AWS Multi-Account Architecture with Control Tower
An AWS account is a strong boundary: its own resources, its own limits, its own bill and its own set of identities. Teams that run more than a handful of workloads usually split them across accounts, for example one per environment or per team, and manage the accounts together with AWS Organizations.
AWS Control Tower sets this up with a recommended structure, called a landing zone. It builds on AWS Organizations, AWS Service Catalog and AWS IAM Identity Center, creates the shared accounts for logs and audit, applies controls to groups of accounts, and lets teams request new accounts from a template. This diagram shows that structure and where people and policies come in.
Scroll sideways to see the whole diagram
Start from this diagram and edit it on your own board.
By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.
What each part does
- Engineers
- The people who build and operate the workloads. They sign in once and are given access to the accounts they need.
- Management account
- The account that owns the organization. It creates and invites accounts, hosts Control Tower and IAM Identity Center, and receives the consolidated bill. AWS recommends keeping production workloads out of it. Service control policies do not apply to it.
- Organizations
- AWS Organizations groups accounts into organizational units (OUs) and attaches policies to them. It is where accounts are created and where service control policies live.
- Control Tower
- Sets up and governs the landing zone. It creates the Security OU and its accounts, enables the controls you choose, and offers Account Factory to provision new accounts from a template.
- IAM Identity Center
- Single sign-on for people. Users and groups are given access to accounts through permission sets, so nobody needs a separate IAM user in each account.
- Security OU
- The OU that Control Tower creates for the shared accounts. It contains the log archive account and the audit account.
- Log archive account
- A shared account that works as the repository for logs of API activity and resource configuration from every account in the landing zone. Few people need access to it.
- Log bucket
- Where the logs are stored, in Amazon S3. Keeping them in an account of their own, away from the accounts that produce them, protects the record of what happened.
- Audit account
- A restricted shared account designed to give your security and compliance teams read and write access to all accounts in the landing zone.
- Cross-account access
- How the audit account reaches the others: programmatically, through a role that is granted to Lambda functions only. The audit account does not let anyone sign in to the other accounts manually.
- Workloads OU
- An OU you create for member accounts that run applications. Controls and policies attached to it apply to every account inside, including accounts added later.
- Production account
- Runs production workloads, separated from development by an account boundary rather than by naming conventions.
- Production apps
- Your production applications and data. Their permissions come from the account and from the controls on the OU.
- Development account
- Where teams build and test. Its own limits and budget keep experiments away from production.
- Development apps
- Test environments and experiments, with looser permissions than production but the same guardrails from the OU.
- SCPs
- Service control policies set the maximum permissions available in the accounts under an OU. They never grant access by themselves, and they do not apply to the management account. In Control Tower, preventive controls are implemented with SCPs.
How accounts, people and policies fit together
- The management account owns the organization and runs Organizations, Control Tower and IAM Identity Center.
- Control Tower builds the landing zone: it creates the Security OU with the log archive and audit accounts, and enables the controls you select.
- You add OUs for your own needs, such as Workloads, and new accounts are created in them with Account Factory.
- SCPs and other controls are attached to an OU and apply to every account in it. Preventive controls block an action, and detective controls find resources that break a rule.
- Each account sends its API activity and configuration logs to the log archive account. The audit account gives the security and compliance teams programmatic access across accounts.
- Engineers sign in once through IAM Identity Center and choose an account and a permission set, for example read-only for production and administrator for development.
When to use it
- Separating production from development so that an experiment cannot touch live data.
- Giving each team or product its own account, bill and limits.
- Meeting a rule that logs must be kept somewhere workload administrators cannot change.
Common variations
Add a Sandbox OU
The Control Tower documentation lists a Sandbox OU among the OUs of a landing zone, created when you set it up. Use an OU like it for individual experimentation, with tight budgets and strong preventive controls.
Add more OUs
Add OUs for infrastructure, policy staging or a business unit. Controls are applied per OU, so group accounts by the rules they share.
Use an existing organization
You can register an existing OU with Control Tower and enroll existing accounts, so you do not have to start from nothing. OUs created outside Control Tower cannot have its controls until they are registered.
Layer the controls
Control Tower has preventive controls (SCPs and resource control policies), detective controls (AWS Config rules) and proactive controls (CloudFormation hooks that check a template before it is deployed). Start with the mandatory ones and add the others as your rules become clear.
Make it yours
Rename the OUs and accounts to match how your company is organised, and decide which SCPs and controls each OU gets.
Opens this diagram as a board you can edit.
By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.