---
title: "Cloud governance: who approves which resource | SUMāTO"
description: How to set limits on cloud provisioning without returning to data-centre waiting times, using automatic guardrails and clear owners.
image: https://sumatogroup.com/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png
---

[Skip to content](https://sumatogroup.com/en/insights/blog/gobierno-de-nube-quien-aprueba#main-content)

- [INSIGHTS](https://sumatogroup.com/en/insights)
- [SUPPORT](https://sumatogroup.com/en/support)
- [CONTACT](https://sumatogroup.com/en/contact)

EN

[Español](https://sumatogroup.com/insights/blog/gobierno-de-nube-quien-aprueba) [English](https://sumatogroup.com/en/insights/blog/gobierno-de-nube-quien-aprueba)

[![SUMāTO Group — home](https://sumatogroup.com/hs-fs/hubfs/BRANDING/SMT%20-%20LOGO.png?width=40&height=40&name=SMT%20-%20LOGO.png)](https://sumatogroup.com/en)

- [HOME](https://sumatogroup.com/en/)
- About
  
  #### SUMāTO
  
    - [About us→](https://sumatogroup.com/en/about-us)
    - [Terms→](https://sumatogroup.com/en/legal)
    - [Legal→](https://sumatogroup.com/en/legal)
    - [Cookies→](https://sumatogroup.com/en/legal)
    - [Data protection→](https://sumatogroup.com/en/legal)
  
  
  #### METHODOLOGIES
  
    - [Design Thinking→](https://sumatogroup.com/en/methodologies#design-thinking)
    - [Lean Startup→](https://sumatogroup.com/en/methodologies#lean-startup)
    - [PMI→](https://sumatogroup.com/en/methodologies#pmi)
    - [Scrum→](https://sumatogroup.com/en/methodologies#scrum)
  
  
  #### Vendors
  
    - [AWS→](https://sumatogroup.com/en/vendors#aws)
    - [Cisco→](https://sumatogroup.com/en/vendors#cisco)
    - [Dahua→](https://sumatogroup.com/en/vendors#dahua)
    - [Fortinet→](https://sumatogroup.com/en/vendors#fortinet)
    - [Huawei→](https://sumatogroup.com/en/vendors#huawei)
    - [Microsoft→](https://sumatogroup.com/en/vendors#microsoft)
    - [OCI→](https://sumatogroup.com/en/vendors#oci)
    - [Panduit→](https://sumatogroup.com/en/vendors#panduit)
- Capabilities
  
  #### TECHNOLOGY
  
    - [Artificial Intelligence→](https://sumatogroup.com/en/artificial-intelligence)
    - [Data Analytics→](https://sumatogroup.com/en/data-analytics)
    - [Automation→](https://sumatogroup.com/en/automation-rpa)
    - [Cybersecurity→](https://sumatogroup.com/en/cybersecurity)
    - [Cloud→](https://sumatogroup.com/en/cloud)
  
  
  #### SEGMENTS
  
    - [SMB→](https://sumatogroup.com/en/smb)
    - [Enterprise→](https://sumatogroup.com/en/enterprise)
    - [Government→](https://sumatogroup.com/en/government)
- Consulting
  
  #### Assessments
  
    - [AI Readiness→](https://sumatogroup.com/en/ai-readiness-assessment)
    - [Analytics→](https://sumatogroup.com/en/data-analytics-maturity-assessment)
    - [Cloud→](https://sumatogroup.com/en/cloud-readiness-assessment)
    - [Cybersecurity→](https://sumatogroup.com/en/cybersecurity-assessment)
    - [Enterprise Architecture→](https://sumatogroup.com/en/enterprise-architecture-assessment)
    - [IT Maturity→](https://sumatogroup.com/en/it-maturity-assessment)
    - [IT Strategy→](https://sumatogroup.com/en/technology-strategy-assessment)
    - [Process Automation→](https://sumatogroup.com/en/process-automation-assessment)
  
  
  #### Consulting & Architecture
  
    - [AI First→](https://sumatogroup.com/en/ai-first)
    - [BCP→](https://sumatogroup.com/en/business-continuity-plan)
    - [DRP→](https://sumatogroup.com/en/disaster-recovery-plan)
    - [Enterprise Architecture→](https://sumatogroup.com/en/enterprise-architecture-togaf)
    - [Enterprise Transformation→](https://sumatogroup.com/en/enterprise-transformation)
    - [IT Strategic Plan→](https://sumatogroup.com/en/it-strategic-plan)
    - [Strategic Consulting→](https://sumatogroup.com/en/strategic-consulting)
- Operations
  
  #### INFRASTRUCTURE
  
    - [Data Center→](https://sumatogroup.com/en/data-center)
    - [Managed Services→](https://sumatogroup.com/en/managed-services)
    - [VDI→](https://sumatogroup.com/en/vdi)
    - [Intelligent Video Surveillance→](https://sumatogroup.com/en/video-surveillance)
  
  
  #### SECURITY
  
    - [NOC→](https://sumatogroup.com/en/noc)
    - [SOC→](https://sumatogroup.com/en/soc)
  
  
  #### USERS
  
    - [Modern Desktop→](https://sumatogroup.com/en/modern-desktop)
    - [Help Desk→](https://sumatogroup.com/en/help-desk)
- Industries
  
  Industries
  
    - [Banking & Finance→](https://sumatogroup.com/en/banking-finance)
    - [Insurance→](https://sumatogroup.com/en/insurance)
    - [Government→](https://sumatogroup.com/en/government)
    - [Healthcare→](https://sumatogroup.com/en/healthcare)
    - [Telecommunications→](https://sumatogroup.com/en/telecommunications)
    - [Retail & Consumer→](https://sumatogroup.com/en/retail)
    - [Manufacturing→](https://sumatogroup.com/en/manufacturing)
    - [Energy, Oil & Gas→](https://sumatogroup.com/en/energy-oil-gas)
    - [Education→](https://sumatogroup.com/en/education)
    - [Logistics & Transportation→](https://sumatogroup.com/en/logistics-transport)
    - [Legal Services→](https://sumatogroup.com/en/legal-services)
    - [Engineering & Construction→](https://sumatogroup.com/en/engineering-construction)
- Resources
  
  #### CONTENT
  
    - [Blog→](https://sumatogroup.com/en/insights)
    - [Use cases→](https://sumatogroup.com/en/use-cases)
  
  
  #### EVENTS
  
    - [Webinars→](https://sumatogroup.com/en/webinars)

EN

[Español](https://sumatogroup.com/insights/blog/gobierno-de-nube-quien-aprueba) [English](https://sumatogroup.com/en/insights/blog/gobierno-de-nube-quien-aprueba)

Search

- There are no suggestions because the search field is empty.

[Nube](https://sumatogroup.com/en/insights/tag/nube)

# Cloud governance: who can create what, and within which limits

[Andrés Lozada](https://sumatogroup.com/en/insights/author/andres-lozada) · Nov 12, 2025, 7:00:00 AM · 5 min read

**The cloud removed the friction of creating infrastructure, and with it went the control that friction had been imposing without anyone designing it. Governing the cloud is not reinstating the paperwork: it is replacing the wait with guardrails that act on their own.**

What follows: what is lost without governance, which guardrails work, what requires judgement, and how to introduce it without slowing the team down.

Before, creating a server required a request, an approval and a purchase. The process was slow and it had a useful side effect: somebody looked at every resource before it existed.

Now it is created in minutes with a card or a corporate account. That is a real gain in speed and, without design, also a complete loss of visibility.

## What is lost without governance

The first thing is attribution. Untagged resources belong to nobody, so their cost cannot be assigned or questioned, and the bill becomes a total nobody can explain.

The second is security consistency. Each team configures to its own judgement, and one internet-accessible storage bucket created in a hurry is enough to turn a one-off configuration into an exposure.

The third is predictability of spend. Without limits, consumption is discovered when the bill arrives, which is the worst moment to find out.

## Which guardrails work

**Preventive policies.** Rules that stop a non-compliant resource being created: without mandatory tags, in an unauthorised region, or with public access configured. They act before the fact, which is where they are cheap.

**A catalogue of approved templates.** Instead of asking permission, the team chooses from a set already reviewed. It preserves speed and guarantees that what is created complies, without anyone having to review case by case.

**Consumption alerts per unit.** Warnings when a project passes an agreed threshold, directed at whoever can act. Early visibility avoids the difficult end-of-month conversation.

**Separation of environments.** Separate accounts or subscriptions per environment and per unit. It is what allows cost to be attributed without argument and limits the blast radius of a mistake.

## What requires judgement

The level of restriction has to match the risk. Applying production controls to an experimentation environment achieves two things: it slows innovation, and it pushes people to create resources outside the framework.

That workaround is the signal that governance is badly calibrated. When complying is slower than not complying, the policy loses, and the policy is what should be corrected — not the insistence on it.

It is also necessary to decide what is forbidden and what is merely flagged. Forbidding everything questionable generates constant exceptions; flagging everything changes no behaviour. The balance is adjusted over time, not got right at the start.

## Who decides what

The rule that works is simple: the team operating a service decides how it builds it within a framework; the organisation decides the framework.

That framework contains few things and all of them verifiable: where data may reside, which tags are mandatory, which access configurations are barred, and what spending limit each unit has.

Everything else stays with whoever is accountable for the service. A short framework applied automatically governs better than a long document nobody consults.

## How to introduce it without slowing the team

Start by observing rather than blocking. Run the policies in audit-only mode for a period and measure how many resources would breach them: that number says how far current practice sits from the proposed framework.

Correct what appears most frequently first, talking to the teams affected. Often the breach reveals that the rule does not contemplate a legitimate case.

And only then move to blocking, starting with what has a security consequence and leaving until later what has a consequence of tidiness.

## What has to exist first

An agreed tagging convention, a separation of accounts by unit and environment, and an identified owner for each. Without those three, any policy is applied to ground nobody can describe.

It is also worth publishing the framework where the team works and explaining the reason for each rule. A restriction whose reason is understood gets followed; one that appears as an obstacle gets routed around.

## How you know it is working

Cloud governance that works shows up in simple indicators, not in the existence of an approved document.

The first is the proportion of resources with complete attribution. If it rises steadily, the tagging convention is being applied; if it stalls, somebody is creating outside the catalogue.

The second is the number of exceptions requested per period. A high, constant figure indicates the framework does not contemplate legitimate cases and is worth revisiting; a falling figure indicates the templates cover what people need.

The third is the time from someone requesting a resource to having it. If that time grows, governance is turning into the very paperwork the cloud came to remove.

### Does governing the cloud make it slow again?

Not if the guardrails act on their own. What slows things down is case-by-case human approval; a preventive policy and a catalogue of templates preserve speed and guarantee compliance.

### Where is it best to start?

With mandatory tagging and the separation of accounts. Without attribution of cost and responsibility, no other measure can be sustained or even discussed.

### Which signal indicates governance is badly calibrated?

Resources appearing outside the framework. When complying is slower than not complying, people route around the rule; that is corrected by revising the policy, not by insisting on it.

### Is it worth blocking from the start?

Observing first is preferable. Running the policies in audit-only mode shows how many resources would breach them and allows rules that miss legitimate cases to be corrected before anything is blocked.

Next step

[Cloud](https://sumatogroup.com/en/cloud)[Cloud Readiness Assessment](https://sumatogroup.com/en/cloud-readiness-assessment)[Cybersecurity](https://sumatogroup.com/en/cybersecurity)

[Nube](https://sumatogroup.com/en/insights/tag/nube)

![Andrés Lozada](https://sumatogroup.com/hs-fs/hubfs/SPEAKERS/AL.jpeg?width=56&height=56&name=AL.jpeg)

Andrés Lozada Nov 12, 2025, 7:00:00 AM 

[LinkedIn](https://www.linkedin.com/in/andreslozada/)

### Explore more from SUMāTO

[Enterprise AI](https://sumatogroup.com/en/artificial-intelligence) [Enterprise Transformation](https://sumatogroup.com/en/enterprise-transformation) [Strategic Consulting](https://sumatogroup.com/en/strategic-consulting) [AI Agent](https://sumatogroup.com/en/artificial-intelligence) [AI Contact Center](https://sumatogroup.com/en/artificial-intelligence) [Cybersecurity](https://sumatogroup.com/en/cybersecurity)

### Related Posts

#### [Hybrid cloud: deciding what moves and what stays](https://sumatogroup.com/en/insights/blog/nube-hibrida-que-se-queda)

**A hybrid architecture combines owned infrastructure with public cloud services and splits workloads between them according to what each one needs. It...**

#### [Automating the accounting close: what works and what does not](https://sumatogroup.com/en/insights/blog/automatizar-cierre-contable-mensual)

**The accounting close is not slow for lack of effort. It is slow because it waits. It waits for data from other areas, for someone to reconcile...**

#### [Cloud Computing: What It Is and Why It's No Longer Optional for Companies](https://sumatogroup.com/en/insights/blog/cloud-computing-que-es-por-que-no-es-opcional)

Ten years ago, the question at many Latin American companies was whether moving to the cloud made sense. Today that question no longer exists: 94% of...

![SUMāTO](https://sumatogroup.com/hs-fs/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png?width=200&height=100&name=SUM%C4%81TO%20%7C%20LOGO%201000x500.png)

Strategic technology planning consultants.

AI, Analytics, Cloud and Cybersecurity

<https://www.linkedin.com/company/sumatogroup> <https://www.youtube.com/@sumatogroup>

## Navigation

[Home](https://sumatogroup.com/en) [Capabilities](https://sumatogroup.com/en/artificial-intelligence) [Consulting](https://sumatogroup.com/en/strategic-consulting) [Operations](https://sumatogroup.com/en/managed-services) [Industries](https://sumatogroup.com/en/banking-finance) [Resources](https://sumatogroup.com/en/insights)

## SUMāTO

[About](https://sumatogroup.com/en/about-us) [Terms](https://sumatogroup.com/en/legal#terminos) [Legal & Privacy](https://sumatogroup.com/en/legal) [Data protection](https://sumatogroup.com/en/legal)

Cookies

## [Contact](https://sumatogroup.com/en/contact)

[sales@sumatogroup.com](mailto:sales@sumatogroup.com)

Mexico HQ

Mexico City, Mexico

[+52 55 8897 5791](tel:+525588975791)

Bogotá

Bogotá, Colombia

[+57 601 724 5059](tel:+576017245059)

© 2026 SUMāTO Group. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Andrés Lozada",
    "url" : "https://sumatogroup.com/en/insights/author/andres-lozada"
  },
  "datePublished" : "2025-11-12T13:00:00.000Z",
  "headline" : "Cloud governance: who approves which resource | SUMāTO",
  "mainEntityOfPage" : {
    "@id" : "https://sumatogroup.com/en/insights/blog/gobierno-de-nube-quien-aprueba",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://sumatogroup.com/hubfs/BRANDING/Logo_SUMATO_Original%20-%201000x500.png"
    },
    "name" : "SUMāTO Group"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Not if the guardrails act on their own. What slows things down is case-by-case human approval; a preventive policy and a catalogue of approved templates preserve speed and guarantee compliance."
    },
    "name" : "Does governing the cloud make it slow again?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "With mandatory tagging and the separation of accounts by unit and environment. Without attribution of cost and responsibility no other measure can be sustained or discussed."
    },
    "name" : "Where is it best to start with cloud governance?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Resources appearing outside the framework. When complying is slower than not complying, people route around the rule; that is corrected by revising the policy, not by insisting on it."
    },
    "name" : "Which signal indicates governance is badly calibrated?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Observing first is preferable. Running the policies in audit-only mode shows how many resources would breach them and allows rules that miss legitimate cases to be corrected."
    },
    "name" : "Is it worth blocking from the start?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://sumatogroup.com/#organization",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "MX",
    "addressLocality" : "Huixquilucan",
    "addressRegion" : "Estado de México",
    "postalCode" : "52787",
    "streetAddress" : "Av. Vialidad de la Barranca No. 6, Torre 1, Suite 400, Piso 4, Col. Bosques de las Palmas"
  },
  "alternateName" : [ "SUMāTO Group", "SUMATO Group", "Sumato Group", "SUMATO", "SUMaTO", "SUMaTO Group", "SUMTO", "SUMTO Group" ],
  "areaServed" : [ {
    "@type" : "Country",
    "name" : "México"
  }, {
    "@type" : "Country",
    "name" : "Colombia"
  }, {
    "@type" : "Place",
    "name" : "Latinoamérica"
  } ],
  "contactPoint" : {
    "@type" : "ContactPoint",
    "areaServed" : "Latinoamérica",
    "availableLanguage" : [ "es", "en" ],
    "contactType" : "sales",
    "email" : "sales@sumatogroup.com"
  },
  "description" : "SUMāTO is a Latin American technology consulting and integration firm founded in 2016, with a presence in Mexico and Colombia. It designs, implements and operates artificial intelligence, data analytics, automation, cybersecurity and cloud on the systems a client already runs, under governance frameworks such as NIST AI RMF and ISO/IEC 42001.",
  "foundingDate" : "2016",
  "knowsAbout" : [ "Inteligencia Artificial", "IA Generativa", "Agentes de IA", "Analítica de Datos", "Big Data", "Automatización de Procesos (RPA)", "Ciberseguridad", "Computación en la Nube", "Continuidad del Negocio y Recuperación ante Desastres", "Arquitectura Empresarial", "Transformación Digital" ],
  "legalName" : "SUMāTO Group",
  "location" : [ {
    "@type" : "Place",
    "address" : {
      "@type" : "PostalAddress",
      "addressCountry" : "MX",
      "addressLocality" : "Huixquilucan",
      "addressRegion" : "Estado de México",
      "postalCode" : "52787",
      "streetAddress" : "Av. Vialidad de la Barranca No. 6, Torre 1, Suite 400, Piso 4, Col. Bosques de las Palmas"
    },
    "name" : "SUMāTO MX",
    "telephone" : "+52 55 8897 5791"
  }, {
    "@type" : "Place",
    "address" : {
      "@type" : "PostalAddress",
      "addressCountry" : "CO",
      "addressLocality" : "Bogotá",
      "streetAddress" : "Cra. 45 # 103-34, Of. 202"
    },
    "name" : "SUMāTO CO",
    "telephone" : "+57 601 724 5059"
  } ],
  "logo" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://sumatogroup.com/hubfs/BRANDING/SUM%C4%81TO%20%7C%20LOGO%201000x500.png",
    "width" : 1000
  },
  "name" : "SUMāTO",
  "sameAs" : [ "https://www.linkedin.com/company/sumatogroup", "https://www.youtube.com/@sumatogroup", "https://torre.ai/teams/SUMaTOGroup", "https://www.cbinsights.com/company/sumto-group", "https://elioplus.com/profiles/channel-partners/57295/sumato-group" ],
  "telephone" : "+52 55 8897 5791",
  "url" : "https://sumatogroup.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://sumatogroup.com/#website",
  "@type" : "WebSite",
  "description" : "Technology consulting in AI, data, automation, cybersecurity and cloud across Latin America.",
  "inLanguage" : "en",
  "name" : "SUMāTO",
  "publisher" : {
    "@id" : "https://sumatogroup.com/#organization"
  },
  "url" : "https://sumatogroup.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://sumatogroup.com/en",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://sumatogroup.com/en/insights/blog/gobierno-de-nube-quien-aprueba",
    "name" : "Cloud governance: who can create what, and within which limits",
    "position" : 2
  } ]
}
```