Overview
Design and automation of governance and identity components across an AWS environment with +20 accounts, supporting multiple teams, responsibilities and compliance requirements.
Context
Managing AWS accounts individually increased operational complexity, security inconsistencies and the effort required to apply organizational policies. Each account evolved independently, creating configuration, access and pattern divergences that hindered auditing and governance.
Challenge
Evolve toward a centralized, auditable and automated governance and identity model without eliminating the operational autonomy required between different responsibilities and workloads.
My role
- AWS Organizations architecture and Organizational Unit structuring
- IAM Identity Center and Permission Sets implementation for federated identity
- Service Control Policies and preventive guardrails definition and evolution
- Terraform automation for governance configuration versioning and review
- Landing Zone strategy evolution and AWS Control Tower evaluation
Architecture
The organization was structured into organizational units with distinct responsibilities, separating security, shared services and production/non-production workloads. Identity centralized via IAM Identity Center eliminated permanent credentials and established access through Permission Sets linked to organizational profiles.
Technical decisions
- Centralized identity with gradual elimination of permanent credentials
- Responsibility separation through Organizational Units with defined scopes
- Service Control Policies applied at appropriate hierarchy levels
- Governance infrastructure as code, with review and pipeline before application
- AWS Control Tower study and evaluation as Landing Zone evolution
Security & governance
The model combined centralized identity, least privilege and preventive organizational policies. SCPs acted as guardrails preventing high-risk actions before they occurred, complementing account-level controls. Continuous permission reviews focused on reducing exposure surface.
Automation
Terraform and CI/CD formed the governance automation and review layer. Changes to SCPs, Permission Sets and organizational structure went through versioning and pipeline before application, reducing divergences between planned and applied configuration in production.
Engineering challenges
The main technical challenge was balancing central governance with justified exceptions, without creating overly rigid or difficult-to-operate controls. Overly restrictive policies generated manual exception requests; overly permissive ones compromised security. Constant iteration with operational teams was necessary to calibrate the appropriate control level.
Results
- Consistent governance across +20 AWS accounts
- Access and policy traceability via Identity Center and versioned SCPs
- Reduced permanent credentials and improved security posture
- Foundation prepared for continuous Landing Zone evolution