Everything AlphaAgent deploys
This page is the inventory for your security and SCP review: eleven CloudFormation stacks (six in the Organisations account, five per Studio account), every resource type in them, what is created outside CloudFormation, what Studio creates while it runs, every outbound call, and what is deliberately not present. Everything lands in the two kinds of AWS account you provide; nothing in the bundle is installed anywhere else.
Who this is for
Security reviewers and the cloud engineer preparing the accounts and their guardrails.
Before you start
Have the account structure from Before you start in mind: one Organisations account, one account per Studio deployment, and one region per account plus us-east-1 for the Studio front door.
The Organisations account
orgctl.py creates six stacks, all named alphaagent-org-<suffix>, in the region you choose. It creates them with your identity's permissions and no CloudFormation service role. The data, jobs and release-cache stacks are created concurrently with foundation; app is uploaded to S3 first because it exceeds CloudFormation's inline size limit.
| Stack | Resource types |
|---|---|
alphaagent-org-auth | Cognito user pool, user pool client, user pool domain (<prefix>.auth.<region>.amazoncognito.com); 1 Secrets Manager secret; 1 SSM parameter |
alphaagent-org-data | 9 DynamoDB tables (alphaagent-org-aws-accounts, -deployments, -provisioning-jobs, -job-steps, -audit, -admins, -locks, -usage-events, -libraries), 6 global secondary indexes in total |
alphaagent-org-jobs | 2 DynamoDB tables (-job-concurrency, -job-events) |
alphaagent-org-release-cache | 1 S3 bucket with bucket policy; 1 DynamoDB table (-release-cache, 1 index) that catalogues mirrored Studio releases |
alphaagent-org-foundation | VPC, 4 subnets, 2 route tables, 2 routes, 4 subnet associations, internet gateway and attachment, 1 NAT gateway with 1 Elastic IP, 3 security groups and 1 ingress rule; 9 VPC endpoints (S3, DynamoDB, Secrets Manager, ECR API, ECR Docker, CloudWatch Logs, SSM, STS, CloudFormation); 3 S3 buckets (bundle cache, frontend, CloudFormation templates); 5 ECR repositories (alphaagent-org/org-app, /studio, /studio-envs, /studio-web-browser-search, /mirror); 6 Secrets Manager secrets (shells, filled by the installer); 3 log groups; no IAM resources |
alphaagent-org-app | Application Load Balancer, 2 listeners, 2 listener rules, 2 target groups; ECS cluster with capacity provider association; 2 task definitions (org-api, org-provisioner) and 2 services; 1 Lambda function (the console's page server) with its permission; 3 IAM roles (spa-server-role, task-exec-role, and alphaagent-org-task-role, the role that assumes into Studio accounts); 1 Cloud Map HTTP namespace; 1 SNS topic (worker alerts); 4 CloudWatch alarms and 4 metric filters; 1 log group |
The Organisations bundle
The bundle you download from AlphaAgent Console, alphaagent-org-cfn-bundle-<version>.zip, holds 30 files: orgctl.py and the modules it imports (org_preflight.py, org_secret_schema.py, model_classes.py, configure-saml.py, _shared/); README.md; RELEASE.txt with the keys version, channel, product, image_tar, image_tag_in_tar, console_base_url and released_at; cloudformation/org-target-account-role.yaml, the six stack templates (org-auth, org-data, org-foundation, org-jobs, release-cache, org-app) and cloudformation/lib/; the console's web files under spa/; and the container image image.tar.gz. No checksum is published; the installer's bundle-complete preflight check lists any missing member.
Created in the Organisations account outside CloudFormation:
| What | When | How |
|---|---|---|
The Organisations container image in alphaagent-org/org-app | push-image step | pushed from the bundle with crane, regctl or Docker |
| Configuration secret values in the six secret shells | seed-config step | PutSecretValue or CreateSecret |
| The console's web files in the frontend bucket | spa step | PutObject with cache and content-type headers, SSE-S3 |
org-app.yaml and org-target-account-role.yaml in the templates bucket | app step | the account template is staged at bootstrap/org-target-account-role.yaml for the Accounts wizard's Launch Stack link |
Secret alphaagent-org-console-credential | console-credential step | validated against AlphaAgent Console, then stored |
| The Cognito SAML identity provider and client settings | saml step | create or update the provider, update the client |
| The first owner row and the break-glass user | saml or bootstrap-admin step | a DynamoDB item in alphaagent-org-admins and a Cognito user with an emailed temporary password |
| Studio release bundles in the bundle-cache bucket | at runtime, per release | downloaded from AlphaAgent Console through a time-limited link and stored by multipart upload |
Studio container images in alphaagent-org/studio, /studio-envs, /studio-web-browser-search | at runtime, per release | pushed by digest from the cached bundle |
| Rows in the DynamoDB tables (jobs, leases, events, deployments, API-key mirrors) | at runtime | by the console's services |
| App-role assignments in your Entra ID tenant | at runtime | written by the console's API through Microsoft Graph; not an AWS resource |
Each Studio account
The Organisation's provisioner assumes the account's target role and creates five stacks named alphaagent-<deployment id>-<suffix>, four in the deployment region and one in us-east-1. Templates come from the cached release bundle; every deploy passes CAPABILITY_NAMED_IAM and CAPABILITY_AUTO_EXPAND. Resource names stem from alphaagent.
| Stack | Region | Resource types |
|---|---|---|
...-core | deployment region | VPC, 4 subnets, 2 route tables, 2 routes, 4 associations, internet gateway and attachment, 1 NAT gateway with 1 Elastic IP, 5 security groups and 1 ingress rule; 10 VPC endpoints (S3, DynamoDB, Secrets Manager, STS, ECR API, ECR Docker, CloudWatch Logs, SQS, SSM, Bedrock runtime); 38 DynamoDB tables (16 with global secondary indexes); 7 S3 buckets (workspaces, knowledge-graph artifacts, knowledge-graph processing, knowledge-graph training, chat overflow, code scripts, frontend); 6 SQS queues and 3 queue policies (three queues each with a dead-letter queue); 18 Secrets Manager secrets (one configuration shell per service); 3 ECR repositories (alphaagent-envs, alphaagent/web-browser-search, alphaagent/studio); 1 ElastiCache Redis replication group with subnet group; 1 EFS file system with 2 mount targets and 2 access points (for the self-hosted graph database); Cognito user pool, client and domain; 2 IAM roles (lambda-execution-role, sandbox-scoped-role); 1 EventBridge rule; 1 SNS topic with subscription; 2 SSM parameters; 10 log groups |
...-stateless | deployment region | Application Load Balancer, 2 listeners, 15 listener rules, 11 target groups, 1 security group; 1 Lambda function (page server) with role and permission; 1 CloudFront distribution whose alias is the app domain (a global resource, created from this stack); AWS WAF IP set, web ACL and association only when a public-API allow-list is configured; 1 log group |
...-compute | deployment region | 1 Cloud Map HTTP namespace; ECS cluster with capacity provider association; 2 IAM roles (task-exec-role, task-role; the task role carries the Bedrock invoke actions and aws-marketplace:ViewSubscriptions, Subscribe, Unsubscribe) |
...-taskdef | deployment region | 12 ECS task definitions and 11 services on ARM64 Fargate (agent-management, agent-runtime, chat, data-connector, workflow, knowledge-base, knowledge-base-mcp, code-interpreter, web-browser-search, notification-service, neo4j), plus one task definition with no service (kg-transfer, run on demand); 6 CloudWatch alarms, 2 metric filters, 3 log groups |
...-edge | us-east-1 | 1 IAM role (alphaagent-<deployment id>-edge-role, trusting Lambda and Lambda@Edge), 1 Lambda function (Node.js 20, inline code) and 1 Lambda version, retained on delete |
Created in the Studio account outside CloudFormation, by the deploy job:
| What | When | How |
|---|---|---|
Deploy bucket alphaagent-deploy-<account>-<region> | first use | CreateBucket, then all four public-access blocks on, SSE-S3, versioning if allowed |
Staging bucket alphaagent-org-staging-<account>-<region> | when you run the account template | created by your registration stack, not by the job |
Secret alphaagent-<deployment id>-edge-origin | edge step | 24 random bytes, minted once; becomes the CloudFront origin-lock header |
Secret alphaagent-neo4j-credentials | neo4j-creds step | PutSecretValue or CreateSecret |
Configuration secret values (alphaagent-common-config, alphaagent-internal-api-key, one per service) | seed-config step | written from the release's own configuration schema; signing and redaction keys minted here |
| The three Studio images in the account's own ECR repositories | push-image and verify-images steps | copied by digest from the Organisation's registry with one tool holding both registries' credentials; no cross-account repository policy on either side |
| The Studio web files in the frontend bucket | spa step | PutObject |
| Maintenance page objects in the frontend bucket | during updates | PutObject |
An ACM certificate for the app domain in us-east-1 | edge step | RequestCertificate with DNS validation, tagged alphaagent:deployment; the job waits for it to issue and, if it does not, lists the validation CNAME records on the failure card |
| The Cognito SAML identity provider and client settings | saml step | create or update |
| ECS service redeploys | settle step | UpdateService |
Created in the Studio account by Studio itself, while it runs:
| What | By | Naming |
|---|---|---|
| An EventBridge rule with an SQS target per workflow schedule | workflow service | <prefix><schedule id> |
A Lambda function per execution environment, from the alphaagent-envs image, optionally inside the VPC | agent-management service | alphaagent-env-<environment id> |
Secret alphaagent/prompt-key | agent-runtime, on licence activation | fixed name |
| A secret holding connector credentials | data-connector service | fixed name from configuration |
| A secret per agent holding that agent's connector credentials | code-interpreter service | <prefix><agent id> |
Knowledge-graph training runs in the knowledge-base task's own disk and storage; it does not use SageMaker or Batch.
Outbound calls
| From | To | Why |
|---|---|---|
| Your workstation (running the Organisations installer) | AWS APIs; telemetry.api.alphaagent.prometheusrl.com | the install; validating the Organisation credential |
| The Organisations VPC (through its endpoints or NAT) | AWS APIs in your account; sts:AssumeRole into each Studio account; telemetry.api.alphaagent.prometheusrl.com; the time-limited S3 link the Console returns | running jobs; reading the Studio release catalogue and downloading release bundles |
| The Organisations console's API | Microsoft Graph (your Entra ID tenant) | creating each Studio's enterprise application and assigning users |
| Each Studio VPC (through its endpoints or NAT) | AWS APIs; Amazon Bedrock through the bedrock-runtime VPC endpoint; telemetry.api.alphaagent.prometheusrl.com | running Studio; model calls; licence activation, heartbeat and metering |
| Each Studio VPC at task start (through NAT) | Docker Hub: neo4j:5.26-community and searxng/searxng:latest | the two containers that are pulled from a public registry rather than from your ECR |
| The web-browser-search service (through NAT) | public search engines | web search for agents |
| Operators' browsers | fonts.googleapis.com, fonts.gstatic.com | the console's web fonts; optional, system fonts are used where blocked |
What crosses to AlphaAgent and what does not is the subject of What leaves your account.
What is not present
- No customer-managed KMS keys: every bucket uses SSE-S3 (
AES256), ECR repositories useAES256, ElastiCache has encryption at rest and in transit on, EFS is encrypted with AWS-managed keys. The target role'skms:*grant applies only through those services. - No CloudTrail trails, no AWS Config rules or recorders.
- No Batch, no SageMaker, no Bedrock resources (Bedrock is reached only through the VPC endpoint and the task role's invoke actions).
- No Route 53 records: every DNS record is yours to create.
- No StackSets, no cross-account ECR repository policies, no IAM users or access keys (the target role and the Organisation's own role deny creating them).
- No public S3 access: every bucket has all four public-access blocks on and no ACLs.
- No permissions boundaries on any created role.
- No common tag set: some resources carry a
Nametag, the staging bucket carriesalphaagent:managed-byandalphaagent:purpose, the us-east-1 certificate carriesalphaagent:deployment; nothing else is tagged.
Limits
- The counts above are read from the templates of the current release; a later release may add or remove resources, and the page is re-verified from the templates named in its sources.
DeletionPolicy: Retainis set on data-bearing resources (71 in the Studio core template alone); deleting a deployment reports what it kept, and Clear account removes it. See Deleting a deployment and clearing an account.
If something goes wrong
If a guardrail in your organisation denies one of these resource types or one of these outbound calls, the install stops with copy that names the denied action or the failed CloudFormation resource; every pattern is listed on SCPs and guardrails that block installs.