1. Home
  2. Articles
  3. Guide

Guide

An AWS account structure for a growing company

When one AWS account stops being enough, and a starting structure that follows AWS’s own guidance without building more than a growing company needs.

  • By Anwar Alawad
  • Updated 1 October 2026
  • Read 6 min
01 · Why

Why one account stops working

An AWS account is the strongest boundary AWS offers. Inside one account, a mistake in a test environment, an over-broad IAM policy or a compromised developer key can reach production. Costs are hard to separate, and so is evidence for an auditor. Separate accounts give each environment its own blast radius, its own bill and its own permissions.

Anwar has set up AWS multi-account organisations from scratch. This is a starting point that follows AWS’s published guidance.

02 · Structure

A starting structure

AWS Organizations groups accounts into organisational units (OUs). AWS recommends these foundational OUs:

OUAccountsPurpose
SecurityLog Archive, Security ToolingCentral, tamper-resistant logs, and the security services that watch every account
InfrastructureShared networking, shared servicesResources every workload uses, such as networking and CI/CD
WorkloadsProduction, and non-productionYour applications, with production separate from everything else
SandboxOne per developer or teamExperiments, with no access to production

A growing company doesn’t need every account on day one. A sensible first step is the management account, Log Archive, Security Tooling, production and non-production. Add the rest when there’s a reason to.

03 · Management

Keep the management account empty

The account that owns the organisation should run no workloads. It holds billing, Organizations and IAM Identity Center, and very few people should be able to sign in to it.

04 · Guardrails

Guardrails with service control policies

Service control policies (SCPs) set the maximum permissions for every account in an OU, which no one in that account can override. Start with a few that are hard to argue with, such as stopping accounts from leaving the organisation:

deny-leave-organization.json
{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "DenyLeavingOrganization",
    "Effect": "Deny",
    "Action": "organizations:LeaveOrganization",
    "Resource": "*"
  }]
}

Others commonly added: stopping anyone switching off CloudTrail or GuardDuty, and limiting which regions can be used.

05 · Access

How people sign in

Use IAM Identity Center, connected to your identity provider, with MFA. People sign in once and choose an account and a role, with temporary credentials. There are no IAM users with long-lived keys to rotate or leak.

06 · Migration

Moving from one account

Your existing account usually becomes production, because moving production is the riskiest step. New accounts are created around it: non-production gets rebuilt from infrastructure code, and logging and security move to their own accounts. See AWS consulting and a minimum AWS security baseline.

07 · Sources

Sources

Next step

Still running everything in one account?

On a 30-minute call we’ll sketch the account structure that fits your company and how to move to it.