
Enterprise Cloud Architect
- 28 installs
- 7 repo stars
- Updated May 20, 2026
- daemon-blockint-tech/agentic-enteprises-skill
Guides enterprise-scale cloud architecture: multi-BU landing zones, Cloud Center of Excellence governance, enterprise-agreement strategy, FinOps, and regulated-workload placement.
About
Guides enterprise cloud architecture at hundreds of accounts, covering landing zones and federation, CCoE governance, enterprise-agreement economics, org-wide FinOps, and regulated placement. An architect uses it when steering CCoE policy, designing account-vending programs, or preparing executive cloud governance materials.
- Federation over central bottlenecks with self-service account vending
- Policy-as-code guardrails with time-boxed ARB exceptions
Enterprise Cloud Architect by the numbers
- 28 all-time installs (skills.sh)
- Ranked #793 of 1,039 Cloud & Infrastructure skills by installs in the Skillselion catalog
- Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill enterprise-cloud-architectAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 28 |
|---|---|
| repo stars | ★ 7 |
| Last updated | May 20, 2026 |
| Repository | daemon-blockint-tech/agentic-enteprises-skill ↗ |
What it does
Guides enterprise-scale cloud architecture: multi-BU landing zones, Cloud Center of Excellence governance, enterprise-agreement strategy, FinOps, and regulated-workload placement.
Files
Enterprise Cloud Architect
When to Use
- Design multi-BU landing zone programs — OUs, account vending, inherited guardrails
- Stand up or refresh Cloud Center of Excellence — standards, ARB, exception process
- Plan enterprise agreement strategy — commits, true-ups, multi-year cloud economics
- Define org-wide FinOps — allocation, showback/chargeback, EA utilization
- Place regulated workloads — residency, encryption, logging, isolation patterns
- Architect hybrid at scale — identity federation, DC portfolio, carrier diversity
- Harmonize multi-cloud posture — primary vs secondary, exit and portability
- Prepare steering and board materials — risk, cost, migration portfolio
- Publish enterprise reference architectures and mandatory controls catalog
When NOT to Use
- Single application or single-account target architecture →
cloud-architect - Configure RDS, IAM errors, autoscaling tuning →
cloud-engineer - Terraform module factory →
infrastructure-engineer - CI/CD and GitOps delivery →
devops - SOC 2 / ISO control evidence packs →
compliance-engineer - Cloud-specific attestations, residency proof, CSPM evidence →
cloud-compliance-specialist - IdP/KMS/SIEM program ownership →
information-security-engineer - IAM entitlement design, access reviews, federation, SoD →
iam-specialist - Non-cloud integration ADRs →
senior-system-architecture - DC facility design →
data-center-design-execution-lead - Multi-site DC capex portfolio →
data-center-portfolio-planning-execution-lead - LLM/RAG enterprise copilot design →
applied-ai-architect-commercial-enterprise - Strategy issue trees without cloud delivery →
business-consultant - Program RAID for mixed software programs →
technical-program-manager - Infrastructure org strategy, capex envelope, executive narratives →
vp-of-infrastructure - Cloud program strategy, migration portfolio funding, cloud SteerCo →
vp-of-cloud - Customer RFP, partner solution design, PoC scoping →
solutions-architect
Related skills
| Need | Skill |
|---|---|
| VP cloud program and executive cloud narrative | vp-of-cloud |
| Product/line-of-business cloud design | cloud-architect |
| Cloud resource implementation | cloud-engineer |
| IaC modules and pipelines | infrastructure-engineer, devops |
| Enterprise system architecture | senior-system-architecture |
| Compliance evidence | compliance-engineer |
| Cloud framework evidence and assessor packages | cloud-compliance-specialist |
| Security architecture | information-security-engineer, cybersecurity |
| Identity governance, federation, PAM, cloud IAM standards | iam-specialist |
| DC portfolio and hybrid capacity | data-center-portfolio-planning-execution-lead |
| FinOps analysis and optimization | finops-analyst |
| EA/commit economic modeling and NPV | cloud-economist |
| Compute accounting and invoices | compute-accounting-manager |
| Customer deal solution and RFP technical design | solutions-architect |
| Enterprise AI on cloud | applied-ai-architect-commercial-enterprise |
| AI governance | ai-risk-governance |
| Large transformation program | technical-program-manager |
| VP infrastructure leadership | vp-of-infrastructure |
Core Workflows
1. Enterprise governance and CCoE
Standards, ARB, federation model.
See `references/enterprise_cloud_governance.md`.
2. Landing zone at scale
Multi-account hierarchy and vending.
See `references/landing_zone_at_scale.md`.
3. Enterprise agreements and FinOps
EA, commits, allocation.
See `references/enterprise_agreements_finops.md`.
4. Regulated enterprise patterns
Residency, controls, isolation.
See `references/regulated_enterprise_patterns.md`.
5. Hybrid and enterprise integration
Identity, ERP, DC linkage.
See `references/hybrid_enterprise_integration.md`.
6. Executive deliverables
Steering packs, standards catalog.
See `references/enterprise_architecture_deliverables.md`.
Outputs
- Enterprise cloud strategy — principles, scope, multi-year themes
- Landing zone blueprint — OU map, guardrails, shared services
- Standards catalog — mandatory, recommended, deprecated patterns
- ARB decision log — exceptions with expiry and owners
- FinOps model — allocation keys, EA coverage plan
- Migration portfolio — waves, dependencies, risk tier
Principles
- Federation over central bottlenecks — standards with self-service account vending
- Policy as code — guardrails enforced; exceptions time-boxed
- One financial truth — billing, tags, and GL alignment with finance
- Regulatory fit by design — not retrofit after launch
- Prefer cloud-architect for team-level designs inside the enterprise frame
Enterprise agreements and FinOps
Table of contents
1. Enterprise agreements 2. Commit strategy 3. Chargeback and showback 4. Optimization cadence
Enterprise agreements
Covers AWS EDP, Azure MCA/EA, GCP commits — structure varies by vendor.
Architecture inputs for procurement (not legal negotiation):
- Growth forecast by BU and workload type (compute, data, AI)
- Region mix and sovereign requirements
- Commit coverage — what spend is in-scope vs marketplace/excluded
- True-up risk — under-commit penalties vs over-commit waste
Coordinate with commercial-counsel on contract structure; compute-accounting-manager on GL mapping.
Commit strategy
| Instrument | Fit |
|---|---|
| Compute/Savings Plans / CUD | Steady baseline |
| RI (legacy) | Long-stable workloads |
| Spot / preemptible | Batch only with SLO headroom |
| SaaS marketplace | Often excluded — track separately |
Model utilization monthly; reforecast quarterly before true-up.
Chargeback and showback
Define allocation keys:
- Direct tags (cost center, project)
- Shared services split (logging, hub network) by % revenue, headcount, or usage
- EA benefit distribution — fixed % or consumption-based
Publish monthly showback before chargeback if culture requires transparency.
Finance owns invoice payment; architecture owns tag policy enforcement.
Optimization cadence
| Cadence | Actions |
|---|---|
| Weekly | Anomalies, untagged spend |
| Monthly | Rightsizing, idle resources, RI/SP coverage |
| Quarterly | Architecture standards updates, EA forecast |
| Annual | EA renegotiation data pack |
BU-level waste remediation → cloud-engineer execution; standards → enterprise catalog.
Enterprise architecture deliverables
Table of contents
1. Steering pack 2. Migration portfolio 3. Standards publication 4. Relationship to cloud-architect
Steering pack
Executive summary (5–10 slides max):
1. Posture — spend, risk, migration progress vs plan 2. EA/commit — utilization, forecast, true-up exposure 3. Incidents/themes — security, outages, policy violations 4. Decisions needed — funding, exceptions, region expansion 5. Next quarter — standards changes, major migrations
Quantify in dollars and risk, not service names alone.
Migration portfolio
Enterprise view across BUs:
| Wave | Apps | Strategy (7R) | Dependency | Risk | Owner |
|---|
Prioritize by value, risk, readiness; capacity in landing zone and network.
Wave execution detail → cloud-architect per application; program office → technical-program-manager.
Standards publication
Publish via:
- Internal architecture portal (versioned)
- IaC module registry with compliance badges
- Training for new account owners
Deprecation: notice period, automated policy warnings, enforcement date.
Relationship to cloud-architect
| Scope | Skill |
|---|---|
| Enterprise guardrails, EA, ARB, multi-BU | enterprise-cloud-architect |
| Application reference architecture, WAF, single migration | cloud-architect |
| Resource configuration | cloud-engineer |
When a BU asks for architecture inside approved standards, route to cloud-architect with enterprise catalog as constraint.
Enterprise cloud governance
Table of contents
1. CCoE operating model 2. Architecture review board 3. Standards catalog 4. Federation vs central IT
CCoE operating model
Typical functions:
| Function | Deliverable |
|---|---|
| Standards | Approved services, regions, patterns |
| Enablement | Training, sandboxes, templates |
| FinOps | Tag policy, EA management, reports |
| Security liaison | Guardrail requirements with security org |
| Vending | Account/subscription provisioning API |
Define RACI with BUs, security, finance, and platform engineering.
Architecture review board
ARB triggers:
- New regulated data class in cloud
- Internet-exposed production workload
- Cross-account trust or org-wide IAM change
- Spend above threshold or new EA commit
- Departure from mandatory standard
ARB packet: context, options, NFRs, cost ROM, risks, recommendation.
Exceptions: time-bound, named owner, re-review date.
Team-level designs → cloud-architect ARB lite; escalate per threshold.
Standards catalog
| Tier | Meaning |
|---|---|
| Mandatory | Block deploy if non-compliant (policy) |
| Recommended | Default in templates |
| Deprecated | Sunset date; migration required |
| Prohibited | e.g. public S3, long-lived access keys |
Version standards; communicate via portal and IaC modules.
Federation vs central IT
Balance:
- Central — landing zone, network hub, logging, EA, break-glass
- Federated — application teams own workloads inside guardrails
- Escalation — disputes on cost allocation or risk acceptance
Align with senior-system-architecture for enterprise integration principles.
Hybrid enterprise integration
Table of contents
1. Identity federation 2. ERP and core systems 3. Data center portfolio 4. Network diversity
Identity federation
Enterprise standard:
- Entra ID / AD as IdP for cloud SSO
- Conditional access — MFA, device compliance, location
- Privileged access — PIM/JIT; break-glass monitored
- Workload identity — no static keys in applications
Map legacy apps on LDAP sync vs SAML/OIDC migration waves.
ERP and core systems
Common integrations:
- SAP on cloud or RISE — latency and private connectivity
- Mainframe batch — scheduled transfer, not synchronous coupling
- Message buses — enterprise Kafka/Event Hub between on-prem and cloud
Architecture defines integration zones — DMZ, API gateway, ESB vs event mesh.
Detailed integration ADRs may involve senior-system-architecture.
Data center portfolio
Align cloud burst and steady-state with on-prem capacity:
- Portfolio roadmap →
data-center-portfolio-planning-execution-lead - Utilization and GPU supply →
data-center-compute-supply-efficiency - New MW delivery →
senior-data-center-capacity-delivery-manager
Hybrid placement rule: default cloud for elastic; on-prem for fixed high-utilization or license-bound unless strategy says otherwise.
Network diversity
Enterprise hybrid requires:
- Dual carriers on ExpressRoute/Direct Connect/Interconnect
- BGP and failover testing
- DNS split-horizon and global load balancing strategy
- Egress inspection policy consistent cloud and on-prem
Document single points of failure in steering reviews.
Landing zone at scale
Table of contents
1. Hierarchy patterns 2. Account vending 3. Guardrails at scale 4. Shared services hub
Hierarchy patterns
Example AWS-style (adapt for Azure MG / GCP folders):
Organization
├── Security (log archive, audit, tooling)
├── Infrastructure (network hub, DNS, egress)
├── Sandbox OU (SCP-limited, auto-suspend)
├── NonProd OU (per BU or per product)
└── Prod OU (stricter SCPs, change windows)Per BU vs per environment account model — document in ADR with cost and blast-radius trade-offs.
Account vending
Self-service flow:
1. Request via portal/ticket with owner, cost center, data class, region 2. Automated create — OU placement, baseline SCPs, tags, networking attachment 3. Handoff — break-glass roles, FinOps tags, security contacts 4. Lifecycle — suspend sandbox idle; decommission with data retention rules
Integrate with infrastructure-engineer module pipeline for baseline config.
Guardrails at scale
| Layer | Examples |
|---|---|
| Org SCP / policy | Region deny, encryption required |
| Tag policy | Mandatory cost center, owner, data class |
| Service control | Allowed instance types, no public DB |
| Detective | Config rules, Security Hub, org trails |
Drift: central dashboard; BU remediation SLAs.
Shared services hub
Centralize:
- Egress and inspection
- Private DNS and certificate authorities
- Central logging and SIEM feed
- Backup vaults for regulated tiers
Document data flows from spoke to hub — cloud-architect network detail for spokes.
Regulated enterprise patterns
Table of contents
1. Data classification 2. Residency and sovereign 3. Control patterns 4. Audit and evidence
Data classification
Map workloads to tiers (example):
| Tier | Cloud placement | Examples |
|---|---|---|
| Public | Standard regions | Marketing sites |
| Internal | Private networking, standard logging | Internal apps |
| Confidential | Restricted regions, CMK, enhanced logging | HR, finance |
| Regulated | Sovereign or approved regions, dedicated controls | PHI, certain financial |
Architecture selects region, encryption, and connectivity; legal/compliance confirms adequacy.
Residency and sovereign
Decisions:
- In-region processing and storage
- Sovereign cloud or dedicated regions when required
- Cross-border replication prohibited or encrypted with approval
- Subprocessor list for SaaS components
Do not provide legal opinions — flag for compliance and counsel.
Control patterns
| Control area | Pattern |
|---|---|
| Encryption | CMK per tier; key hierarchy and rotation |
| Network | No public endpoints; PrivateLink; egress allowlist |
| Identity | SSO federation; no local IAM users; PIM for admin |
| Logging | Immutable central store; retention per tier |
| Backup | Encrypted, cross-region only if permitted |
| AI/LLM | No training on customer data; private endpoints — applied-ai-architect-commercial-enterprise |
Audit and evidence
Architecture delivers:
- Control mapping — which cloud config satisfies which control intent
- Diagrams — data flows for assessors
- Config baselines — policy-as-code references
Evidence collection automation → compliance-engineer.
Security sign-off → information-security-engineer.