Well-Architected posture for multi-account AWS

Everything Trusted Advisor tells you. Without the support plan.

StationChief scores your whole AWS organisation against the Well-Architected Framework from free APIs, and hands you a ranked list with the fix identified on every item.

638
Checks in the catalogue
627
Collected, no support plan
4
Ungated AWS sources
117
Rules of our own
Compliance profiles the baseline layers on
CIS · NIST 800-53 r5 · FedRAMP Moderate · FedRAMP High · CMMC L2 · PCI DSS 4
The scorecard
STATIONCHIEF Scorecard › Acme Corp · 14 accounts Scanned 2h ago
Well-Architected
74

Unweighted mean across five pillars. Sustainability is out of scope rather than extrapolated. Coverage is shown on every row — a score without its denominator hides a shallow pillar.

Pillar
Score
Cov.
Security
78
96%
Cost Optimization
64
93%
Reliability
81
74%
Performance Efficiency
88
61%
Operational Excellence
59
42%
Evidence · 4 ungated AWS sources + StationChief rules
Security Hub Service Quotas Compute Optimizer Cost Optimization Hub StationChief rules 627/638 checks

Operational Excellence scores 59 over 42% coverage — and says so. A number without its denominator isn’t a score.

Why StationChief

A number you can check is worth more than one you can’t.

01

See everything

4 ungated AWS sources and 117 rules of our own reach 627 of the 638 Trusted Advisor checks. No support plan, no per-account upgrade, no agent to install.

02

Ranked, with the fix

Every finding names its remediation. The ranked list stays filled and re-orders daily as findings arrive and age — so the top of it is correct without anyone maintaining it.

03

Published, not proprietary

The category sells a score and calls the arithmetic behind it a trade secret. Ours is documented — how each source becomes a pillar number, what is excluded from the denominator, and why. You can reproduce it, and dispute it.

How it works

One stack. Then it runs itself.

The active list
STATIONCHIEF Queue · profile: balanced Re-ranked 04:00 UTC
  • 01
    Cost 41d open
    Three idle RDS instances in prod-data, running 41 days
    $1,840/mo
    Agent · running
  • 02
    Security 6d open
    Root account has no MFA in two member accounts
    Critical
    Ready
  • 03
    Cost 12d open
    Savings Plan coverage at 34% against a stable 12-month baseline
    $6,200/mo
    Ready
  • 04
    Reliability 3d open
    Lambda concurrency quota at 91% headroom breach in us-east-1
    High
    Ready
  • 05
    Security 88d open
    CloudTrail not enabled in ap-southeast-2 for four accounts
    High
    Closed via API
10 active · refilled daily from 1,284 open findings Ordered by severity, dollars, and age

Nobody promoted these items. The list ordered itself, and closes itself.

  1. 01
    Connect

    One stack, in the management account, once.

    A single CloudFormation template creates a read-only audit role in every member account by service-managed StackSet with auto-deployment, and in the management account directly. The role name is fixed, so every account’s role ARN is derived — nothing is registered per account, and an account created later is covered on placement and scanned on the next run.

  2. 02
    Collect

    Free APIs, on a schedule you do not maintain.

    We read 4 ungated AWS sources — Security Hub, Service Quotas, Compute Optimizer, and Cost Optimization Hub — and run 117 rules of our own against the control plane. Together that reaches 627 of the 638 Trusted Advisor checks with no support plan involved. Schedules live in Postgres and are reconciled on every worker boot, so a cache flush cannot silently stop your scans.

  3. 03
    Rank

    The list orders itself.

    Findings become recommendations, and recommendations become a ranked list that stays at least ten items deep. Severity, dollars and age all feed the ordering, and an organisation-level profile decides which wins when savings and risk disagree. A daily pass re-ranks as findings arrive and age, so the top of the list is current without anyone maintaining it.

  4. 04
    Act

    Worked by your people, or by your agents.

    Every item names its remediation. Work it by hand, or let agents you run yourself work it — completion is an API call, so an agent closes its own items and the queue reflects what actually happened rather than who remembered to tick a box.

Cost

Spend, at the grain you actually ask about.

How cost reporting works

CUR 2.0 normalised into Parquet across every account. Daily rollups serve the dashboards; Athena answers the questions a dashboard can’t. Current-month figures are labelled provisional, because the Cost and Usage Report restates — and a number that quietly moves under you is worse than no number.

CUR 2.0
Ingested

Backfilled from onboarding

Daily
Rollup grain

Account × service

Athena
Resource detail

Unit economics

Access

We don’t ask for ReadOnlyAccess.

What we can and can’t see

It’s the policy most tools request, and it grants s3:GetObject and friends — your actual data. The StationChief audit role is SecurityAudit plus ViewOnlyAccess, with an explicit Deny on data-plane reads. We have no business reading your files, and we ask for no permission to. The template that creates the role is published, and it is verbatim what the StackSet delivers.

Tenant-isolated by RLS No data-plane reads US-hosted No model training You set retention SSO / SAML SCIM Signed access logs

Connect an account and see your score.

One CloudFormation stack, a read-only role, and your first scan runs on the spot.

No demo required. No sales call. The pricing is on the pricing page.