AWS Training
Modules Listen Certification

← The Quick Suite AI Layer

Starts this lesson and continues through 10 more to the end of the course.

Research, auditability, and running the meter

Why this matters

The last mile of being the Quick expert isn't a feature — it's being able to answer "what did the AI do, who told it to, and what did it cost?" This lesson covers Quick Research (the most expensive button in the product), the logging architecture that answers auditors, and the cost traps across everything this module introduced.

Quick Research

What it is (using-amazon-quick-research, verified 2026-08-26): "conduct comprehensive research by analyzing multiple data sources and generating detailed reports… gather, analyze, and synthesize information from various sources including web search, uploaded files, connected data spaces, knowledge bases, actions, and third-party data providers… AI-generated research reports with proper citations and source tracing."

The operational facts (view-research-report, verified 2026-08-26):

Research also appears as a step type inside Flows — the page "Quick Research steps in Amazon Quick Flows" exists, but its content wouldn't render on fetch (2026-08-26), so treat the details as unverified and check the page before designing around it. Similarly, we found no documented hard limits for Research (report length, source count, runs/month beyond agent hours) — say "not documented" rather than inventing a number.

Who did what: the logging architecture

The suite's audit story is split across services, and the split is the exam question. Incident response, logging and monitoring (verified 2026-08-26):

You want to know Look in
"Which API calls occurred for AI features (flows, agents, automations, action connectors)" CloudTrail (management and data events)
Chat conversations and feedback content CloudWatch vended logs — CHAT_LOGS, FEEDBACK_LOGS
Index consumption, knowledge-base syncs INDEX_USAGE_LOGS, KB_FILE_SYNC_LOGS
Agent-hours consumption agent-hours usage logs (CloudWatch)
Non-API user events like dashboard views CloudTrail's "documented set of non-API events"
Routing/alerting EventBridge; CloudWatch metrics
The built-in usage analytics dashboard gated by the IAM action quicksight:QuickSuiteUsageMetrics

The sentence to internalize: CloudTrail has the actions; CloudWatch vended logs have the conversations. An auditor asking "show me what users asked the AI" gets CHAT_LOGS, not CloudTrail — and if vended logs were never enabled, that history may simply not exist. Enabling them is a day-one governance task, not a post-incident one.

For Automate specifically (lesson 5's pages, verified 2026-08-26): per-run "logs, metrics" with inputs/outputs "available as structured artifacts in the logs panel on the Runs page", plus per-agent unit testing with metrics ("Total execution time, Number of tools used, Number of tasks created"). Flows and automations are also governable pre-deployment: flow sharing "may require approval review", automations deploy only from committed versions, and the quota table carries approval policies (500/account, 100/asset type — both adjustable; verified 2026-08-26 on the Service Quotas page).

Actions: the other blast radius

Chat, agents, flows, and automations can all write to external systems through action connectors — the supported-integrations table lists ~60, from Slack and Jira to SAP, plus generic MCP, OpenAPI, and REST API connectors (supported-integrations, verified 2026-08-26). Governance handles:

The cost recap for the whole module

The complete meter list for the AI layer, with sources from this module's lessons (all verified 2026-08-26):

Meter Rate Trap
Seats $0 / $20 / $20 / $40 per user/month Plans ≠ editions; Topics still gate on Enterprise Edition
Infrastructure fee $250/account/month (Pro/Ent) Exists at one user or one thousand
Index storage 25/50 GB/user pooled; $5/GB/month over Counts source bytes; extra-Region capacity is all overage
Agent hours 4/8 per user pooled; $3/hour over Research ≈ 0.3–0.7 hr/run; scheduled automations run unattended
Dashboard Q&A "the associated enablement fee" (dashboard-qa page) Per-feature fee, easy to miss in a proposal
Custom-model (Bedrock) inference billed to the Bedrock account Invisible on the Quick bill

What to hand AWS Support

For an AI-layer case, the evidence bundle (pattern from Q2/Q8, adapted):

account ID + home Region · plan/edition · the feature and its doc-tree URL (say which of the three trees, given the inconsistencies) · for flows/automations: automation-group ID, automation ID, JobId from start-automation-job, job status, and the run's log artifacts · for index/space issues: index capacity setting, INDEX_USAGE_LOGS excerpt, KB_FILE_SYNC_LOGS for sync failures · for chat quality issues: the conversation from CHAT_LOGS and the Explanation panel's generated SQL · CloudTrail event IDs for the API calls involved.

Check yourself

  1. An auditor asks for every prompt users sent to chat last quarter. Where is it — and what's the catch?
  2. Which IAM action gates the built-in usage analytics dashboard?
  3. Estimate the agent-hour cost of a team running 30 Research reports a month on Professional with 5 users.
  4. What makes an MCP connector different in risk from the Slack connector?
  5. A customer's automation "ran but nothing happened in the target app." Name three evidence items you'd collect before escalating.
  6. Which costs from the AI layer never appear on the Quick bill?
Answers
  1. CloudWatch vended logs (CHAT_LOGS) — not CloudTrail. The catch: vended logs must have been enabled; there's no retroactive capture, and chat conversations are retained 90 days in-product.
  2. quicksight:QuickSuiteUsageMetrics.
  3. 5 users × 2 Research hours = 10 pooled Research hours. 30 runs × 20–40 min ≈ 10–20 hours, so roughly 0–10 hours of overage ≈ $0–30 — cheap, but scale by 10× users and it isn't.
  4. Slack is a fixed, AWS-shipped integration; MCP points at an arbitrary remote server whose tools your agents will call — it's third-party code in the loop and needs dependency-style review.
  5. JobId + describe-automation-job status; the run's structured input/output artifacts from the Runs page logs panel; CloudTrail events for the action-connector calls (plus whether the target app's credential is valid).
  6. Custom-mode Bedrock inference (bills to the Bedrock-integrated account) — and arguably the human hours resolving HITL tasks.

Teaching this section

← PreviousFlows, Automate, and agentic developmentFinished →Cheat sheet, lab & quiz