OrchestrAI Live

AWS · Cloud service

AWS Key Management Service with OrchestrAI

Catalog exported 2026-09-02

Manage AWS KMS keys from chat: create customer managed keys and aliases, disable keys, schedule deletion.

OrchestrAI exposes 5 KMS operations: 1 is low-risk (read-only or low-impact), 3 create or modify resources and run only after you confirm the plan, and 1 is destructive and requires a typed risk phrase. 4 of them also carry a step-level approval gate.

5operations
1low risk
3create or modify
1destructive
4step-level approval

What teams use it for

Security teams use OrchestrAI to create a customer managed key for a new workload, give it an alias like alias/prod-db, disable a key that is being retired, and schedule deletion with the AWS waiting period of 7 to 30 days. Key creation and disabling wait for your confirmation, alias creation is high risk, and scheduling deletion is critical and requires a typed risk phrase. Key policies, rotation settings, re-enabling a key, cancelling a scheduled deletion, and listing keys are not covered.

Every KMS operation, with its risk level

AWS Key Management Service operations available through OrchestrAI
Operation What it does Risk Step-level approval
Create KMS Key Create a KMS encryption key Low risk No
Create KMS Key Create an AWS KMS customer managed key for encryption Creates resources Yes
Disable KMS Key Disable a KMS key so it can no longer be used (reversible) Creates resources Yes
Create KMS Key Alias Create an alias for a KMS key Modifies existing Yes
Schedule KMS Key Deletion Schedule deletion of a KMS key (7–30 day AWS waiting period) Destructive Yes

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • Create a KMS key for the payments service in us-east-1 with the alias alias/payments-data
  • Disable the KMS key alias/legacy-backups
  • Schedule deletion of key 1234abcd-12ab-34cd-56ef-1234567890ab with a 30 day waiting period

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI cancel a scheduled KMS key deletion?
No, it can schedule deletion, which is critical risk with a typed phrase, but cancelling or re-enabling a key is done in the console.
Does OrchestrAI let me edit a KMS key policy?
Not yet; key policy and rotation configuration are outside the current operations, so set those in the console after creation.
Which KMS operations need an extra approval step?
4 operations carry a step-level approval gate on top of plan confirmation: Create KMS Key Alias, Create KMS Key, Disable KMS Key, Schedule KMS Key Deletion. One of these is classed destructive and cannot run without a typed risk phrase.

Other AWS services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.