OpsCanary
awsiamPractitioner

Enhancing Operational Investigations with AWS DevOps Agent and Wiz

5 min read AWS DevOps BlogJul 29, 2026Reviewed for accuracy
Share
PractitionerHands-on experience recommended

In today's cloud environments, operational incidents can spiral out of control if not handled with a comprehensive security context. The integration of AWS DevOps Agent with Wiz addresses this challenge by allowing real-time security insights to be incorporated into operational investigations. This means you can identify not just what went wrong, but also the security implications of affected resources, all in one go.

The integration utilizes the Model Context Protocol (MCP), which enables the AWS DevOps Agent to call Wiz's remote MCP server during its investigations. When the agent identifies affected resources, it sends their identifiers to Wiz’s MCP endpoint and receives security findings in response. This process occurs automatically as part of the evidence collection—no separate steps or manual triggers are required. The endpoint URL for the Wiz MCP server is https://mcp.app.wiz.io/?toolset=devops, and you’ll need to configure authentication that matches your Wiz MCP server setup.

In production, you need to ensure that you have an active AWS DevOps Agent configuration with at least one Agent Space and a Wiz tenant with a remote MCP server endpoint. Authentication credentials are also necessary for successful integration. This setup can significantly enhance your operational investigations, but remember that no operational telemetry or broader investigation context is shared with Wiz, which keeps your data secure while still providing valuable security insights.

Key takeaways

  • Leverage the Model Context Protocol (MCP) for seamless security queries during investigations.
  • Configure the Wiz MCP server endpoint at https://mcp.app.wiz.io/?toolset=devops.
  • Ensure you have an active AWS DevOps Agent configuration and a Wiz tenant for integration.
  • Use authentication credentials that match your Wiz MCP server setup.

Why it matters

Incorporating security context into operational investigations can drastically reduce response times and improve incident resolution. By automating security insights, teams can focus on remediation rather than manual data gathering.

When NOT to use this

The official docs don't call out specific anti-patterns here. Use your judgment based on your scale and requirements.

Want the complete reference?

Read official docs

Test what you just learned

Quiz questions written from this article

Take the quiz →
DigitalOceanSponsor

Simple, affordable cloud — VMs, Kubernetes, and managed databases in minutes. Trusted by 600,000+ developers. Spin up a Droplet in 60 seconds.

Try DigitalOcean →

Get the daily digest

One email. 5 articles. Every morning.

No spam. Unsubscribe anytime.