Deleting a deployment and clearing an account
For Owners and Operators (or a DeploymentOperator or AccountManager Role) removing a Studio deployment, then resetting the AWS account it lived in; Viewers can watch the jobs. Deleting is irreversible once the grace window has passed, so export anything you need from Studio first. Nothing here touches your DNS records or your Microsoft Entra tenant.
Delete a deployment
- Open Fleet, click the deployment, click Delete in the header.
- Delete this deployment warns that this starts an irreversible teardown of the deployment's CloudFormation stacks, cancellable for a short grace window. Type the deployment's name and click Start teardown.
- The console opens the uninstall job in the Jobs view.
Refusals: already uninstalled; "Another job is already in flight for this deployment."; the name could not be confirmed; or the request could not be sent (nothing was applied). Delete is disabled while another job runs and without the DeploymentOperator permission.
Cancel during the grace window
While the first step waits, a bar reads "Nothing has been deleted yet. Cancel now to keep <name>." Click Cancel teardown. Once the window has passed the bar refuses ("this teardown can no longer be cancelled from here"). The window is 30 seconds by default (engine setting ORG_DESTRUCTIVE_GRACE_SECONDS); the bar disappears when it has passed.
Read the teardown report
Resources that hold data (tables, secrets, buckets, repositories, file systems) are retained rather than deleted. When the job deletes the core stack, the Jobs view adds What was retained: a table grouped by resource type, each row "<identifier> · <region>" with a note on its scope, or "Nothing is retained".
On success the Fleet row reads Uninstalled and the Overview stays readable. Its Endpoints group warns that the app domain's CNAME points at a distribution that no longer exists: remove or re-point it, because CloudFront refuses a new install under the domain while it stands; after the new install, point it at the new DNS target. A failed uninstall names what stopped it; stack_delete_failed, core_stack_blocked_by_lambda_enis and redis_busy resume once the named resource is released (Failure codes).
Clear the account
Open Accounts, click the account, and find Clear account. It scans the account's first allowed region for every AlphaAgent resource still there and permanently deletes it: use it to reset an account before re-registering it, or to finish a teardown that did not complete.
- Click Scan for stray resources. Results list each resource as "<type>: <id>" under its region, or "No AlphaAgent resources found in this account/region." If some types could not be checked, the account role is missing a permission: re-run the CloudFormation template above, then scan again.
- Click Wipe N resource(s). The confirmation warns that every AlphaAgent resource in this account/region is deleted (every deployment's stacks, data and networking), irreversibly; the registration role and stack are preserved so Verify keeps working. Deployment records are marked uninstalled here too; if one is still running you must type the account id.
- Click Start clearing. The job runs on this page with the same parked-step card, failure card and timeline as a deployment job, and appears in job lists as Account wipe.
A wipe that finds resources still standing fails with wipe_leftovers, listing them. Redo re-runs the whole pass (every step is idempotent) and a second pass clears most leftovers; or Abandon, then scan and wipe again. A resource that survives twice is held by a bucket with Object Lock, a resource-level service control policy (SCP) or a cross-account share; lift that in the AWS console first.
Verify the account afterwards
Click Verify again. Verify assumes the account's role, retries any CloudFront edge stacks still waiting on Lambda@Edge replica cleanup, and confirms "Last Clear account left nothing behind". A clean account can take a new deployment (Accounts).
What you should see
- After a delete: an Uninstall job ending Succeeded, What was retained listing the data-bearing resources, the Fleet row Uninstalled.
- After a clear: an Account wipe job ending Succeeded, a scan that finds nothing, and Verify passing.
Notes
- What remains yours to remove: the app domain's DNS record; the Enterprise Applications Microsoft created for the deployment's single sign-on (the console never removes them; delete them in the Entra admin center); the account's registration stack, if you also delete the account from Organisations; and the retained data resources, once you no longer need their contents (Clear account removes them).
- Clear account works on the account's first allowed region only. The registration role and stack are preserved.
- A deployment record stays in the Fleet as Uninstalled.
- Lambda@Edge replicas are released by AWS after a distribution is deleted, so an edge stack can linger; Verify retries it each time.