Skip to content

Part 6 of 7 · Access review reporter series ~5 min read

What the access review reporter costs

This polls a handful of APIs once a week and does a join. Forty collections is about ten services checked weekly. It is one of the cheapest systems in the series and one of the few whose value is measured in things that did not happen. Here is where each cent goes.

Key takeaways

  • About $1 a month at 12 services weekly. Roughly $2 at 40 services weekly.
  • One Bedrock read per collection is the only line that scales. Everything else is rounding.
  • Nothing is always-on, so a quiet month genuinely costs almost nothing.
  • No model, and the APIs are free. Storage grows with retained snapshots, which is the only line that moves.
  • The duplicate test runs before the read, so resends are free.
  • The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.

The bill at three volumes

These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.

Monthly cost of the access review reporter at three volumesA stacked bar chart with three bars, one per volume tier: 40 collections totalling about $1, 12 services weekly totalling about $1, and 40 services weekly totalling about $2. Each bar is stacked from bands. The largest and fastest-growing is Bedrock, one read per collection, in teal. Then SES for the messages, in pink. Then S3 and DynamoDB storage in green. Then a fixed orange band for Secrets Manager and AWS Budgets, which is eighty-six cents at every volume. Then a grey band for Lambda, SQS and CloudWatch. A note says the read is the only bar that grows with the business and the orange band never moves.$0$1$2$3$4~$1.340 collections~$1.4312 services weekly~$1.8640 services weeklyBedrock — one read per collectionSES — asks, results, receiptsS3 + DynamoDBFixed — Secrets Manager, BudgetsLambda, SQS, CloudWatchThe read is the only bar that grows with the business. The orange fixed band never moves.
Fig 1. The monthly bill at three volumes. The teal band — one model read per collection — is the only part that grows; the orange fixed band is the same 86 cents at every volume.

Line by line

LineAt 12 services weeklyHow it scales
Bedrock read$0.00Linear. One call per collection, roughly 1,800 in and 200 out tokens.
SES$0.07Linear. About 0.6 messages per collection.
DynamoDB + S3$0.30Storage grows with what you retain, not with throughput.
Lambda + SQS$0.12Linear, and effectively free at this scale.
CloudWatch$0.16Flat, if you set retention. Unbounded if you do not.
Secrets Manager$0.40Flat. One secret, $0.40 a month.
AWS Budgets$0.46Flat. Two actions, so you find out before the bill does.

There is no read line: nothing here calls a model. The variable cost is a handful of API calls and the storage of weekly snapshots.

The three ways this bill surprises you

Every one of these has happened to somebody, and all three are cheap to prevent.

  • Storing a full snapshot per service per week forever. Small, but it compounds, and snapshots older than about two years answer no question anybody asks. Expire them deliberately.
  • Polling on a schedule that hits rate limits. Several SaaS user APIs are aggressively rate limited. Collect services sequentially with a delay rather than in parallel; there is no hurry.
  • Log retention left at never. With a bill this small, unbounded logs will be the whole of it within months.

What it costs when nothing happens

This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.

The monthly bill at four volumes plus one failure modeA horizontal row of five boxes. Quiet month, about one dollar. 40 collections, about $1. 12 services weekly, about $1. 40 services weekly, about $2. And one bad retry loop, about two hundred dollars. A note says four of these are the design working and the fifth is a missing dead-letter queue.THE BILL, AT A GLANCEQuiet month~$140 collections~$112 services weekly~$140 services weekly~$2One bad loop~$200Four of these are the design working. The fifth is a missing dead-letter queue.
Fig 2. The bill at a glance, including the one that is not a volume at all. A retry loop with no dead-letter queue costs more than every legitimate use of the system put together.
  • Management
  • Analytics
  • Front-end & mobile

Set these on day one

  • A dead-letter queue on every SQS queue, with a maximum receive count of three.
  • Thirty-day retention on every CloudWatch log group. There is no default that is safe.
  • An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
  • Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
  • Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.

Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.

All posts