Decided once, inherited by everything after
Account and subscription topology
Workload, environment and tenant separation, shared services, sandbox, and dedicated security and log-archive accounts.
Identity and access
Federation with your existing identity provider, a role model people can actually work within, permission boundaries, privileged access and tested break-glass paths.
Network
Hub-and-spoke or transit topology, a deliberate address plan, controlled egress, private connectivity to platform services, DNS design and hybrid connectivity.
Guardrails
Preventive policy rather than after-the-fact reporting: permitted regions and services, mandatory encryption, enforced tagging, and the actions no one can take regardless of role.
Logging and audit
Centralised, immutable log archive, configuration and drift recording, and a feed your SIEM can consume.
Security baseline
Key and secrets management, posture monitoring, backup and recovery defaults applied by default rather than per project.
Cost control
Allocation model, tagging enforcement, budgets and anomaly alerting from day one, so spend is attributable before it is a problem.
Account vending
A repeatable path for issuing a new account or subscription that arrives already compliant, in minutes rather than a ticket queue.
Won or lost before anything is built
Your estate, your team, your regulatory obligations, and an honest decision about how much structure you can operate. This is where the design is won or lost.
Topology, identity, network and policy documented as decisions with reasoning, so the design can be reviewed by your architects and your auditors rather than taken on trust.
Delivered as Terraform or Bicep with a module structure and a pipeline that deploys it — reproducible from an empty organisation, not clicked together once in a console.
Runbooks, drift detection, and your team able to extend it. Optionally we keep owning the baseline while your engineers concentrate on workloads.
Sized to the estate, not to a template
For a small estate, the platform’s own reference implementation — AWS Control Tower and the Landing Zone Accelerator, or the Azure landing zone accelerator — gets a compliant foundation in place quickly, and we extend rather than replace it. For a multi-entity or regulated estate, the topology, identity model and policy set are designed properly, because the constraints are specific to you.
The failure we see most often is not an under-built landing zone. It is a fifteen-person company running a twelve-account structure with guardrails nobody understands, sold by someone who charged for the complexity. We size to what your team can operate.
Most of this work is not greenfield
If you already have accounts that grew organically, no consistent identity model and no baseline, we bring them under one governance model without a rebuild: assessment of what exists, a target structure, then account-by-account remediation with the guardrails introduced in audit mode before anything is enforced.
Where compliance stops being a document
Data residency, encryption, access separation, retention and audit evidence are all guardrail and logging decisions, and mapping them to DORA, NIS2, GDPR or BSI C5 obligations at design time costs a fraction of proving them retrospectively. The evidence an auditor asks for should be a query against the platform, not a project.
Four ways in
Landing zone design and build
Fixed scope, from requirements through to a foundation your first workload can land on.
Landing zone review
An existing foundation assessed against platform practice and your regulatory obligations, with a prioritised remediation list.
Remediation of an existing estate
Bringing organically grown accounts under one governance model, without a rebuild.
Baseline as a managed product
We keep the foundation current, patched and drift-free while your team builds on it.
What foundation does your estate need?
Tell us what you are running today and what has to be true a year from now, and we will tell you what foundation it needs.
- Documented design decisions for topology, identity, network, policy and logging
- The landing zone deployed as infrastructure code, reproducible from scratch
- Guardrail and policy set mapped to your compliance obligations
- Centralised logging, audit and cost allocation in place
- Account or subscription vending pipeline
- Runbooks, drift detection and team handover
