Exam Room · Cloud Practitioner

A Question Nobody on the Team Could Answer

· 34 min read

Cloud Fundamentals · part of The Exam Room

The situation

A company in Adelaide sells rostering software to aged-care providers. Eleven people, four of them engineers, one AWS account, and a little under AUD$9,000 a month of AWS spend. The account has been on Basic Support since the day it was opened, because nobody ever chose otherwise.

On a Wednesday afternoon, the integration that pushes shift confirmations into a customer’s payroll system starts failing. The errors say the request rate has been exceeded. Two engineers spend three hours on it. They cannot tell whether the limit belongs to them, whether it can be raised, or whether anything is wrong at the AWS end at all. Halfway through the afternoon somebody says the thing out loud: we do not know who to ask.

Five more questions land over the following month. The finance officer finds a charge on the invoice that nobody recognises. An engineer needs the account’s EC2 vCPU quota raised in ap-southeast-4 before a customer goes live in November. A hospital group’s procurement team wants log retention and alerting evidence for a security questionnaire, and building that in-house would take a quarter the team does not have. The same customer wants an on-premises SQL Server database migrated into the platform by March, and nobody here has done a migration. And underneath all of it, a quieter one: when somebody asks what AWS actually recommends, where is that written down?

What actually matters

These look like one problem and are not. Sorting them by who holds the answer does most of the work. AWS answers questions about your own account, such as an invoice line or a quota. AWS answers questions about how a service behaves, but only for customers on a plan that carries technical cases. A software vendor answers questions about their product. A consulting firm answers questions by doing the work. And a large share of what small teams ask has already been written down and published, at no charge, before anyone asks it. Picking the wrong route usually produces no answer at all, three weeks later.

The second thing to settle is what the current plan reaches. Basic Support includes account and billing cases and service quota increases, for every customer, at no extra charge. Technical cases are not included. So one of the six questions above cannot be raised with AWS today, and two of them can. That line matters most when it is discovered during an outage rather than before one, because changing plans in the middle of an incident adds an administrative step to an afternoon that already has enough of them.

Third, response speed is chosen rather than granted. Severity is a field on the case, set when the case is created, and it selects the first-response target that AWS works to. A team that files everything at the lowest severity gets the slowest target and then concludes support is slow. A team that files everything at the highest one has no signal left for the real emergency. Worth separating in the same breath: a first-response target is about when a human replies, not when the problem is fixed.

Finally, two of these questions need something other than an answer. Compliance tooling and a database migration both need capability the team does not have, and they arrive in different shapes. One is software somebody else wrote, which the team subscribes to and then runs. The other is people who do the work and then leave. How each appears in the finances differs too: third-party software bought through AWS Marketplace is charged to the AWS account and lands on the AWS invoice, while a consulting engagement is normally a contract with that firm.

What we’ll filter on

  1. Who holds the answer: AWS about your account, AWS about a service, a vendor about their product, or a partner with hands on your project.
  2. Whether Basic Support reaches it, or a paid plan is required first.
  3. Whether a first-response target applies, and whether you select it.
  4. Who runs the result afterwards: AWS, you, or somebody else.
  5. Whether the charge appears on the AWS invoice or as a separate contract.

The landscape

AWS Support Center is the console where cases are created, tracked, resolved and reopened. It sits at the question-mark icon in the AWS Management Console. Three case types are offered, and the type is the first choice made:

  • Account and billing, available to all AWS customers, for invoices, charges, account access and similar.
  • Service limit increase, also available to all AWS customers, which is how service quota increases are requested. AWS still labels the case type with the older word.
  • Technical, which connects you to technical support for a service-related problem. On Basic Support you cannot create a technical case.

After the type comes the service, then a category within that service, then the severity, then the description. Severity is the field that selects the first-response target AWS works to: General guidance at 24 hours, System impaired at 12 hours, Production system impaired at 4 hours, Production system down at 1 hour, and Business-critical system down at under 30 minutes on AWS Business Support+, under 15 minutes on AWS Enterprise Support, and 5 minutes from an Incident Management Engineer on AWS Unified Operations. Those severities are available on the paid plans. A case opens as Unassigned, becomes Work in Progress, and moves between Pending Customer Action and Pending Amazon Action as the correspondence goes back and forth. On a paid plan the severity can be reassigned mid-case; on Basic it cannot be changed after creation. A resolved case can be reopened for 14 days, after which the route is a related case that links back to the old one, and case history is viewable for 24 months.

IAM users have no access to Support Center by default. The AWSSupportAccess managed policy grants it, and anyone with that access can see every case on the account.

The AWS Support API does the same job programmatically: CreateCase, DescribeCases, AddCommunicationToCase, ResolveCase, plus operations that read and refresh Trusted Advisor checks. It requires Business Support+, Enterprise Support or Unified Operations. Calling it from an account without one returns SubscriptionRequiredException.

The support plans themselves are Basic, AWS Business Support+, AWS Enterprise Support and AWS Unified Operations. Developer Support, Business Support and Enterprise On-Ramp are all discontinued on 1 January 2027 and remain only in the AWS GovCloud (US) Region, so none of them is a choice for a company deciding now. Business Support+ starts at USD$29 a month minimum per account and brings 24/7 phone, web and chat access to Cloud Support Engineers, more than 500 Trusted Advisor checks, and the Support API. Enterprise Support adds a designated Technical Account Manager, a 15-minute production-critical response, AWS Security Incident Response at no additional cost, and strategic business reviews.

What AWS has already published splits into four places, each answering a different shape of question. Documentation at docs.aws.amazon.com describes how a service behaves, including its quotas and which of them can be raised. Whitepapers and guides at aws.amazon.com/whitepapers carry the longer-form material, the Well-Architected Framework among it, and answer what AWS recommends in general rather than what a setting does. The AWS blogs at aws.amazon.com/blogs are organised by team, including News, Architecture, Security and AWS Marketplace, and are where changes are announced and walkthroughs published. AWS Prescriptive Guidance collects patterns, strategies and playbooks written by AWS teams for recurring situations, migrations among them.

AWS re:Post at repost.aws is the free community question-and-answer service that replaced the old AWS Forums, and since 2023 it also hosts the AWS Knowledge Center articles, which are written by an AWS team and carry an AWS Official badge. It needs no support plan. AWS re:Post Private is a separate, organisation-specific version for Enterprise Support and Enterprise On-Ramp customers, and AWS ends support for it on 30 June 2027.

The AWS Partner Network is the global community of organisations that build on AWS, and firms enrol through one of five Partner Paths: Software, Hardware, Services, Training and Distribution. The distinction worth holding is between the first two kinds of partner a customer meets. An independent software vendor joins the Software Path: they write software that runs on or integrates with AWS, and they sell it, usually listed in AWS Marketplace. A system integrator joins the Services Path, alongside consulting firms, managed service providers and resellers: they design, build and often operate the thing for you. Partners get training and certification, AWS Partner Central for managing their membership, partner events and webinars, marketing resources, incentive programmes, and a route to sell through Marketplace. AWS Professional Services is the AWS-badged version of the same consulting work, delivered by AWS rather than by a partner.

AWS Marketplace is a curated digital catalogue of third-party software, data and services, with pricing that runs from free trials through hourly, monthly, annual and multi-year terms to bring-your-own-licence. AWS handles the billing, and the charges appear on your AWS bill. Four things it does beyond listing products:

  • Private offers: a seller negotiates pricing and EULA terms with you privately and extends the offer to accounts you designate, up to 25 of them. Accept it from an organisation’s management account and the terms can be shared with member accounts.
  • Governance and entitlements: Managed Entitlements distributes, activates and tracks licence entitlements through AWS License Manager, so a licence bought once is granted to the accounts that need it.
  • Procurement control: Private Marketplace lets an administrator publish a curated catalogue of approved products for the whole organisation, for named organisational units, or for individual accounts, and blocks new subscriptions to anything outside it. It is administered from the management account or a delegated administrator account.
  • Procurement insight and cost management: a procurement insights dashboard in the Marketplace console reports spend and agreements, and because the charges land on the AWS bill they are visible to Cost Explorer, AWS Budgets and cost allocation tags like any other line. Integrations exist for Coupa and SAP Ariba.

Evaluation

Side by side

Route Who holds the answer Reachable on Basic Response target you select Who does the work after On the AWS invoice
Support case, account and billing AWS, about your account AWS n/a
Support case, service limit increase AWS, about your quotas AWS n/a
Support case, technical AWS, about a service You, with guidance n/a
AWS Support API As a technical case, automated Your automation n/a
Documentation, whitepapers, blogs, Prescriptive Guidance AWS, written in advance n/a You n/a
re:Post and the Knowledge Center The community, plus AWS-badged articles You n/a
AWS Marketplace, ISV software A vendor, about their product n/a You run it
A system integrator from the Services Path A partner, about your project n/a They build it
AWS Professional Services AWS’s own consultants n/a They build it

Which question takes which route

Question Route
A charge on the invoice nobody recognises Support case, account and billing, on Basic today
Raise the vCPU quota before the November go-live Support case, service limit increase, on Basic today
Why is the payroll integration being throttled Technical case, which needs Business Support+ or above
What does AWS recommend for this in general Whitepapers and Prescriptive Guidance
Has anyone hit this exact error before re:Post and the Knowledge Center
Log retention and alerting for the questionnaire AWS Marketplace, an ISV product on the AWS bill
Migrate the SQL Server database by March A system integrator, or AWS Professional Services

Nothing in the first table answers more than one row of the second, and one route is closed to this account until the plan changes.

The solution

Start with the two cases Basic already reaches, because they need no decision from anyone. In Support Center, open an account and billing case for the unrecognised charge, choose the billing category, attach the invoice month, and describe the line as it appears. Open a service limit increase case for the vCPU quota, naming ap-southeast-4, the instance family and the target value, with the go-live date in the description. Neither case costs anything on Basic and neither needs a plan change.

Then settle the plan, before the next incident rather than during one. The throttling problem is a technical case and Basic does not carry technical cases. Business Support+ starts at USD$29 a month minimum per account, and brings technical cases at every severity, 24/7 access to Cloud Support Engineers, more than 500 Trusted Advisor checks and the Support API. For a company with paying customers on the platform, an unanswerable production problem makes the case for the upgrade. Set expectations along with it: a case at Production system down has a one-hour first-response target, one at Business-critical system down under 30 minutes on that plan, and a first response is a human reading your case rather than a resolution.

While that is being arranged, the free material answers more of the throttling question than the team expects. The service’s documentation page lists its quotas and says which are adjustable. Prescriptive Guidance has patterns for the shape of the problem. The blogs say whether anything changed recently. re:Post is where to ask, and the Knowledge Center article may already exist, with the AWS Official badge on it. That sequence, documentation for behaviour, guidance for a pattern, blogs for recency, re:Post to ask, takes an hour and closes a good share of questions at this level.

For the compliance tooling, use AWS Marketplace rather than building. Subscribe to the ISV product, and the charge arrives on the AWS invoice where Cost Explorer, Budgets and the cost allocation tags can see it. If the vendor’s list pricing does not suit an eleven-person company, ask for a private offer: negotiated pricing and EULA terms, extended to the account you nominate. If the team later runs several accounts, Private Marketplace restricts what anyone can subscribe to, and Managed Entitlements grants the licence to the accounts that need it through AWS License Manager.

The SQL Server migration goes to a partner, and the path they enrolled in tells you which kind. A system integrator on the Services Path builds and runs the migration; the contract is with that firm, not with AWS. An ISV on the Software Path would instead sell the team a migration product to run themselves, which is a different offer to a team with no migration experience. AWS Professional Services covers the same ground with AWS’s own consultants.

Two details worth settling this week. Give the on-call engineers the AWSSupportAccess policy now, since IAM users cannot reach Support Center without it and an outage is a poor time to find that out. And note the 14-day reopen window: a case resolved and then recurring a fortnight later needs a related case, which carries a link back to the original so the agent can read the history.

Worked example

The throttling case, once the plan allows it, is five fields and a description.

Case type. Technical, because it concerns how a service is behaving rather than an invoice or a quota. If the answer turns out to be a raised quota, that becomes a second case of a different type.

Service. The service returning the errors, chosen from the list. Guessing here routes the case to a team that does not own the problem, and the correction adds hours.

Category. The category list is specific to the service chosen, and it is what routes the case within that service’s support team.

Severity. Shift confirmations are failing for one customer and the platform is otherwise up, so Production system impaired fits, with a four-hour first-response target. Filing it as Production system down to go faster is a habit that removes the distinction when it is needed. On a paid plan it can be raised later, and AWS reroutes it.

Description. The request IDs, the timestamps in UTC, the Region, the error text as returned, the rate observed, and what has already been ruled out. The case then runs through Unassigned, Work in Progress and Pending Customer Action, with every reply landing by email and answered in the console.

What’s worth remembering

  1. AWS Support Center is where cases are created, tracked, resolved and reopened, and its three case types are account and billing, service limit increase, and technical; the first two are available on every plan including Basic, and technical cases are not.
  2. Severity is chosen when the case is created and selects the first-response target, from 24 hours at General guidance to one hour at Production system down and under 30 minutes at Business-critical system down on Business Support+.
  3. The AWS Support API does case management and Trusted Advisor operations programmatically, and requires Business Support+, Enterprise Support or Unified Operations.
  4. An independent software vendor enrols on the Software Path and sells software that runs on AWS; a system integrator enrols on the Services Path and builds and operates it for you, which is the distinction behind most partner questions.
  5. AWS Marketplace is a catalogue plus procurement machinery: private offers for negotiated terms, Managed Entitlements for licence distribution, Private Marketplace for an approved catalogue, and billing consolidated onto the AWS invoice where Cost Explorer and Budgets can see it.
  6. Documentation describes how a service behaves, whitepapers and Prescriptive Guidance describe what AWS recommends, the blogs carry what changed, and re:Post is the free community service that now hosts the Knowledge Center articles.

These posts are LLM-aided. Backbone, original writing, and structure by Craig. Research and editing by Craig + LLM. Proof-reading by Craig.