supervised deployments for aws

for solo builders & small-to-medium teams without devops — shipping with Claude Code, Codex & friends

Delegate your infra to your agent. Reliably.

Your agent deploys. Waypointer verifies — before apply and after. Independent, read-only, no migration.

You just confirm it’s what you meant.

Read-only AWS connect in five minutes. Works with the AWS you already have — nothing to migrate. A few beta seats open.

THE CATCH waypointer check_plan
task: “clean up the old database replica”
agent wrote a destroy plan · checking against reality… ✗ PLAN CHECK — blocked
aws_db_instance  db-prod-01 — the PRIMARY database
  group: database / web-app / prod · you likely meant:
  db-prod-replica-02 nothing was applied · valid Terraform, wrong resource
A CLEAN DEPLOY waypointer check_plan
task: “add a dead-letter queue to the billing worker” ✓ PLAN CHECK — safe
+ 2 resources → group: queue / billing-worker / prod
  untouched: database group (20), shared ALB, all other apps
✓ post-apply scan — reality matches the plan
logged → history: billing-worker / prod · note saved

The problem

Your agent is fast. Your account is the part that can’t be undone.

BLOCKED BEFORE APPLY

Agent about to delete the wrong database?

The plan is checked against what is actually running — not against a state file that may already be wrong. The verdict is in plain words: app, environment, what’s affected — no Terraform to read.

Valid Terraform aimed at the primary instance stops here.

CAUGHT IN MINUTES

Apply diverged from the plan?

An independent scan reads the account after every apply and tells you exactly what differs.

Two resources promised, one created — you hear it from us, not from the bill.

NEVER AGAIN

Re-explaining your infra every session?

Your agent reads the full map — and the trail behind it. Changes are logged as they happen, and your notes land without typing: say “mark this ALB as shared, don’t touch” — it’s on the resource.

“What did we do to billing last week?” — answered before you finish typing it.

One connected map

Repo, application, environment, cloud account — joined once and kept joined. Your agent works across the top; Waypointer runs underneath and checks every link it touches.

your agent repo app env cloud Waypointer

Built by scanning your real AWS — not by asking you to describe it. Works on day one with whatever’s already there. You just confirm the map.

Delegate your infra to your agent. Reliably.

Connect one AWS account read-only and watch the next plan get checked.

$ npx @waypointer/cli connect

Read-only IAM role · nothing to migrate · a few beta seats open