Control-M on AWS

AI-Ready Execution with Control-M and AWS

Control-M orchestrates applications, data pipelines, file transfers, AI workflows, and Amazon Bedrock agents as one governed process, connecting AWS services with the rest of your cloud or hybrid environments so enterprises can move from isolated execution to trusted orchestration.

aws-partner

What is AI workflow orchestration on AWS?

AI workflow orchestration on AWS is running AI models, agents, and the data pipelines which feed them as one governed production process.

With Control-M, coordinate Amazon Bedrock agents, Amazon SageMaker models, AWS data services, applications, and file transfers in a single workflow. Control-M tracks the dependencies between steps, manages service level agreements (SLAs), and keeps one audit trail across every run.

Teams see the whole process to know whether the business outcome is on track, before a delay occurs. When a process extends beyond AWS, the same workflow carries it across your hybrid environment.

Where AI initiatives stall

For most enterprises running AI across hybrid environments that include AWS, the constraint is neither model quality nor automation coverage. It is the absence of a reliable account of what happens between systems. A pipeline finishes late, an agent acts on what it produced, and downstream work runs on incomplete data. By the time anyone connects those events, the business process has already missed its window. No single system failed, which is one reason the problem went undetected.

Agent adoption compounds the problem. Teams deploy Amazon Bedrock agents, custom agents, and framework-based agents across separate AWS accounts and business units. Each has its own trigger, and few share an approval path, runtime policy, or audit record. Every agentic step adds another execution path the business depends on. Because no team has a complete view of how those paths connect, a stalled step usually surfaces through a missing report rather than an alert.

How Control-M works with AWS

Control-M operates above AWS services as an orchestration layer. It invokes a service, monitors status, waits for completion, retries or recovers on failure, and reports the result as one step in a larger business process. Most processes extend beyond AWS, incorporating an on-premises application, an enterprise resource planning (ERP) transaction, or a file transfer from a partner.

Because Control-M defines the full sequence, it records how each step relates to the others. When an upstream step is delayed, Control-M immediately identifies the downstream work it feeds and the teams that depend on it.

aws-databrew-control-m

In a BMC reference implementation, Control-M runs an AI governance pipeline for portfolio rebalancing across Snowflake and AWS. The workflow extracts market and portfolio data from Snowflake, then runs an AWS Glue DataBrew job that checks the snapshot for completeness, duplicates, numeric ranges, and schema consistency. A failed check halts the workflow before the Amazon Bedrock agent acts on the data.

When validation passes, the agent analyzes market conditions, recommends a rebalance, and calls an AWS Lambda action group to generate a PDF report. Control-M watches Amazon S3 until the report arrives and meets a size threshold, then sends it to the investment committee through Amazon SES and refreshes an Amazon QuickSight dashboard. Snowflake governance tables record each run, recommendation, and decision for audit.

What Control-M orchestrates on AWS

AWS serviceWhat Control-M does
Amazon Bedrock, Amazon SageMaker
Runs agent and model steps as governed workflow steps, with dependencies, halt-on-failure, and a persisted audit record of each run
AWS Lambda, AWS Step Functions
Triggers functions and state machines as workflow steps, and holds downstream work until they finish
AWS Glue, AWS Glue DataBrew, Amazon EMR
Sequences transformation and validation jobs so each waits for complete source data; a failed data-quality check halts the workflow before downstream steps run
Amazon S3, Amazon Redshift
Watches for file arrival and gates dependent jobs on it
Amazon QuickSight, Amazon SES
Releases reporting and notification only after upstream data is verified
Amazon EC2, Amazon ECS, AWS Batch, AWS App Runner, AWS Auto Scaling
Runs compute jobs as workflow steps and scales resources with demand
Amazon Athena, Amazon RDS, Amazon DynamoDB, Amazon MWAA, AWS DataSync, Amazon AppFlow, AWS Data Pipeline, AWS Database Migration Service
Coordinates data movement, queries, and migrations with the workflows that depend on them
Amazon SQS, Amazon SNS, AWS Backup, AWS CloudFormation
Triggers messaging, backup, and infrastructure actions as governed workflow steps

Beyond AWS, Control-M integrates with Snowflake and Databricks, so pipelines that cross platform boundaries remain within a single workflow.

How enterprises orchestrate AI with Control-M

AI-powered orchestration

AI makes Control-M more intuitive, intelligent, and productive for every user.

  • Operate Control-M from AI agents and assistants
    The Control-M Model Context Protocol (MCP) Server gives AI agents and assistants a secure, standards-based interface to Control-M. Beyond checking workflow status and investigating failures, agents can take operational actions, such as triggering tasks, under the user and role authorizations already in place.

  • Put AI to work across the workflow lifecycle
    Control-M builds its own AI capabilities on Amazon Bedrock. Jett, the Control-M AI advisor, helps teams understand workflows and troubleshoot what ran. Control-M AI Pilot capabilities, including AI Workflow Creator, help teams build, analyze, and optimize workflows. Together, they bring intelligence to each stage of the workflow lifecycle, so anyone on the team can understand, build, and analyze workflows.

    BMC uses Amazon Bedrock for its flexibility, security, and broad support for foundation models.

Orchestrate AI in production

Control-M puts AI models and agents in to production-ready workflows and governs execution.

  • Run AI agents as workflow steps
    Control-M runs Amazon Bedrock agent steps inside production workflows that already carry SLAs, approval checkpoints, and audit requirements. An agent operating on production data requires the same controls as any other production step, so each agent step carries a dependency, a retry policy, and a record of its execution.

  • Deliver complete data to models and dashboards
    Control-M coordinates ingestion, transformation, and delivery across Amazon S3, AWS Glue, AWS Glue DataBrew, Amazon Redshift, Snowflake, Databricks, and Amazon SageMaker as one workflow with one set of dependencies. Analytics and AI outputs are only as reliable as the pipelines feeding them.

    When a source file arrives late, Control-M has already identified which downstream steps were waiting on it and which SLA is at risk. Control-M SLA Management reports the exposure while there is still time to respond.

  • Define hybrid workflows once
    Control-M defines a workflow spanning a partner file transfer, an ERP job, and a cloud service as one process, run by one team and recorded in one audit trail. Business processes rarely align to those boundaries. A file arrives from a partner, an ERP job posts it, a cloud service transforms it, and a report is delivered to a business user who has no visibility into the systems involved.

    Where a step runs does not change how Control-M manages it. Managed file transfer runs inside the same workflow as the steps that depend on it, so a late transfer appears as an SLA risk alongside every other step.

  • Apply uniform controls wherever workflows run
    Control-M applies the same policies, authorizations, and monitoring to every workflow, whether it runs on AWS or elsewhere in your hybrid environment, and whether a person, a time-based trigger, an event, or an agent starts it.

    Workload Policies enforce runtime rules across AWS accounts and environments. Role-based authorization and segregation of duties determine who can define, run, and modify workflows, and human approval checkpoints hold sensitive steps until someone signs off.

    Every execution carries a record of what ran, when, under whose authority, and with what result. Control-M records automated recovery and rollback actions on the same basis, so auditors and operators work from an identical history.

Control-M SaaS is built on AWS

Control-M SaaS runs exclusively on AWS. BMC hosts the service there; the workflows it orchestrates can run anywhere in your hybrid environment. Organizations can buy Control-M SaaS through AWS Marketplace and apply the purchase toward existing AWS spend commitments. 

Explore Control-M SaaS in AWS Marketplace right-arrow

AWS Integrations

Explore AWS integrations with Control-M

More Control-M on AWS resources

Learn more about the Control-M and Amazon Bedrock integration

Amazon Bedrock and Control-M help you orchestrate AI workflows, automate cross-tool dependencies, and keep model-driven business processes running reliably from data ingestion through delivery.

Control-M on AWS FAQs