Skip to content
Nube

Cloud governance: who can create what, and within which limits

The cloud removed the friction of creating infrastructure, and with it went the control that friction had been imposing without anyone designing it. Governing the cloud is not reinstating the paperwork: it is replacing the wait with guardrails that act on their own.

What follows: what is lost without governance, which guardrails work, what requires judgement, and how to introduce it without slowing the team down.

Before, creating a server required a request, an approval and a purchase. The process was slow and it had a useful side effect: somebody looked at every resource before it existed.

Now it is created in minutes with a card or a corporate account. That is a real gain in speed and, without design, also a complete loss of visibility.

What is lost without governance

The first thing is attribution. Untagged resources belong to nobody, so their cost cannot be assigned or questioned, and the bill becomes a total nobody can explain.

The second is security consistency. Each team configures to its own judgement, and one internet-accessible storage bucket created in a hurry is enough to turn a one-off configuration into an exposure.

The third is predictability of spend. Without limits, consumption is discovered when the bill arrives, which is the worst moment to find out.

Which guardrails work

Preventive policies. Rules that stop a non-compliant resource being created: without mandatory tags, in an unauthorised region, or with public access configured. They act before the fact, which is where they are cheap.

A catalogue of approved templates. Instead of asking permission, the team chooses from a set already reviewed. It preserves speed and guarantees that what is created complies, without anyone having to review case by case.

Consumption alerts per unit. Warnings when a project passes an agreed threshold, directed at whoever can act. Early visibility avoids the difficult end-of-month conversation.

Separation of environments. Separate accounts or subscriptions per environment and per unit. It is what allows cost to be attributed without argument and limits the blast radius of a mistake.

What requires judgement

The level of restriction has to match the risk. Applying production controls to an experimentation environment achieves two things: it slows innovation, and it pushes people to create resources outside the framework.

That workaround is the signal that governance is badly calibrated. When complying is slower than not complying, the policy loses, and the policy is what should be corrected — not the insistence on it.

It is also necessary to decide what is forbidden and what is merely flagged. Forbidding everything questionable generates constant exceptions; flagging everything changes no behaviour. The balance is adjusted over time, not got right at the start.

Who decides what

The rule that works is simple: the team operating a service decides how it builds it within a framework; the organisation decides the framework.

That framework contains few things and all of them verifiable: where data may reside, which tags are mandatory, which access configurations are barred, and what spending limit each unit has.

Everything else stays with whoever is accountable for the service. A short framework applied automatically governs better than a long document nobody consults.

How to introduce it without slowing the team

Start by observing rather than blocking. Run the policies in audit-only mode for a period and measure how many resources would breach them: that number says how far current practice sits from the proposed framework.

Correct what appears most frequently first, talking to the teams affected. Often the breach reveals that the rule does not contemplate a legitimate case.

And only then move to blocking, starting with what has a security consequence and leaving until later what has a consequence of tidiness.

What has to exist first

An agreed tagging convention, a separation of accounts by unit and environment, and an identified owner for each. Without those three, any policy is applied to ground nobody can describe.

It is also worth publishing the framework where the team works and explaining the reason for each rule. A restriction whose reason is understood gets followed; one that appears as an obstacle gets routed around.

How you know it is working

Cloud governance that works shows up in simple indicators, not in the existence of an approved document.

The first is the proportion of resources with complete attribution. If it rises steadily, the tagging convention is being applied; if it stalls, somebody is creating outside the catalogue.

The second is the number of exceptions requested per period. A high, constant figure indicates the framework does not contemplate legitimate cases and is worth revisiting; a falling figure indicates the templates cover what people need.

The third is the time from someone requesting a resource to having it. If that time grows, governance is turning into the very paperwork the cloud came to remove.

Does governing the cloud make it slow again?

Not if the guardrails act on their own. What slows things down is case-by-case human approval; a preventive policy and a catalogue of templates preserve speed and guarantee compliance.

Where is it best to start?

With mandatory tagging and the separation of accounts. Without attribution of cost and responsibility, no other measure can be sustained or even discussed.

Which signal indicates governance is badly calibrated?

Resources appearing outside the framework. When complying is slower than not complying, people route around the rule; that is corrected by revising the policy, not by insisting on it.

Is it worth blocking from the start?

Observing first is preferable. Running the policies in audit-only mode shows how many resources would breach them and allows rules that miss legitimate cases to be corrected before anything is blocked.

Andrés Lozada
Andrés Lozada
LinkedIn

Explore more from SUMāTO

Enterprise AI Enterprise Transformation Strategic Consulting AI Agent AI Contact Center Cybersecurity