CloudLens
Build evidence · September 2026

How CloudLens was built.

CloudLens turns live AWS accounts into searchable architecture, dependency, change-risk, security, cost, and operational intelligence. This page documents the shipped system, the coding-agent connection to AWS, and the boundaries of each public claim.

● Live on AWSCommercial PotentialStartup laneAmazon BedrockWeb + Android
01 · LIVE PRODUCT

Try the application.

The public judge experience exposes the full CloudLens workflow with synthetic infrastructure data, so reviewers can explore the product without receiving customer credentials or access to a private AWS account. The authenticated product uses real tenant-scoped AWS discovery.

Reviewer-safe by designThe demo is intentionally synthetic. It demonstrates product capability without bypassing Cognito or disclosing tenant infrastructure. Real AWS inventory requires an authenticated tenant and a customer-owned read-only IAM role.
02 · ARCHITECTURE

Built and running on AWS.

CloudFront delivers the web application from a private S3 origin. Cognito authenticates tenants. API Gateway and Lambda enforce authorization and orchestrate discovery, analysis, billing, reports, and chat. DynamoDB stores tenant-scoped state. EventBridge schedules collection. Bedrock generates grounded explanations. STS assumes customer-owned read-only roles with a unique External ID.

ExperienceCloudFront, S3, custom domain, React web, React Native Android
IdentityAmazon Cognito, tenant membership, roles, invitations, MFA challenges
ApplicationAPI Gateway, Lambda, DynamoDB, EventBridge, CloudWatch
IntelligenceAmazon Bedrock, Knowledge Bases, Cost Explorer, account evidence
USER → COGNITO → CLOUDFRONT / API GATEWAY → LAMBDA → AWS DATA + BEDROCK

Customer accounts remain under customer control. CloudLens receives short-lived STS credentials and performs read-only collection. Users never paste long-lived AWS access keys into the product.

03 · CONNECTION PROOF

Built on AWS with a coding agent.

The coding agent participated in the real AWS delivery loop—not only local code generation. It synthesized CDK, prepared and pushed changes, monitored GitHub Actions, inspected deployment failures, helped diagnose IAM and CloudFormation behavior, verified Cognito and Bedrock, and browser-tested the deployed application.

Redacted evidence board showing the coding agent, GitHub Actions OIDC, AWS IAM deployment role, CDK deployment, and live CloudLens verification
Reviewer-safe evidence board. Account identifiers, tokens, role ARNs, request IDs, certificate identifiers, and secrets are omitted.
01 · AGENT

Implementation and diagnosis

Built features, ran tests, investigated CloudFormation replacement constraints, IAM failures, Cognito sessions, Bedrock access, and production behavior.

02 · GITHUB OIDC

Short-lived deployment credentials

GitHub Actions requested temporary AWS credentials through OIDC; no long-lived AWS access key is published or required.

03 · AWS IAM + CDK

Dedicated deployment boundary

The workflow assumed the dedicated CloudLens deployment role, synthesized CDK, and updated the CloudFormation stack.

04 · LIVE VERIFICATION

Tests after deployment

The workflow ran smoke checks and production browser tests against the public custom-domain application.

Dated deployment recordThe public judge-demo deployment completed through GitHub Actions on September 22, 2026. The expanded showcase deployment completed on September 23. The published evidence record reports 84 passing tests, a successful CDK deployment, an AWS-mode smoke test, and production Playwright checks.
04 · CLAIMS AND LIMITS

Implementation and evidence.

This table distinguishes shipped capability from proof and explicitly records important limits. It is intended to help reviewers audit the project without relying on promotional claims.

ClaimWhat supports itLimits
Live AWS applicationPublic custom domain, CloudFront delivery, deployment smoke checks, and production Playwright tests.Availability can change after a dated observation; reviewers should test the live URL.
Cross-account discoveryCustomer-owned IAM role template, External ID flow, STS validation, and authenticated discovery results.The public demo does not assume a real customer role and uses synthetic resources.
Evidence-grounded AIBedrock analysis and copilot consume bounded topology, relationship, telemetry, cost, security, and change context while retaining resource references.Recommendations are advisory and require human review; CloudLens does not execute remediation.
Coding-agent AWS connectionRedacted connection board, public evidence narrative, sanitized GitHub Actions OIDC workflow, CDK records, and live verification steps.Secrets and tenant identifiers are deliberately excluded. AWS judges decide whether evidence satisfies event requirements.
Multi-tenant SaaS controlsCognito authentication, tenant-scoped records, server-side account grants, role checks, invitations, limits, billing lifecycle, and audit controls.The product is an early paid-pilot MVP, not a certified compliance platform.
05 · ANDROID COMPANION

CloudLens goes mobile.

The React Native Android companion uses the same tenant-scoped CloudLens APIs and authentication lifecycle. It brings live inventory, architecture, costs, alerts, the Bedrock copilot, and commercial plan controls to a phone-sized experience.

CloudLens mobile application showing sign-in, AWS operational overview, costs, service footprint, and architecture copilot
Presentation composite derived from the implemented React Native interface and CloudLens design system.
06 · ZERO TO SHIPPED

Submission status.

SHIP GATELive and publicly reachableCustom-domain application and judge demo are deployed on AWS.
BUILDER CENTERProject publishedCategory: Commercial Potential · Lane: Startup.
PUBLIC EVIDENCEReviewer-safe pack availableArchitecture, development story, security model, role template, deployment workflow, and agent proof are public.
FINAL EVENT CHECKVerify submission associationA published project does not by itself prove final event submission. Confirm the event entry and required tags in Builder Center.
07 · AWS CONSOLE PROOF

The deployed architecture, observed in AWS.

These direct AWS Console captures document the deployed CloudLens environment: completed CloudFormation stacks, the live stack's 84 managed resources, and the generated Infrastructure Composer graph. They were captured on September 26, 2026 from the authenticated deployment account.

AWS CloudFormation console showing the completed CloudLens application, customer read-only role, and CDK toolkit stacks
CloudFormation stack inventory. The CloudLens application stack is in UPDATE_COMPLETE; the customer read-only access stack and CDK bootstrap stack are also complete.
AWS CloudFormation Resources tab showing the CloudLens stack with 84 managed resources
The deployed CloudLens-dev stack reports 84 resources, including encrypted data, knowledge-source, vector-search, API, identity, and automation components.
AWS Infrastructure Composer overview generated from the deployed CloudLens CloudFormation template
AWS Infrastructure Composer overview generated from the deployed template. The full graph is intentionally shown at fit-to-canvas scale to document the breadth and relationships of the infrastructure definition.
Privacy-safe captureThe AWS identity and account header was cropped from every published image. Physical resource identifiers, ARNs, credentials, tokens, customer inventory, and secrets are not exposed. These are captures of the real deployed stack—not synthetic judge-demo data.
08 · BEDROCK RESOURCES

Grounded intelligence, deployed in Amazon Bedrock.

CloudLens uses Amazon Bedrock for evidence-grounded architecture analysis and its account-aware copilot. These AWS Console captures document the deployed retrieval and safety resources, plus the serverless model selected for cost-conscious inference.

Amazon Bedrock console showing two available CloudLens Knowledge Bases
The Bedrock resource inventory shows two available CloudLens Knowledge Bases. The current CloudLens_dev_v2 vector-store Knowledge Base has one attached data source and no recorded sync warnings.
Amazon Bedrock CloudLens knowledge data source showing available status and S3 source
The active CloudLens_dev_evidence data source is backed by Amazon S3, reports Available, and uses fixed-size chunking for bounded retrieval.
Amazon Bedrock Guardrails console showing the ready CloudLens safety guardrail
The deployed CloudLens Guardrail is Ready and is described in AWS as protecting evidence-grounded analysis from unsafe content and credential disclosure.
Amazon Bedrock model catalog filtered to the Amazon Nova Lite serverless model
The Bedrock model catalog filtered to Amazon Nova Lite, the cost-conscious serverless model used by CloudLens for architecture analysis and recommendations.
What this provesThe screenshots show deployed Bedrock retrieval and safety resources in the production AWS account. They do not expose prompts, customer architecture documents, generated answers, Knowledge Base identifiers, role ARNs, or credentials.