Overview
Design and automation of governance and identity components across multiple AWS accounts.
Context
Managing accounts individually increased operational complexity, security inconsistencies and the effort required to apply corporate policies.
Challenge
Move toward a centralized, auditable and automated model while preserving appropriate autonomy between responsibilities and workloads.
My role
- AWS Organizations and organizational structure
- IAM Identity Center and permission sets
- Service Control Policies and guardrails
- Terraform, version control and CI/CD
- Landing zone strategy evolution
Architecture
The organization used separate units for security, shared services and production/non-production workloads.
Technical decisions
- Centralized identity and fewer permanent credentials
- Responsibility separation through organizational units
- Guardrails at appropriate hierarchy levels
- Code and pipeline-based change review
Security & governance
The model combined centralized identity, least privilege and preventive organizational policies.
Automation
Terraform and CI/CD reduced configuration drift and made governance changes reviewable.
Engineering challenges
The key challenge was balancing centralized governance with justified exceptions while maintaining operational usability.
Results
- More consistent governance across accounts
- Greater access and policy traceability
- A foundation ready for landing zone evolution