OrchestrAI Live

AWS · Cloud service

AWS Systems Manager with OrchestrAI

Catalog exported 2026-09-02

Configure AWS Systems Manager from chat: documents, associations, maintenance windows, and patch baselines.

OrchestrAI exposes 4 Systems Manager operations: 2 are low-risk (read-only or low-impact), and 2 create or modify resources and run only after you confirm the plan.

4operations
2low risk
2create or modify
0destructive
0step-level approval

What teams use it for

Operations teams use OrchestrAI to write an SSM document as a runbook, create a State Manager association that applies it to tagged instances, set a maintenance window for patching, and define a patch baseline that approves security patches after a set number of days. Document and patch baseline creation are low risk; associations and maintenance windows are medium risk. Run Command, Parameter Store, Session Manager, and registering tasks or targets with a maintenance window are not covered, so executing a runbook on demand happens in the console.

Every Systems Manager operation, with its risk level

AWS Systems Manager operations available through OrchestrAI
Operation What it does Risk Step-level approval
Create SSM Document Create an SSM document (runbook) for automation and configuration management Low risk No
Create SSM Patch Baseline Create an SSM patch baseline for OS patching policies Low risk No
Create SSM Association Create an SSM State Manager association for automated configuration Creates resources No
Create SSM Maintenance Window Create an SSM maintenance window for scheduled patching and tasks Creates resources No

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • Create an SSM document called restart-nginx that runs systemctl restart nginx
  • Create a maintenance window every Sunday at 03:00 UTC for 2 hours named prod-patching
  • Create a patch baseline for Amazon Linux 2023 that approves critical security patches after 3 days

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI run a command on EC2 instances through Systems Manager?
No, Run Command is not covered. It can create documents and associations, which apply configuration on a schedule, but on-demand execution is done in the console.
Does OrchestrAI manage Parameter Store values?
Not currently; Systems Manager coverage is limited to documents, associations, maintenance windows, and patch baselines.
Which Systems Manager operations need an extra approval step?
None of the Systems Manager operations currently carries a step-level approval gate; they are read-only or run after plan confirmation like any other change.

Other AWS services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.