Catalogue › AI & agents › CrewPoppy
CrewPoppy
The Crew HQ for your AI crew.
Download AgentsPoppy to get CrewPoppy
The AgentsPoppy app is free, and runs on macOS, Windows and Linux. CrewPoppy installs from inside it — the app asks your permission, shows exactly what will be created in your cloud, and can remove all of it later.
Screenshots
What you'd be asked to approve
Before CrewPoppy can touch your AWS account, AgentsPoppy shows this exact grant and waits for your yes. This preview is computed from the poppy's reviewed package by the same assessor code the app runs — it is the approval screen, shown early.
- cloudformationIts own
Can create, change and delete only CLOUDFORMATION resources named arn:aws:cloudformation:*:*:stack/CrewPoppyStack/* — it cannot change or delete any CLOUDFORMATION resource with a different name.
6 actions
CreateStack · UpdateStack · DeleteStack · DescribeStacks · DescribeStackEvents · DescribeStackResources - dynamodbIts own
Can create, change and delete only DYNAMODB resources named arn:aws:dynamodb:*:*:table/CrewPoppy* — it cannot change or delete any DYNAMODB resource with a different name.
12 actions
CreateTable · DeleteTable · DescribeTable · UpdateTimeToLive · DescribeTimeToLive · TagResource · ListTagsOfResource · GetItem · PutItem · UpdateItem · DeleteItem · Query - s3Its own
Can create, change and delete only S3 resources named arn:aws:s3:::crewpoppy-* — it cannot change or delete any S3 resource with a different name.
5 actions
CreateBucket · DeleteBucket · PutBucketTagging · PutBucketPublicAccessBlock · ListBucket - s3Its own
Can create, change and delete only S3 resources named arn:aws:s3:::crewpoppy-*/* — it cannot change or delete any S3 resource with a different name.
3 actions
PutObject · GetObject · DeleteObject - lambdaIts own
Can create, change and delete only LAMBDA resources named arn:aws:lambda:*:*:function:CrewPoppy* — it cannot change or delete any LAMBDA resource with a different name.
15 actions
CreateFunction · DeleteFunction · GetFunction · UpdateFunctionCode · UpdateFunctionConfiguration · TagResource · ListTags · InvokeFunction · AddPermission · RemovePermission · GetPolicy · CreateFunctionUrlConfig · GetFunctionUrlConfig · UpdateFunctionUrlConfig · DeleteFunctionUrlConfig - iamIts own
Can create, change and delete IAM identities and permissions named arn:aws:iam::*:role/CrewPoppy* — this controls who can do what in your account.
10 actions
CreateRole · DeleteRole · GetRole · PutRolePolicy · DeleteRolePolicy · GetRolePolicy · PassRole · TagRole · PutRolePermissionsBoundary · DeleteRolePermissionsBoundary - bedrockBroad
Can read any BEDROCK resource in your account. AWS offers no way to narrow this: this action accepts no resource limit at all, so this is the tightest form the grant can take.
1 action
GetFoundationModelAvailability - sesBroad
Can read any SES resource in your account — not just its own.
1 action
GetEmailIdentity - eventsIts own
Can create, change and delete only EVENTS resources named arn:aws:events:*:*:rule/CrewPoppy* — it cannot change or delete any EVENTS resource with a different name.
8 actions
PutRule · DeleteRule · DescribeRule · PutTargets · RemoveTargets · ListTargetsByRule · TagResource · ListTagsForResource - logsIts own
Can create, change and delete only LOGS resources named arn:aws:logs:*:*:log-group:/aws/lambda/CrewPoppy* — it cannot change or delete any LOGS resource with a different name.
5 actions
CreateLogGroup · DeleteLogGroup · PutRetentionPolicy · TagResource · ListTagsForResource - cognito-idpBroad
Can create new COGNITO-IDP resources in your account, but cannot change or delete anything that already exists. Its tag writes are compiled with conditions: it can only claim or release its own label, never another resource's.
7 actions
CreateUserPool · CreateUserPoolClient · DescribeUserPool · DescribeUserPoolClient · ListUsers · TagResource · UntagResource - cognito-idpIts own
Can create, change and delete only COGNITO-IDP resources tagged as its own — it cannot change or delete any COGNITO-IDP resource with a different tag.
7 actions
DeleteUserPool · UpdateUserPool · DeleteUserPoolClient · UpdateUserPoolClient · AdminCreateUser · AdminSetUserPassword · AdminDeleteUser
Nothing can be approved from a web page. The real Approve lives in the AgentsPoppy app on your machine, where this grant meets your actual AWS account — and where you can reject it, or tear down everything it created, at any time.
Evaluating CrewPoppy for a company? Its vendor security package is audit-ready documentation for your SOC 2 or vendor-risk process — generated from the same reviewed package, with a machine-readable copy for procurement tooling.
About CrewPoppy
CrewPoppy runs task-specific AI agents entirely in your own AWS — give each one a name, a role, a face and only the capabilities its job needs. Every external email waits for your approval, every dollar is capped and visible, and removing it leaves no trace.
What you get
Included, free
- ✓Your agents, your cloudPrompts, memory, outputs, logs and token spend all stay in your own AWS, on Amazon Bedrock.
- ✓Give an agent a job, not a training setA name, a role and instructions — with an optional AI-generated face so your crew feels like a team.
- ✓Nothing sends without your say-soAgents ask before anything consequential, and you answer from your desktop or your phone.
- ✓A runaway agent can't surprise youHard per-run and per-agent spend caps, a kill switch, and a live cost meter.
- ✓Zero lock-inYour agents are just data you own — export the whole crew and re-import it anywhere.
Pricing
Prices are read live from the developer's own listing. Whatever this poppy costs, the cloud resources it creates are billed by AWS directly to you — AgentsPoppy never marks them up.
Data & privacy
Nothing leaves your cloud. The developer declared that no data this poppy handles is ever sent outside the AWS account it runs in. You can verify that claim yourself — the source is public.
Developer & support
| Developer | CrewPoppy |
|---|---|
| Website | https://crewpoppy.com |
| Phone app | App Store · Google Play |
| Source code | https://github.com/leonct74/CrewPoppyPublic by requirement — you or your AI can audit exactly what it does before installing. |
| Support | support@crewpoppy.com |
| Privacy policy | https://crewpoppy.com/privacy |
| Terms of use | https://crewpoppy.com/terms |
| Age rating | Everyone |
| Runs on | macOS, Windows and LinuxNeeds AgentsPoppy 0.3.1 or newer. |
| Where it runs | Your own AWS account.AgentsPoppy holds no copy of your data and cannot read it. Cloud usage is billed to you by AWS at their prices. |
Support for the poppy itself comes from its developer. For the AgentsPoppy app, see Security or our terms.
Ready to run CrewPoppy in your own cloud?
Download the free AgentsPoppy app for macOS, Windows or Linux, connect your AWS account once, and install CrewPoppy from the catalogue inside it.