What did the agent do in your AWS account?
Every AWS call an AI coding agent makes, from CloudTrail: grouped into sessions, split from what people did, checked against risk rules, and turned into the permissions it actually needed.
Every session below is real, recorded by CloudTrail: Claude Code building Chaperone through the AWS MCP Server, and the person working beside it. Identifiers are masked, so the account shows as 111122223333, AWS's documentation placeholder.
Judging this entry? Start with the judges' guideThe agent asks Chaperone about its own work
Claude Code created and deleted a queue through the AWS MCP Server, then asked Chaperone "was anything I did risky?" The answer comes from CloudTrail, which the agent didn't write and can't edit: one destructive call, on a queue the same session created.
risky_calls("me") →
{
"risky": {
"destructive": {
"calls": [{
"time": "2026-09-27T22:30:13Z",
"action": "sqs:DeleteQueue",
"target": "https://sqs.us-east-1.amazonaws.com/111122223333/chaperone-demo-queue",
"via": "mcp",
"tool": "aws___run_script",
"reasons": ["sqs:DeleteQueue removes or stops a resource"],
"on_resource_created_this_session": true
}]
}
},
"summary": { "destructive": 1 }
}Sessions recorded
23
14 by an AI agent
AWS calls
8,668
6,999 by the agent
Risky calls
23
destructive, identity, public or audit
Riskiest agent session
Identity escalation
iam:PutRolePolicy grants or assumes more access
Sessions
- chaperone-agentAI agent · Identity Center · ChaperoneAgent181 AWS callsAgent read across 12 AWS services and invalidated one CloudFront distribution cache.WriteFri 2 Oct, 12:52 UTC
11 min - rootPerson · role root163 AWS callsRoot user spent six minutes reading billing, cost, and account data across 22 services.ReadWed 30 Sept, 22:30 UTC
7 min - chaperone-agentAI agent · Identity Center · ChaperoneAgent5 AWS callsAgent submitted one CloudFront cache invalidation against an existing distribution.WriteMon 28 Sept, 20:38 UTC
26s - chaperone-agentAI agent · Identity Center · ChaperoneAgent211 AWS callsAgent deployed updates to three Lambda functions and a CloudFront cache policy over about three minutes.WriteMon 28 Sept, 19:43 UTC
3 min - chaperone-agentAI agent · Identity Center · ChaperoneAgent231 AWS calls · 8 MCP tool callsAgent deployed updated Lambda functions and wrote DynamoDB records over 19 minutes.WriteMon 28 Sept, 17:04 UTC
19 min - chaperone-agentAI agent · Identity Center · ChaperoneAgent18 AWS calls · 3 MCP tool callsAgent authenticated via SSO, invalidated a CloudFront distribution, and created then deleted a test SQS queue.DestructiveSun 27 Sept, 21:43 UTC
1 h 12 min - adminPerson · IAM user883 AWS callsAdmin browsed AWS account and submitted a Bedrock model-access use-case form.WriteSun 27 Sept, 21:24 UTC
16 min - chaperone-agentAI agent · Identity Center · ChaperoneAgent4 AWS callsAgent obtained an SSO token after three authorization-pending retries.WriteSun 27 Sept, 12:52 UTC
3s - adminPerson · IAM user61 AWS callsAdmin updated the AWS IAM Identity Center SSO configuration during a five-minute session.WriteSun 27 Sept, 12:49 UTC
5 min - adminPerson · IAM user38 AWS callsAdmin ran a 19-minute read-only survey of account health and cost data.ReadSun 27 Sept, 01:51 UTC
19 min - chaperone-agentAI agent · Identity Center · ChaperoneAgent767 AWS calls · 12 MCP tool callsAgent updated Chaperone Lambda functions and inline IAM policy, then invalidated a CloudFront distribution twice.Identity escalationSun 27 Sept, 01:25 UTC
2 h 40 min - chaperone-agentAI agent · Identity Center · ChaperoneAgent354 AWS calls · 1 MCP tool callsAgent performed a 12-minute read-only survey of infrastructure across 12 AWS services.ReadSat 26 Sept, 14:03 UTC
12 min - chaperone-agentAI agent · Identity Center · ChaperoneAgent747 AWS callsAgent deployed updates to Chaperone's CloudFront distribution and three Lambda functions via Terraform and CLI.WriteSat 26 Sept, 12:11 UTC
1 h 0 min - chaperone-agentAI agent · Identity Center · ChaperoneAgentStart here3,365 AWS calls · 27 MCP tool callsAgent updated Chaperone infrastructure and added a new API Lambda with IAM roles over 76 minutes.Identity escalationFri 25 Sept, 18:28 UTC
1 h 16 min - chaperone-agentAI agent · Identity Center · ChaperoneAgent216 AWS calls · 2 MCP tool callsAgent deployed Chaperone forwarder infrastructure across 16 regions and modified an existing CloudTrail trail.Identity escalationFri 25 Sept, 15:49 UTC
2 min - adminPerson · IAM user134 AWS callsAdmin signed in to the console and spent 30 seconds reading billing and account data.WriteFri 25 Sept, 14:40 UTC
27s - chaperone-agentAI agent · Identity Center · ChaperoneAgent865 AWS calls · 5 MCP tool callsAgent deployed Chaperone ingest pipeline and then verified its own infrastructure over 44 minutes.Identity escalationFri 25 Sept, 14:07 UTC
44 min - adminPerson · IAM user11 AWS callsAdmin read-only session querying account status across six AWS servicesReadFri 25 Sept, 13:51 UTC
1s - adminPerson · IAM user1 AWS callsAdmin made a single CloudTrail read call and nothing else.ReadFri 25 Sept, 03:19 UTC
0s - chaperone-agentAI agent · Identity Center · ChaperoneAgent11 AWS calls · 5 MCP tool callsAgent ran a short-lived EventBridge-to-SQS probe, then cleaned up all resources it created.DestructiveFri 25 Sept, 03:13 UTC
5 min - adminPerson · IAM user16 AWS callsA 13-second read-only survey of account configuration across seven servicesReadFri 25 Sept, 02:28 UTC
13s - chaperone-agentAI agent · Identity Center · ChaperoneAgent24 AWS calls · 10 MCP tool callsAgent built an S3-backed CloudFront distribution and requested a TLS certificate over 46 minutes.WriteFri 25 Sept, 01:46 UTC
46 min - adminPerson · IAM user362 AWS callsAdmin bootstrapped CloudTrail, AWS Organizations, and IAM Identity Center in a single 52-minute console session.Audit tamperingFri 25 Sept, 01:01 UTC
52 min