Overview
Overview
Many teams reach production on AWS before the foundation is in place. Workloads end up in a single account with no organizational boundaries, security findings are scattered or switched off, backup and recovery were never designed in, and nobody owns cost. This service puts the foundation underneath what you have already built — or builds it correctly from the start.
We assess your current state (or design the target state for a greenfield build) against the AWS Cloud Adoption Framework and the AWS Well-Architected Framework, then deploy a multi-account foundation using AWS Control Tower, the Landing Zone Accelerator on AWS, or a combination of the two, depending on how complex or regulated your environment is.
What the foundation includes
- Multi-account structure with organizational units in AWS Organizations
- Centralized logging — AWS CloudTrail and AWS Config aggregation
- Organization-wide security baseline — Amazon GuardDuty and AWS Security Hub
- Centralized backup strategy using AWS Backup
- Preventive guardrails via Service Control Policies
- Centralized identity through AWS IAM Identity Center
How we deliver
- Assess / design — current-state review against CAF and Well-Architected, or target-state design for a new environment. Output: a written findings and design document.
- Deploy — the landing zone is built with AWS Control Tower (managed, console-based) and/or the Landing Zone Accelerator on AWS (infrastructure-as-code, for complex or regulated needs).
- Migrate — existing workloads are moved into the new account structure with a planned, low-downtime cutover. Skipped for greenfield engagements.
- Hand over — architecture documentation, runbooks, and a prioritized remediation backlog. Not just a deployed stack.
Who this is for
Organizations running production workloads on AWS without account separation or a governance baseline; teams starting a migration to AWS who want the foundation right the first time; and organizations preparing for an audit or a security review.
Scope options
- Greenfield / migrate-to-AWS — fixed-scope engagement, quoted from the standard scope.
- Existing AWS environment (retrofit) — scoped and quoted after the assessment, since the work depends on what is already deployed.
Recommended next step
Most customers pair this engagement with a block of senior architecture time for the weeks immediately after go-live, when the remediation backlog is being worked through. See "Adamass AWS Architect as a Service" — 40 hours of hands-on support, usable within two months of handover. It can be included in the same private offer as this engagement.
AWS charges
This service does not include your AWS infrastructure costs. Any AWS resources deployed into your account as part of the engagement are billed to you by AWS separately from this AWS Marketplace transaction.
Access and permissions
Delivery requires access to your AWS accounts, granted through an IAM role that you create and control, scoped to the permissions listed in the statement of work. No long-lived access keys are used, and access is revoked at the end of the engagement. Full details of the provisioned AWS services and the IAM policy statements are provided before work begins.
Highlights
- Multi-account foundation deployed with AWS Control Tower and or our Landing Zone Accelerator on AWS, assessed against the AWS Cloud Adoption Framework and Well-Architected Framework
- Built for brownfield as well as greenfield, existing production workloads are migrated into the new account structure with a planned, low-downtime cutover
- Handover includes documentation and a prioritized remediation backlog, plus optional bi-weekly security posture reviews after go-live
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
"Adamass AWS Architect as a Service" — 40 hours of hands-on support, usable within two months of handover. It can be included in the same private offer as this engagement.
Other inquiries: aws@adamass.se