Sherpa
← Blog
Blog

AWS has a FinOps, Security, and DevOps agent. The hard problems live between them.

Zohair, Founder of Sherpa
AWSAI agentsFinOpsCloud Security

At its New York Summit this month, AWS expanded its agent lineup: a DevOps Agent and a Security Agent, joining the FinOps Agent it launched earlier in June. Three agents, all on Bedrock AgentCore, all genuinely capable. It’s a strong signal that working with the cloud is becoming conversational — which is good for everyone building here.

It’s also worth looking at the shape of what shipped: one agent per domain.

What AWS shipped at Summit NY 2026

In the span of a couple of weeks, AWS put an agent in front of three of your biggest cloud surfaces: cost (FinOps Agent), security (Security Agent, with threat modeling and a Claude Code plugin), and delivery (DevOps Agent, with custom SRE agents and release management). The agent interface is no longer a question — the largest cloud provider just standardized on it.

One agent per domain

Each of these agents is excellent inside its lane. A cost agent reads cost data. A security agent reads security data. A DevOps agent reads pipelines and operations. The natural question is what happens between the lanes — because the promise of “talk to your cloud” was one conversation over everything, not a separate conversation per tool.

Why the expensive problems live between domains

The findings that cost the most money or carry the most risk rarely sit cleanly in one domain:

  • An idle load balancer isn’t only wasted spend — it may still be fronting an exposed workload. That’s a cost finding and a high-value security fix, and you only see the connection if one system holds both.
  • A cost spike is sometimes an over-permissioned IAM role calling a service it never should — a billing symptom of a security problem.
  • A rightsizing decision is only safe if you can see the workload’s real performance signals, not just its bill.

Give those to a single-domain agent and each sees half the picture. The connection — the part that matters — sits in the gap between the agents.

What a cross-domain agent does differently

Sherpa is built as one agent across cost, security, observability, and inventory, grounded on your live AWS environment. Because it reads all four on one connected layer, it can trace a finding instead of just listing it: surface the waste a cost engine has no category for, link an idle resource to the exposed workload behind it, size a Savings Plan on your optimized spend, then propose the exact fix to apply with your approval.

An agent per function and an agent across the whole cloud are different design choices, and both will have their place. But for the questions that span domains — which tend to be the ones that hurt — the connected view is the one that can answer them.

FAQ

What did AWS announce at Summit NY 2026?

Among other launches, AWS expanded its agent lineup with a DevOps Agent (custom SRE agents, release management) and a Security Agent (threat modeling, Claude Code plugin), both on Amazon Bedrock AgentCore. They join the AWS FinOps Agent released earlier in June 2026.

How is Sherpa different from AWS’s agents?

AWS ships a separate agent per domain — cost, security, DevOps — each scoped to its own data. Sherpa is a single agent across cost, security, observability, and inventory in one connected view, so it can link findings that span domains, such as an idle resource that is also an exposed attack surface.

Why does a single-domain agent miss things?

Because it only reads one domain’s data. Many of the most expensive cloud problems are cross-domain — a cost anomaly caused by a misconfigured identity, or idle spend that’s also a security exposure — and connecting them requires seeing both at once.

Can Sherpa take action, not just recommend?

Yes, with your approval. Sherpa Automate turns a recommendation into a ready-to-apply change — a plan plus a CloudFormation template and matching CLI — behind a human-in-the-loop gate, with every action audit-logged.

See what Sherpa finds in your AWS.