AWS Training
Modules Listen Certification
0:00 0:00

← Platform Foundations

Starts this lesson and continues through 29 more to the end of the course.

Editions, subscriptions, and roles

Two pricing models, both documented as current

Ask "what edition are we on?" and you'll get a confident answer. Ask "what subscription are we on?" and you'll get a different confident answer. Both people are reading current AWS documentation.

Here is the actual state of affairs, verified 2026-08-09:

⚠️ Documentation inconsistency: the page at /quick/latest/userguide/editions.html — a URL that promises editions — resolves to a page titled "Amazon Quick user types" that describes subscriptions and never mentions Standard or Enterprise. Meanwhile Connecting to data in Amazon Quick Sight has sections headed "Amazon Quick Standard edition capabilities" and "Amazon Quick Enterprise edition capabilities", and the data source quotas page gives different numeric quotas per edition.

Both models are live in the docs. You need to hold both.

What the edition actually gates

This is the list that matters, because if you're on Standard, several things people assume are "basic BI features" are simply not available to you.

Standard edition capabilities (verbatim from Connecting to data in Amazon Quick Sight):

Enterprise edition adds (verbatim, same page):

The three in bold are the ones that decide architectures:

Capability Standard Enterprise
VPC / on-premises data sources ❌ ✅
Encryption at rest ❌ ✅
Row-level and column-level security ❌ ✅
Hourly refresh ❌ ✅
ML insights, narrative insights ❌ ✅
Emailed reports ❌ ✅

⚠️ If your data lives in a private VPC, Standard edition cannot reach it. Not "with difficulty" — the capability is edition-gated. This is the single most common way a proof-of-concept account turns out to be unusable for the real deployment.

⚠️ Multi-tenancy is impossible on Standard. Row-level security is the mechanism by which one dataset serves many customers or many regions. Without it, your only isolation is one dataset per tenant, which multiplies your SPICE footprint and your ingestion-call consumption (Q2, lesson 2).

The edition also changes your quotas

From Data source quotas and the Service Quotas table:

Quota Standard Enterprise
Rows per SPICE dataset 25,000,000 2,000,000,000
Size per SPICE dataset 25 GB 2 TB
CreateIngestion calls per 24h 8 32
Incremental refresh ❌ ✅

That's an 80× difference in rows and a 4× difference in refresh calls. If you are doing anything at volume, the edition question is settled before you start.

Subscriptions and roles

The post-rename model describes three personas — administrator, author, reader — across six roles, where the "Pro" variants unlock the AI capabilities (Amazon Quick user types):

Subscription Equivalent role
Amazon Quick Professional Quick Sight Reader Pro
Amazon Quick Enterprise Quick Sight Author Pro
— (BI only) Quick Sight Reader
— (BI only) Quick Sight Author

"To manage Amazon Quick users, billing and services, you need the Admin Pro role, which is the same as Amazon Quick Enterprise user subscription."

"To manage Amazon Quick Sight users, billing and services, you need Admin role, which is the same as Amazon Quick Sight Author user subscription."

In plain terms: Admin is not a separate subscription you buy. It's an Author (or Author Pro) with administrative rights. Making somebody an admin costs an author seat, not an admin seat.

Roughly:

Pricing, and the fee people forget

From the announcement blog (2025-10-09):

Role Price
Reader $3/month
Author $24/month
Reader Pro $20/month
Author Pro $40/month (reduced from $50)

Plus: a $250/month infrastructure fee for Pro users or active Topics / Dashboard Q&A, described as "promotionally waived through December 31, 2025" for new activations after 2025-10-09.

⚠️ That $250 is a monthly floor, not a per-user charge, and it turns on when somebody enables a Pro capability or a Q&A topic. A team of three doing a Pro trial can add $250/month to the bill without anybody choosing to spend it.

⚠️ These figures are from an October 2025 announcement and this lesson was verified 2026-08-09 — the promotional waiver period described has passed. Do not quote these prices in a business case. Get current numbers from Amazon Quick pricing. They are here so you recognise the shape of the model, not the amounts.

Admin rights are split between two systems

This one causes real confusion, and it's documented plainly. When your account is integrated with IAM Identity Center, admin capability is split: some of the admin console is governed by IAM permissions, and some by the Quick admin role (Amazon Quick user types).

Admin action IAM permissions Quick admin role
Manage assets ✅ ❌
Security & permissions ✅ ❌
Manage VPC connections ✅ ❌
KMS keys ✅ ❌
Account settings ✅ ❌
Account customization ❌ ✅
Manage users ✅ (IAM Identity Center users) ✅ (Quick and IAM users)
Your subscriptions ❌ ✅
Mobile settings ❌ ✅
Domains and embedding ❌ ✅
SPICE capacity ❌ ✅

Read the two rows in bold together and you get the practical consequence:

A cloud-platform engineer with broad IAM rights cannot manage SPICE capacity, and a Quick admin cannot manage VPC connections or KMS keys. Those are two different people in most organisations, and neither can do the other's job.

⚠️ If you are the person who will be paged about a failed overnight refresh, you need the Quick admin role — IAM power alone will not let you see or buy SPICE capacity.

How to tell what you're actually on

The console is the fastest answer, but from the CLI:

# Edition, notification email, account name, subscription status
aws quicksight describe-account-settings \
  --aws-account-id 111122223333 --region us-east-1

# Who exists and with what role
aws quicksight list-users \
  --aws-account-id 111122223333 --namespace default --region us-east-1 \
  --query 'UserList[].{Name:UserName,Role:Role,Email:Email,Active:Active}' --output table

Run both on any account you inherit, before you promise anybody anything.

Check yourself

  1. A proof of concept ran on Standard and worked. Production data is in a private VPC. What happens?
  2. Your CTO asks for row-level security so one dashboard can serve 40 customers. Account is Standard. What are you actually asking for budget for?
  3. Someone is made an admin. Which seat does that consume?
  4. You have full AdministratorAccess in IAM. Can you purchase SPICE capacity?
  5. Why shouldn't you put the prices from this lesson in a business case?
Answers
  1. It can't connect. VPC and on-premises data sources are an Enterprise edition capability. The PoC proved nothing about the production topology.
  2. An edition upgrade to Enterprise — RLS and CLS are edition-gated. Frame it that way, and note that the alternative (one dataset per customer) multiplies both SPICE footprint and CreateIngestion quota consumption.
  3. An Author seat (or Author Pro). Admin is not a separate subscription — it's an author with administrative rights.
  4. No. SPICE capacity is governed by the Quick admin role, not IAM permissions. IAM governs assets, security & permissions, VPC connections, KMS keys and account settings.
  5. They're from an October 2025 announcement, the promotional waiver described has since lapsed, and this lesson was verified 2026-08-09. Pull current numbers from the pricing page.

Teaching this section

← PreviousThe rename, and the three live doc treesNext →Identity: the decisions you make once