Skip to main content

Everything AlphaAgent deploys

This page is the inventory for your security and SCP review: eleven CloudFormation stacks (six in the Organisations account, five per Studio account), every resource type in them, what is created outside CloudFormation, what Studio creates while it runs, every outbound call, and what is deliberately not present. Everything lands in the two kinds of AWS account you provide; nothing in the bundle is installed anywhere else.

Who this is for​

Security reviewers and the cloud engineer preparing the accounts and their guardrails.

Before you start​

Have the account structure from Before you start in mind: one Organisations account, one account per Studio deployment, and one region per account plus us-east-1 for the Studio front door.

The Organisations account​

orgctl.py creates six stacks, all named alphaagent-org-<suffix>, in the region you choose. It creates them with your identity's permissions and no CloudFormation service role. The data, jobs and release-cache stacks are created concurrently with foundation; app is uploaded to S3 first because it exceeds CloudFormation's inline size limit.

StackResource types
alphaagent-org-authCognito user pool, user pool client, user pool domain (<prefix>.auth.<region>.amazoncognito.com); 1 Secrets Manager secret; 1 SSM parameter
alphaagent-org-data9 DynamoDB tables (alphaagent-org-aws-accounts, -deployments, -provisioning-jobs, -job-steps, -audit, -admins, -locks, -usage-events, -libraries), 6 global secondary indexes in total
alphaagent-org-jobs2 DynamoDB tables (-job-concurrency, -job-events)
alphaagent-org-release-cache1 S3 bucket with bucket policy; 1 DynamoDB table (-release-cache, 1 index) that catalogues mirrored Studio releases
alphaagent-org-foundationVPC, 4 subnets, 2 route tables, 2 routes, 4 subnet associations, internet gateway and attachment, 1 NAT gateway with 1 Elastic IP, 3 security groups and 1 ingress rule; 9 VPC endpoints (S3, DynamoDB, Secrets Manager, ECR API, ECR Docker, CloudWatch Logs, SSM, STS, CloudFormation); 3 S3 buckets (bundle cache, frontend, CloudFormation templates); 5 ECR repositories (alphaagent-org/org-app, /studio, /studio-envs, /studio-web-browser-search, /mirror); 6 Secrets Manager secrets (shells, filled by the installer); 3 log groups; no IAM resources
alphaagent-org-appApplication Load Balancer, 2 listeners, 2 listener rules, 2 target groups; ECS cluster with capacity provider association; 2 task definitions (org-api, org-provisioner) and 2 services; 1 Lambda function (the console's page server) with its permission; 3 IAM roles (spa-server-role, task-exec-role, and alphaagent-org-task-role, the role that assumes into Studio accounts); 1 Cloud Map HTTP namespace; 1 SNS topic (worker alerts); 4 CloudWatch alarms and 4 metric filters; 1 log group

The Organisations bundle​

The bundle you download from AlphaAgent Console, alphaagent-org-cfn-bundle-<version>.zip, holds 30 files: orgctl.py and the modules it imports (org_preflight.py, org_secret_schema.py, model_classes.py, configure-saml.py, _shared/); README.md; RELEASE.txt with the keys version, channel, product, image_tar, image_tag_in_tar, console_base_url and released_at; cloudformation/org-target-account-role.yaml, the six stack templates (org-auth, org-data, org-foundation, org-jobs, release-cache, org-app) and cloudformation/lib/; the console's web files under spa/; and the container image image.tar.gz. No checksum is published; the installer's bundle-complete preflight check lists any missing member.

Created in the Organisations account outside CloudFormation:

WhatWhenHow
The Organisations container image in alphaagent-org/org-apppush-image steppushed from the bundle with crane, regctl or Docker
Configuration secret values in the six secret shellsseed-config stepPutSecretValue or CreateSecret
The console's web files in the frontend bucketspa stepPutObject with cache and content-type headers, SSE-S3
org-app.yaml and org-target-account-role.yaml in the templates bucketapp stepthe account template is staged at bootstrap/org-target-account-role.yaml for the Accounts wizard's Launch Stack link
Secret alphaagent-org-console-credentialconsole-credential stepvalidated against AlphaAgent Console, then stored
The Cognito SAML identity provider and client settingssaml stepcreate or update the provider, update the client
The first owner row and the break-glass usersaml or bootstrap-admin stepa DynamoDB item in alphaagent-org-admins and a Cognito user with an emailed temporary password
Studio release bundles in the bundle-cache bucketat runtime, per releasedownloaded from AlphaAgent Console through a time-limited link and stored by multipart upload
Studio container images in alphaagent-org/studio, /studio-envs, /studio-web-browser-searchat runtime, per releasepushed by digest from the cached bundle
Rows in the DynamoDB tables (jobs, leases, events, deployments, API-key mirrors)at runtimeby the console's services
App-role assignments in your Entra ID tenantat runtimewritten by the console's API through Microsoft Graph; not an AWS resource

Each Studio account​

The Organisation's provisioner assumes the account's target role and creates five stacks named alphaagent-<deployment id>-<suffix>, four in the deployment region and one in us-east-1. Templates come from the cached release bundle; every deploy passes CAPABILITY_NAMED_IAM and CAPABILITY_AUTO_EXPAND. Resource names stem from alphaagent.

StackRegionResource types
...-coredeployment regionVPC, 4 subnets, 2 route tables, 2 routes, 4 associations, internet gateway and attachment, 1 NAT gateway with 1 Elastic IP, 5 security groups and 1 ingress rule; 10 VPC endpoints (S3, DynamoDB, Secrets Manager, STS, ECR API, ECR Docker, CloudWatch Logs, SQS, SSM, Bedrock runtime); 38 DynamoDB tables (16 with global secondary indexes); 7 S3 buckets (workspaces, knowledge-graph artifacts, knowledge-graph processing, knowledge-graph training, chat overflow, code scripts, frontend); 6 SQS queues and 3 queue policies (three queues each with a dead-letter queue); 18 Secrets Manager secrets (one configuration shell per service); 3 ECR repositories (alphaagent-envs, alphaagent/web-browser-search, alphaagent/studio); 1 ElastiCache Redis replication group with subnet group; 1 EFS file system with 2 mount targets and 2 access points (for the self-hosted graph database); Cognito user pool, client and domain; 2 IAM roles (lambda-execution-role, sandbox-scoped-role); 1 EventBridge rule; 1 SNS topic with subscription; 2 SSM parameters; 10 log groups
...-statelessdeployment regionApplication Load Balancer, 2 listeners, 15 listener rules, 11 target groups, 1 security group; 1 Lambda function (page server) with role and permission; 1 CloudFront distribution whose alias is the app domain (a global resource, created from this stack); AWS WAF IP set, web ACL and association only when a public-API allow-list is configured; 1 log group
...-computedeployment region1 Cloud Map HTTP namespace; ECS cluster with capacity provider association; 2 IAM roles (task-exec-role, task-role; the task role carries the Bedrock invoke actions and aws-marketplace:ViewSubscriptions, Subscribe, Unsubscribe)
...-taskdefdeployment region12 ECS task definitions and 11 services on ARM64 Fargate (agent-management, agent-runtime, chat, data-connector, workflow, knowledge-base, knowledge-base-mcp, code-interpreter, web-browser-search, notification-service, neo4j), plus one task definition with no service (kg-transfer, run on demand); 6 CloudWatch alarms, 2 metric filters, 3 log groups
...-edgeus-east-11 IAM role (alphaagent-<deployment id>-edge-role, trusting Lambda and Lambda@Edge), 1 Lambda function (Node.js 20, inline code) and 1 Lambda version, retained on delete

Created in the Studio account outside CloudFormation, by the deploy job:

WhatWhenHow
Deploy bucket alphaagent-deploy-<account>-<region>first useCreateBucket, then all four public-access blocks on, SSE-S3, versioning if allowed
Staging bucket alphaagent-org-staging-<account>-<region>when you run the account templatecreated by your registration stack, not by the job
Secret alphaagent-<deployment id>-edge-originedge step24 random bytes, minted once; becomes the CloudFront origin-lock header
Secret alphaagent-neo4j-credentialsneo4j-creds stepPutSecretValue or CreateSecret
Configuration secret values (alphaagent-common-config, alphaagent-internal-api-key, one per service)seed-config stepwritten from the release's own configuration schema; signing and redaction keys minted here
The three Studio images in the account's own ECR repositoriespush-image and verify-images stepscopied by digest from the Organisation's registry with one tool holding both registries' credentials; no cross-account repository policy on either side
The Studio web files in the frontend bucketspa stepPutObject
Maintenance page objects in the frontend bucketduring updatesPutObject
An ACM certificate for the app domain in us-east-1edge stepRequestCertificate with DNS validation, tagged alphaagent:deployment; the job waits for it to issue and, if it does not, lists the validation CNAME records on the failure card
The Cognito SAML identity provider and client settingssaml stepcreate or update
ECS service redeployssettle stepUpdateService

Created in the Studio account by Studio itself, while it runs:

WhatByNaming
An EventBridge rule with an SQS target per workflow scheduleworkflow service<prefix><schedule id>
A Lambda function per execution environment, from the alphaagent-envs image, optionally inside the VPCagent-management servicealphaagent-env-<environment id>
Secret alphaagent/prompt-keyagent-runtime, on licence activationfixed name
A secret holding connector credentialsdata-connector servicefixed name from configuration
A secret per agent holding that agent's connector credentialscode-interpreter service<prefix><agent id>

Knowledge-graph training runs in the knowledge-base task's own disk and storage; it does not use SageMaker or Batch.

Outbound calls​

FromToWhy
Your workstation (running the Organisations installer)AWS APIs; telemetry.api.alphaagent.prometheusrl.comthe install; validating the Organisation credential
The Organisations VPC (through its endpoints or NAT)AWS APIs in your account; sts:AssumeRole into each Studio account; telemetry.api.alphaagent.prometheusrl.com; the time-limited S3 link the Console returnsrunning jobs; reading the Studio release catalogue and downloading release bundles
The Organisations console's APIMicrosoft Graph (your Entra ID tenant)creating each Studio's enterprise application and assigning users
Each Studio VPC (through its endpoints or NAT)AWS APIs; Amazon Bedrock through the bedrock-runtime VPC endpoint; telemetry.api.alphaagent.prometheusrl.comrunning Studio; model calls; licence activation, heartbeat and metering
Each Studio VPC at task start (through NAT)Docker Hub: neo4j:5.26-community and searxng/searxng:latestthe two containers that are pulled from a public registry rather than from your ECR
The web-browser-search service (through NAT)public search enginesweb search for agents
Operators' browsersfonts.googleapis.com, fonts.gstatic.comthe console's web fonts; optional, system fonts are used where blocked

What crosses to AlphaAgent and what does not is the subject of What leaves your account.

What is not present​

  • No customer-managed KMS keys: every bucket uses SSE-S3 (AES256), ECR repositories use AES256, ElastiCache has encryption at rest and in transit on, EFS is encrypted with AWS-managed keys. The target role's kms:* grant applies only through those services.
  • No CloudTrail trails, no AWS Config rules or recorders.
  • No Batch, no SageMaker, no Bedrock resources (Bedrock is reached only through the VPC endpoint and the task role's invoke actions).
  • No Route 53 records: every DNS record is yours to create.
  • No StackSets, no cross-account ECR repository policies, no IAM users or access keys (the target role and the Organisation's own role deny creating them).
  • No public S3 access: every bucket has all four public-access blocks on and no ACLs.
  • No permissions boundaries on any created role.
  • No common tag set: some resources carry a Name tag, the staging bucket carries alphaagent:managed-by and alphaagent:purpose, the us-east-1 certificate carries alphaagent:deployment; nothing else is tagged.

Limits​

  • The counts above are read from the templates of the current release; a later release may add or remove resources, and the page is re-verified from the templates named in its sources.
  • DeletionPolicy: Retain is set on data-bearing resources (71 in the Studio core template alone); deleting a deployment reports what it kept, and Clear account removes it. See Deleting a deployment and clearing an account.

If something goes wrong​

If a guardrail in your organisation denies one of these resource types or one of these outbound calls, the install stops with copy that names the denied action or the failed CloudFormation resource; every pattern is listed on SCPs and guardrails that block installs.