What the safety incident logger costs
A business reporting properly generates far more of these than one that is not, which is the point and also the only thing that scales the bill. Sixty reports a month across a few sites is a healthy reporting culture. Here is where each cent goes.
Key takeaways
- About $1 a month at 60 reports. Roughly $2 at 250 reports.
- One Bedrock read per report is the only line that scales. Everything else is rounding.
- Nothing is always-on, so a quiet month genuinely costs almost nothing.
- A rising bill here means a rising report count, which is the outcome the system is built to produce.
- The duplicate test runs before the read, so resends are free.
- The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.
The bill at three volumes
These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.
Line by line
| Line | At 60 reports | How it scales |
|---|---|---|
| Bedrock read | $0.13 | Linear. One call per report, roughly 1,800 in and 200 out tokens. |
| SES | $0.05 | Linear. About 2.6 messages per report. |
| DynamoDB + S3 | $0.29 | Storage grows with what you retain, not with throughput. |
| Lambda + SQS | $0.12 | Linear, and effectively free at this scale. |
| CloudWatch | $0.16 | Flat, if you set retention. Unbounded if you do not. |
| Secrets Manager | $0.40 | Flat. One secret, $0.40 a month. |
| AWS Budgets | $0.46 | Flat. Two actions, so you find out before the bill does. |
The read is one model call per report to propose a severity and pick out the equipment and activity. Reports that trip the injury or vehicle keywords route before that call and are cheaper still.
The three ways this bill surprises you
Every one of these has happened to somebody, and all three are cheap to prevent.
- Photos kept at full resolution forever. A yard photo is several megabytes and safety records are kept for years. Store a downscaled legible copy and expire the original at your actual retention horizon.
- SMS on every high-severity route. Correct, and worth capping: a keyword false positive that texts three people costs little, and a loop that does it repeatedly does not. A maximum receive count of three on the queue.
- Log retention left at never. Incident-adjacent logs are the ones you least want kept indefinitely, quite apart from the cost.
What it costs when nothing happens
This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.
- Management
- Analytics
- Front-end & mobile
Set these on day one
- A dead-letter queue on every SQS queue, with a maximum receive count of three.
- Thirty-day retention on every CloudWatch log group. There is no default that is safe.
- An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
- Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
- Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.
Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.
All posts