← Portfolio · Case Study

AWS Organisation Design for TAM Platform Enablement

Infrastructure · AWS · Sept 2023 – Dec 2023

Own from Salesforce (formerly Own Company) — London, UK

The challenge

Technical Account Managers needed to safely test and troubleshoot platform export and encryption features against real AWS infrastructure — without falling back on personal accounts or ungoverned, uncapped spend.

What I built

Designed and implemented a multi-account AWS Organisation to enable Technical Account Managers to securely test and troubleshoot Own Platform export and encryption features. Architected three segregated accounts (Alpha for billing/IAM, Beta for S3 exports, Charlie for RDS MySQL), with role-based access control, CloudTrail audit logging, CloudWatch alerting, and per-account usage caps.

Outcomes

  • Eliminated personal account usage across the global TAM team
  • Centralised billing with automated cost controls
  • Full CloudTrail audit capability across all accounts
  • Aligned to AWS Well-Architected Framework

Tech & approach

AWS Organizations · IAM · S3 · RDS MySQL · CloudTrail · CloudWatch