Multi-Account Landing Zone

Organizations and Control Tower foundation. Guardrails as policy, accounts as code, security as default.

Control Tower · Organizations · SCPs · Terraform · Security Hub

$32M
program on the platform
Org-wide
SCP guardrail coverage
Day one
security baselines
MANAGEMENT AWS Organizations Management account SCP Guardrails Preventive controls Control Tower Landing zone Account Vending Blueprints, Terraform WORKLOADS OU Vended Account Baselines on day one Program Accounts $32M network build SECURITY GuardDuty Org-wide detection Security Hub Delegated admin AWS Config Rules + aggregator applies provisions constrains vends vends telemetry recording findings findings
Fig. 1 — Org structure and vending flow; findings aggregate to delegated security admin.

solid = account · long dash = VPC · short dash = zone or planned

Context

  • Enterprise platform foundation at Guidehouse, 2024-present.
  • New accounts needed guardrails, baselines, tagging, budgets on day one.
  • A $32M program depended on landing-zone integration for its network.

Decision

  • AWS Organizations under Control Tower. OUs by function; SCPs per OU.
  • Account vending blueprints. Every account arrives configured, never hand-built.
  • Terraform modules for the platform. Versioned, reviewed, reused.
  • Detective baseline everywhere: Security Hub, GuardDuty, Config. Delegated admin.

Outcome

  • One vending path. Consistent accounts, org-wide guardrails, central findings.
  • Foundation absorbed a $32M program's network build.
  • Tagging and budgets enforced from account creation.