Cloud Governance / Security

AWS Multi-Account Governance & Identity

Centralized governance, federated identity and automation for an AWS multi-account environment.

AWS OrganizationsIAM Identity CenterIAMSCPTerraformGitLab CI/CD
01

Overview

Design and automation of governance and identity components across multiple AWS accounts.

02

Context

Managing accounts individually increased operational complexity, security inconsistencies and the effort required to apply corporate policies.

03

Challenge

Move toward a centralized, auditable and automated model while preserving appropriate autonomy between responsibilities and workloads.

04

My role

  • AWS Organizations and organizational structure
  • IAM Identity Center and permission sets
  • Service Control Policies and guardrails
  • Terraform, version control and CI/CD
  • Landing zone strategy evolution
05

Architecture

The organization used separate units for security, shared services and production/non-production workloads.

Conceptual architecture — details intentionally generalized
AWS Organization
Organizational Units
Security / Shared Services
Production / Non-Production
IAM Identity CenterSCP Guardrails
Git
CI/CD
Terraform
06

Technical decisions

  • Centralized identity and fewer permanent credentials
  • Responsibility separation through organizational units
  • Guardrails at appropriate hierarchy levels
  • Code and pipeline-based change review
07

Security & governance

The model combined centralized identity, least privilege and preventive organizational policies.

08

Automation

Terraform and CI/CD reduced configuration drift and made governance changes reviewable.

09

Engineering challenges

The key challenge was balancing centralized governance with justified exceptions while maintaining operational usability.

10

Results

  • More consistent governance across accounts
  • Greater access and policy traceability
  • A foundation ready for landing zone evolution