Consulting · Cloud Operating Models
Cloud Operating Models
Cloud arrived team by team. Each of them solved identity, networking and deployment again, slightly differently, and the bill arrives as one number nobody can attribute. [Draft copy]
The problem
Nobody owns the standard, so there is no standard.
Adoption happened where the pressure was: one team needed to ship, another had a contract expiring. Each made reasonable local choices. There was no forum with the authority to make those choices once, so they were made five times.
The result is an estate where security posture varies by team, cost cannot be attributed to a business capability, and governance is either absent or has become a review meeting that delivery teams route around.
What enterprise-grade looks like here
A Cloud Centre of Excellence that enables rather than gatekeeps.
The CCoE is the answer to "who decides", and it fails whenever it becomes the answer to "who approves". Enterprise-grade means a small standing group with named decision rights, a paved road that is genuinely the easiest way to ship, and guardrails expressed as policy-as-code so compliance is checked by machines rather than argued in meetings.
Cost is attributed to a business capability rather than a subscription, so the conversation about spend can happen with the people who caused it.
This framing repeats on every capability page. It is the differentiator, and it reads consistently across all of them (§9 T3).
What we do
Five moves, in this order.
-
Stand up the CCoE
Charter, membership and decision rights — what it decides, what it recommends, and what it deliberately leaves to teams. A CCoE that decides everything becomes a queue.
-
Define the paved road
Landing zone patterns, identity model, network segmentation, tagging and naming. One documented way to do the common things, with the rejected alternatives recorded.
-
Express the guardrails as code
Policy-as-code that fails a deployment rather than a review. Preventive where the risk warrants it, detective everywhere else.
-
Attribute the cost
Tagging enforced by the guardrails, then showback by capability, then a forecast the business can actually challenge.
-
Hand over the cadence
The CCoE meets, decides, records and publishes without us. That is the exit condition.
[Draft copy]
What you end up owning
Documents and configuration, not a dependency.
| Deliverable | Owned by |
|---|---|
| CCoE charter, membership and decision rights | IT leadership |
| Paved-road patterns with recorded design decisions | Platform team |
| Policy-as-code guardrail set | Platform and security |
| Cost attribution and showback model | Finance and IT jointly |
| Operating cadence and decision log | The CCoE itself |
[Draft copy]
Tell us what you are being asked to prove.
If cloud spend or operational risk has outgrown the model beneath it, that is the conversation to start with.
Start a conversation