AI-Powered FinOps for Smarter SaaS Spend Management Mawarid Holdings’ Journey to Agentic AI-Driven Enterprise Operations on AWS

AI-Powered FinOps for Smarter SaaS Spend Management Mawarid Holdings’ Journey to Agentic AI-Driven Enterprise Operations on AWS

Mawarid Holdings, a global enterprise FinOps organization, needed a unified AI-assisted portal to manage SaaS spending and seat allocation across five high-value platforms, with strict data privacy, auditability, and zero autonomous execution. SUDO deployed an agentic FinOps assistant using Amazon Bedrock AgentCore, operating entirely within a private VPC with scoped IAM roles, Cedar policy enforcement, and KMS encryption across all data layers. The result was 100% blocked autonomous write actions, zero PII leakage in agent responses, and a SOC 2-aligned secure AI baseline delivered within an 8-week production timeline.

About Organization

Mawarid holding investment

Mawarid Holdings is a global enterprise organization managing complex SaaS operations and financial workflows across multiple high-value platforms. With FinOps data spread across invoices, spreadsheets, and vendor portals, the company required a smarter, more secure approach to managing software spend, seat allocation, and renewal decisions at scale while maintaining full compliance and auditability across all operations.

Deliver the right solutions on the leading cloud platform

Cloud Consultancy

Unmatched due to SUDO’s wide knowledge and experience with the top three public cloud providers: AWS, Microsoft Azure and Google Cloud, we provide cloud solutions that work uniquely in line with your business model. With our experienced professionals based in Dubai, UAE you’ll be able to gain deep insights into critical trends and opportunities in cloud technologies, access real-time data analytics, and modernize your entire infrastructure.

The Challenge

Auditability
Full SOC 2-aligned traceability was required from the initial alert through every agent tool invocation down to the final human acknowledgment.

Data Privacy and PII Exposure
Invoice PDFs and seat export data for platforms like Office 365 and Box contained sensitive employee identifiers and payment metadata, creating a high risk of model context leakage

Generative AI Abuse
Unconstrained agents posed a risk of prompt injection, where an attacker could coerce the agent into exfiltrating portfolio data or executing unauthorized API write actions

Agentic Scope Creep
Allowing the AgentCore Browser to navigate vendor portals created a significant attack surface if web egress was not strictly bounded and controlled

Why Choose SUDO

SUDO is a trusted AWS Premier Tier Services Partner with deep expertise in agentic AI, enterprise security, and data governance on AWS. SUDO brings strong experience in designing suggest-only AI architectures, zero-trust network configurations, and SOC 2- aligned governance frameworks for organizations handling sensitive financial and operational data.

The Solution

SUDO designed and deployed a secure, agentic FinOps assistant on AWS using Amazon Bedrock AgentCore, built around a strict suggest-only posture with zero autonomous execution and full enterprise-grade data governance.

Infrastructure and Network Isolation

  • AI workload operates in private subnets with VPC interface endpoints routing all Bedrock,
    AgentCore, and S3 traffic
  • Prevents public AI egress entirely across all data flows
  • Amazon Aurora and S3 ingest buckets are encrypted via AWS KMS

Identity and Data Security

  • Amazon Cognito gates agent invocation to authenticated root and admin sessions only
  • AgentCore Gateway tool Lambdas use scoped IAM roles with read-only access to
    normalized Aurora data
  • Secrets are retrieved at runtime and never embedded in prompts

AI Application Layer with Suggest-Only Posture

  • AgentCore Policy (Cedar) enforces a strict suggest-only workflow
  • Tools like get_case and create_recommendation are permitted; all execute_* tools are
    cryptographically denied
  • AgentCore Browser operates on a strict allowlist restricted to specific SaaS vendor
    domains only

Results & Benefits

The agentic FinOps assistant delivered measurable outcomes across security, compliance, and operational efficiency for Mawarid Holdings.

Blocked Autonomous Execution: 100% of write and remediation tool invocations were successfully denied by AgentCore Policy during PoC validation, eliminating unauthorized action risk.

Zero PII Leakage: Achieved zero unredacted employee identifiers in agent responses by injecting portfolio context via tool retrieval rather than raw document exposure.

Rapid Secure Deployment: Delivered a production-oriented, SOC 2-aligned baseline in 8 weeks,
compared to an estimated 5 to 6 months for a custom build.

Reusable Zero-Trust Blueprint: The ECS, Lambda, and Agent Core architecture serves as a repeatable pattern for internal operational AI assistants handling sensitive enterprise data across any industry