My company has a pretty unique strategy where we have separate AWS accounts for each unit within the company. Each unit gets a prod and non-prod account.
We have ~150 accounts, so roughly 75 different department, with some having not much and others have a lot of resources.
Its complex, but provides a lot of nice security primitives. We have an overarching administrative account, but that doesnt get used (and lots of alarm bells go off when it is).
We have ~150 accounts, so roughly 75 different department, with some having not much and others have a lot of resources.
Its complex, but provides a lot of nice security primitives. We have an overarching administrative account, but that doesnt get used (and lots of alarm bells go off when it is).