practice

Account Vending

Automated creation of new cloud accounts pre-configured with the organisation's networking, identity, logging, guardrails and cost allocation.

landing-zoneautomationgovernance

The alternative — creating accounts by hand — produces an estate where each account was configured slightly differently, according to what was known and cared about that week. That estate cannot be secured, audited or costed coherently, and remediating it later is far more expensive than getting it right once.

A vending mechanism issues an account already carrying: the organisational-unit placement and its guardrails, a network with an allocated non-overlapping address range, identity federation and baseline roles, centralised logging into an account nobody can delete from, encryption and network defaults, budget alerts, and mandatory tags for cost allocation.

Why accounts rather than a shared account with separate roles: an account is the strongest isolation boundary a cloud provider offers — for blast radius, for quota, for cost attribution and for security. Separating by environment and by major workload is one of the highest-value structural decisions available.

The failure to avoid is treating the vending machine as a one-off project. Standards change, and accounts created a year apart diverge unless there is a migration path for existing accounts. Without it, the estate splits into "before the standard" and "after", and the first group is never brought forward.