization?

    supported: fresh

    Charge or no-charge status, currency, recurrence, and material conditions are disclosed.

    AWS discloses its pricing models, including pay-as-you-go, flat-rate, and Savings Plans commitments, and provides catalog prices via the AWS Price List APIs and service pricing pages.

    commitment_disclosure: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can payment be authorized within scoped agent or explicit human authority?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The evidence outlines account creation requirements and payment method management in the console, but it does not document a payment authorization rail supporting scoped agent delegation or human authorization with receipts.

    payment_authorization: Unknown: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Is a direct self-service path to paid access documented?

    supported: fresh

    A documented direct purchase path reaches paid access without a vendor decision point.

    AWS documents a direct self-service path to create an account, enter billing information, select a Support plan, and complete sign-up to activate services without vendor intervention.

    self_service_purchase: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

  4. 04

    Provision

    Ready

    Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

    Credentials, grants, or configuration are delivered through a documented agent-usable flow.

    A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.

    Evidence and actions3 signals

    Can usable access material be delivered securely to an authorized agent?

    supported: fresh

    Credentials, grants, or configuration are delivered through a documented agent-usable flow.

    AWS STS API operations create temporary security credentials that include an access key ID, a secret key, and a session token, which applications or users can use to access resources.

    access_material_delivery: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent determine successful provisioning completion and reconcile asynchronous failure?

    supported: fresh

    A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.

    AWS Cloud Control API provides get-resource-request-status to poll request progress using a RequestToken, returning an OperationStatus set to SUCCESS upon successful completion.

    provisioning_completion: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can provisioning be initiated within supported agent authority?

    supported: fresh

    Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

    AWS Cloud Control API provides a CreateResource operation to initiate resource creation programmatically.

    provisioning_operability: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

  5. 05

    Operate

    Limited

    Only part of the credential lifecycle is agent-operable.

    Every essential target has a stable documented agent-usable interface alternative.

    Request-time authentication is documented and usable under scoped agent authority.

    Essential operations have stable readable request, response, and effect semantics.

    Applicable limits, errors, retry, idempotency, cancellation, and reconciliation semantics are documented.

    Evidence and actions6 signals

    Is an agent-native protocol interface verified against the essential targets?

    missing: unknown

    Current admissible evidence does not resolve this finding.

    agent_protocol_interface: Unknown

    Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?

    supported: fresh

    Only part of the credential lifecycle is agent-operable.

    AWS STS documentation establishes that agents can request temporary credentials with specified validity durations using operations like GetFederationToken or AssumeRole. However, the evidence does not detail complete agent-executable revocation, compromise response, or recovery procedures.

    credential_lifecycle: Limited: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent handle applicable failure modes safely?

    supported: fresh

    Applicable limits, errors, retry, idempotency, cancellation, and reconciliation semantics are documented.

    AWS Cloud Control API documents idempotency via client tokens (valid for 36 hours), retries, and detailed HTTP status codes and error types (such as ThrottlingException, ConcurrentOperationException, and HandlerFailureException). Status tracking is supported via GetResourceRequestStatus using a RequestToken.

    failure_contract: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent authenticate service operations with scoped authority?

    supported: fresh

    Request-time authentication is documented and usable under scoped agent authority.

    AWS STS operations allow requesting temporary security credentials (access key ID, secret key, session token) and applying session policies to scope permissions programmatically for service requests.

    operation_authentication: Ready: tested 20 Aug

    Method public-http-semantic-assessment 2026-08-20

    Are essential operation inputs, outputs, and effects stable and decidable?

    supported: fresh

    Essential operations have stable readable request, response, and effect semantics.

    Essential operations and pricing endpoints across Cloud Control API, IAM STS, and AWS Price List have stable request/response schemas, JSON/HTTP parameters, and defined operational effects.

    operation_contract: Ready: tested 20 Aug

    • cloud-control
    • public-pricing

    Method public-http-semantic-assessment 2026-08-20

    Can an agent perform every essential assessment target through a usable interface?

    supported: fresh

    Every essential target has a stable documented agent-usable interface alternative.

    All evaluated targets provide documented programmatic interfaces, including HTTP APIs, AWS CLI commands, and SDK implementations.

    target_interface_access: Ready: tested 20 Aug

    • cloud-control
    • public-pricing

    Method public-http-semantic-assessment 2026-08-20

    What would improve this stage

    • Provide scoped expiry, rotation, revocation, compromise, and recovery operations.

What works

  • Sign up: A stable canonical route begins the required access bootstrap.
  • Pay: Charge or no-charge status, currency, recurrence, and material conditions are disclosed.
  • Provision: Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

What blocks agents

  • Evaluate: Only some material eligibility conditions are decidable before commitment.
  • Operate: Only part of the credential lifecycle is agent-operable.

Startup offers

AWS on the startup-offers board

catalog record →

Improve the report

Correct it, rerun it, or improve the funnel.

Profile
arp_01kzez1rxy9f1wce0r3p6yd35y
Projection
sha256:b39cc094dae8836d18a1de7af28c175b23975923db55fc94215687d0f3606f6b
Policy
service-use-2026-08-20-public-evidence-r9 · sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139