OrchestrAI Live

AWS · Cloud service

Amazon CloudWatch with OrchestrAI

Catalog exported 2026-09-02

Manage Amazon CloudWatch from chat: alarms, dashboards, log groups, metric queries, and custom metrics.

OrchestrAI exposes 10 CloudWatch operations: 7 are low-risk (read-only or low-impact), and 3 create or modify resources and run only after you confirm the plan. 1 of them also carries a step-level approval gate.

10operations
7low risk
3create or modify
0destructive
1step-level approval

What teams use it for

Operations teams use OrchestrAI to pull metric statistics for a resource, create or update alarms with an SNS action, assemble dashboards, publish custom metrics from a script, and create log groups for new services. Reading metrics and listing alarms are low risk, while creating an alarm waits for confirmation. CloudWatch Logs coverage is limited to creating log groups, with no Logs Insights queries or log event retrieval, and there is no operation to delete alarms or dashboards.

Every CloudWatch operation, with its risk level

Amazon CloudWatch operations available through OrchestrAI
Operation What it does Risk Step-level approval
Create CloudWatch Alarm Create a CloudWatch metric alarm Low risk No
Create CloudWatch Alarm Create or update a CloudWatch metric alarm for monitoring Low risk No
Create CloudWatch Dashboard Create a CloudWatch dashboard for monitoring Low risk No
Create CloudWatch Dashboard Create or update a CloudWatch dashboard for visualization Low risk No
Get CloudWatch Metrics Get metric statistics Low risk No
List CloudWatch Alarms List CloudWatch metric alarms Low risk No
Put CloudWatch Metric Put custom metric data Low risk No
Create CloudWatch Alarm Create CloudWatch metric alarm Creates resources Yes
Create CloudWatch Dashboard Create CloudWatch dashboard Creates resources No
Create CloudWatch Log Group Create a CloudWatch Logs log group Creates resources No

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • Get CPUUtilization for the prod-orders RDS instance over the last 6 hours at 5-minute intervals
  • Create a CloudWatch alarm that fires when 5xx errors on the checkout ALB exceed 50 in 5 minutes and notify the ops-alerts SNS topic
  • Build a dashboard called api-health with request count, latency, and error rate for the api-service

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI query CloudWatch Logs?
Not yet; it can create log groups, but it has no operation to search or retrieve log events, so Logs Insights queries stay in the console.
How does OrchestrAI handle CloudWatch alarm creation?
It shows the metric, threshold, and actions in a plan and waits for your confirmation. Existing alarms can be listed and updated with the same put operation.
Which CloudWatch operations need an extra approval step?
One operation carries a step-level approval gate on top of plan confirmation: Create CloudWatch Alarm. None of them is classed destructive.

Other AWS services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.