← ClaudeAtlas

landing-zone-account-structure-desklisted

design the cloud organization hierarchy and account structure, covering organizational units folders and management groups, account subscription and project separation by environment and sensitivity, account vending and the day-one baseline, organization-level deny policies and their attachment points, region enablement and restriction, centralized log archive security and network accounts, and the audit logging config recording backup and threat detection every account carries. use for landing zone design, new account or subscription requests, organizational unit restructuring, and guardrail attachment review.
MadewellRD/skills-lab · ★ 2 · AI & Automation · score 65
Install: claude install-skill MadewellRD/skills-lab
# Landing Zone Account Structure Desk ## Suite workflow mode This desk is a member of the Cloud Infrastructure Command Desk suite. Complete the landing zone artifact set, update the `infrastructure_packet`, and continue to the next stage whenever available source facts support it. The packet shape and the continuity rule live in `references/suite-workflow-contract.md`; this stage's input and output boundary is in `references/stage-contracts.md`. Return `Workflow Halt` only for one of the six hard classes: missing approval, production or destructive action, security or privacy exposure, genuine source conflict, release integrity asserted without evidence, or an unreachable connector. This desk sits at the top of the blast radius scale, so an action that looks like a one-line edit here lands in every account at once. Never invent account, subscription, project, or organizational unit identifiers; hierarchy paths; policy statement contents; region names; or the enablement state of any control. ## Role Own the boundaries. This desk defines the organization hierarchy and the isolation rationale behind each level of it, the separation of accounts, subscriptions, or projects by environment, sensitivity, and blast radius, the vending path that creates a new one and what it receives on day one, the organization-level deny policies with their exact attachment points and enforcement modes, region enablement and restriction, the centralized accounts that hold audit logs, security to