What the consent preference keeper costs
The resolver is asked constantly and the answer is cached, which makes this cheap at almost any volume. Fifty thousand resolutions a month is a business sending a few campaigns and a lot of transactional mail. Here is where each cent goes.
Key takeaways
- About $2 a month at 200k resolutions. Roughly $3 at 1M resolutions.
- One Bedrock read per thousand resolutions is the only line that scales. Everything else is rounding.
- Nothing is always-on, so a quiet month genuinely costs almost nothing.
- Cache invalidation on write rather than a short TTL is what keeps a million resolutions a month affordable.
- The duplicate test runs before the read, so resends are free.
- The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.
The bill at three volumes
These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.
Line by line
| Line | At 200k resolutions | How it scales |
|---|---|---|
| Bedrock read | $0.00 | Linear. One call per thousand resolutions, roughly 1,800 in and 200 out tokens. |
| SES | $0.10 | Linear. About 0.05 messages per thousand resolutions. |
| DynamoDB + S3 | $0.31 | Storage grows with what you retain, not with throughput. |
| Lambda + SQS | $0.12 | Linear, and effectively free at this scale. |
| CloudWatch | $0.16 | Flat, if you set retention. Unbounded if you do not. |
| Secrets Manager | $0.40 | Flat. One secret, $0.40 a month. |
| AWS Budgets | $0.46 | Flat. Two actions, so you find out before the bill does. |
There is no model and no third-party API. The cost is DynamoDB reads on cache misses plus Lambda duration, both of which are tiny per resolution.
The three ways this bill surprises you
Every one of these has happened to somebody, and all three are cheap to prevent.
- A short cache TTL instead of invalidation. A five-minute TTL at a million resolutions a month means most queries hit the table, which multiplies the read cost and still gives a worse withdrawal latency than invalidation.
- Per-person resolution during a campaign. Twelve thousand individual calls where one bulk call would do. Build the bulk endpoint before the first campaign, not after.
- Log retention left at never. A resolver logging every query at a million a month is by a wide margin the largest line on this bill.
What it costs when nothing happens
This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.
- Management
- Analytics
- Front-end & mobile
Set these on day one
- A dead-letter queue on every SQS queue, with a maximum receive count of three.
- Thirty-day retention on every CloudWatch log group. There is no default that is safe.
- An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
- Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
- Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.
Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.
All posts