We already use JanitorMonkey. It would likely involve tagging the instance in AWS with a tainted tag, and adding code to JanitorMonkey to do the normal mark-and-sweep.
That's awesome! I don't know how I've missed JanitorMonkey amongst their tools, but that looks great. Definitely giving it a whirl.