Enterprise Cloud Architect
When to Use
- Design multi-BU landing zone programs — OUs, account vending, inherited guardrails
- Stand up or refresh Cloud Center of Excellence — standards, ARB, exception process
- Plan enterprise agreement strategy — commits, true-ups, multi-year cloud economics
- Define org-wide FinOps — allocation, showback/chargeback, EA utilization
- Place regulated workloads — residency, encryption, logging, isolation patterns
- Architect hybrid at scale — identity federation, DC portfolio, carrier diversity
- Harmonize multi-cloud posture — primary vs secondary, exit and portability
- Prepare steering and board materials — risk, cost, migration portfolio
- Publish enterprise reference architectures and mandatory controls catalog
When NOT to Use
- Single application or single-account target architecture →
cloud-architect
- Configure RDS, IAM errors, autoscaling tuning →
cloud-engineer
- Terraform module factory →
infrastructure-engineer
- CI/CD and GitOps delivery →
devops
- SOC 2 / ISO control evidence packs →
compliance-engineer
- Cloud-specific attestations, residency proof, CSPM evidence →
cloud-compliance-specialist
- IdP/KMS/SIEM program ownership →
information-security-engineer
- IAM entitlement design, access reviews, federation, SoD →
iam-specialist
- Non-cloud integration ADRs →
senior-system-architecture
- DC facility design →
data-center-design-execution-lead
- Multi-site DC capex portfolio →
data-center-portfolio-planning-execution-lead
- LLM/RAG enterprise copilot design →
applied-ai-architect-commercial-enterprise
- Strategy issue trees without cloud delivery →
business-consultant
- Program RAID for mixed software programs →
technical-program-manager
- Infrastructure org strategy, capex envelope, executive narratives →
vp-of-infrastructure
- Cloud program strategy, migration portfolio funding, cloud SteerCo →
vp-of-cloud
- Customer RFP, partner solution design, PoC scoping →
solutions-architect
Related skills
| Need |
Skill |
| VP cloud program and executive cloud narrative |
vp-of-cloud |
| Product/line-of-business cloud design |
cloud-architect |
| Cloud resource implementation |
cloud-engineer |
| IaC modules and pipelines |
infrastructure-engineer, devops |
| Enterprise system architecture |
senior-system-architecture |
| Compliance evidence |
compliance-engineer |
| Cloud framework evidence and assessor packages |
cloud-compliance-specialist |
| Security architecture |
information-security-engineer, cybersecurity |
| Identity governance, federation, PAM, cloud IAM standards |
iam-specialist |
| DC portfolio and hybrid capacity |
data-center-portfolio-planning-execution-lead |
| FinOps analysis and optimization |
finops-analyst |
| EA/commit economic modeling and NPV |
cloud-economist |
| Compute accounting and invoices |
compute-accounting-manager |
| Customer deal solution and RFP technical design |
solutions-architect |
| Enterprise AI on cloud |
applied-ai-architect-commercial-enterprise |
| AI governance |
ai-risk-governance |
| Large transformation program |
technical-program-manager |
| VP infrastructure leadership |
vp-of-infrastructure |
Core Workflows
1. Enterprise governance and CCoE
Standards, ARB, federation model.
See references/enterprise_cloud_governance.md.
2. Landing zone at scale
Multi-account hierarchy and vending.
See references/landing_zone_at_scale.md.
3. Enterprise agreements and FinOps
EA, commits, allocation.
See references/enterprise_agreements_finops.md.
4. Regulated enterprise patterns
Residency, controls, isolation.
See references/regulated_enterprise_patterns.md.
5. Hybrid and enterprise integration
Identity, ERP, DC linkage.
See references/hybrid_enterprise_integration.md.
6. Executive deliverables
Steering packs, standards catalog.
See references/enterprise_architecture_deliverables.md.
Outputs
- Enterprise cloud strategy — principles, scope, multi-year themes
- Landing zone blueprint — OU map, guardrails, shared services
- Standards catalog — mandatory, recommended, deprecated patterns
- ARB decision log — exceptions with expiry and owners
- FinOps model — allocation keys, EA coverage plan
- Migration portfolio — waves, dependencies, risk tier
Principles
- Federation over central bottlenecks — standards with self-service account vending
- Policy as code — guardrails enforced; exceptions time-boxed
- One financial truth — billing, tags, and GL alignment with finance
- Regulatory fit by design — not retrofit after launch
- Prefer cloud-architect for team-level designs inside the enterprise frame
1---2name: enterprise-cloud-architect3description: Guides enterprise-scale cloud architecture—multi-BU landing zones and federation, cloud Center of Excellence governance, enterprise agreement and commit strategy, org-wide FinOps and chargeback, regulated-workload patterns (residency, segmentation), hybrid integration with identity and ERP, and architecture review board standards for large organizations. Use when designing cloud at hundreds of accounts, steering CCoE policy, EA/MACC optimization, sovereign or regulated cloud placement, or executive cloud governance—not for single-product cloud designs (cloud-architect), hands-on service config (cloud-engineer), SOC 2 evidence automation (compliance-engineer), general cross-domain ADRs (senior-system-architecture), or enterprise AI copilot architecture (applied-ai-architect-commercial-enterprise), or VP-level cloud program portfolio and board narratives (vp-of-cloud).4---56# Enterprise Cloud Architect78## When to Use910- Design **multi-BU landing zone** programs — OUs, account vending, inherited guardrails11- Stand up or refresh **Cloud Center of Excellence** — standards, ARB, exception process12- Plan **enterprise agreement** strategy — commits, true-ups, multi-year cloud economics13- Define **org-wide FinOps** — allocation, showback/chargeback, EA utilization14- Place **regulated workloads** — residency, encryption, logging, isolation patterns15- Architect **hybrid at scale** — identity federation, DC portfolio, carrier diversity16- Harmonize **multi-cloud** posture — primary vs secondary, exit and portability17- Prepare **steering and board** materials — risk, cost, migration portfolio18- Publish **enterprise reference architectures** and mandatory controls catalog1920## When NOT to Use2122- Single application or single-account target architecture → `cloud-architect`23- Configure RDS, IAM errors, autoscaling tuning → `cloud-engineer`24- Terraform module factory → `infrastructure-engineer`25- CI/CD and GitOps delivery → `devops`26- SOC 2 / ISO control evidence packs → `compliance-engineer`27- Cloud-specific attestations, residency proof, CSPM evidence → `cloud-compliance-specialist`28- IdP/KMS/SIEM program ownership → `information-security-engineer`29- IAM entitlement design, access reviews, federation, SoD → `iam-specialist`30- Non-cloud integration ADRs → `senior-system-architecture`31- DC facility design → `data-center-design-execution-lead`32- Multi-site DC capex portfolio → `data-center-portfolio-planning-execution-lead`33- LLM/RAG enterprise copilot design → `applied-ai-architect-commercial-enterprise`34- Strategy issue trees without cloud delivery → `business-consultant`35- Program RAID for mixed software programs → `technical-program-manager`36- Infrastructure org strategy, capex envelope, executive narratives → `vp-of-infrastructure`37- Cloud program strategy, migration portfolio funding, cloud SteerCo → `vp-of-cloud`38- Customer RFP, partner solution design, PoC scoping → `solutions-architect`3940## Related skills4142| Need | Skill |43|---|---|44| VP cloud program and executive cloud narrative | `vp-of-cloud` |45| Product/line-of-business cloud design | `cloud-architect` |46| Cloud resource implementation | `cloud-engineer` |47| IaC modules and pipelines | `infrastructure-engineer`, `devops` |48| Enterprise system architecture | `senior-system-architecture` |49| Compliance evidence | `compliance-engineer` |50| Cloud framework evidence and assessor packages | `cloud-compliance-specialist` |51| Security architecture | `information-security-engineer`, `cybersecurity` |52| Identity governance, federation, PAM, cloud IAM standards | `iam-specialist` |53| DC portfolio and hybrid capacity | `data-center-portfolio-planning-execution-lead` |54| FinOps analysis and optimization | `finops-analyst` |55| EA/commit economic modeling and NPV | `cloud-economist` |56| Compute accounting and invoices | `compute-accounting-manager` |57| Customer deal solution and RFP technical design | `solutions-architect` |58| Enterprise AI on cloud | `applied-ai-architect-commercial-enterprise` |59| AI governance | `ai-risk-governance` |60| Large transformation program | `technical-program-manager` |61| VP infrastructure leadership | `vp-of-infrastructure` |6263## Core Workflows6465### 1. Enterprise governance and CCoE6667Standards, ARB, federation model.6869**See `references/enterprise_cloud_governance.md`.**7071### 2. Landing zone at scale7273Multi-account hierarchy and vending.7475**See `references/landing_zone_at_scale.md`.**7677### 3. Enterprise agreements and FinOps7879EA, commits, allocation.8081**See `references/enterprise_agreements_finops.md`.**8283### 4. Regulated enterprise patterns8485Residency, controls, isolation.8687**See `references/regulated_enterprise_patterns.md`.**8889### 5. Hybrid and enterprise integration9091Identity, ERP, DC linkage.9293**See `references/hybrid_enterprise_integration.md`.**9495### 6. Executive deliverables9697Steering packs, standards catalog.9899**See `references/enterprise_architecture_deliverables.md`.**100101## Outputs102103- **Enterprise cloud strategy** — principles, scope, multi-year themes104- **Landing zone blueprint** — OU map, guardrails, shared services105- **Standards catalog** — mandatory, recommended, deprecated patterns106- **ARB decision log** — exceptions with expiry and owners107- **FinOps model** — allocation keys, EA coverage plan108- **Migration portfolio** — waves, dependencies, risk tier109110## Principles111112- **Federation over central bottlenecks** — standards with self-service account vending113- **Policy as code** — guardrails enforced; exceptions time-boxed114- **One financial truth** — billing, tags, and GL alignment with finance115- **Regulatory fit by design** — not retrofit after launch116- **Prefer cloud-architect** for team-level designs inside the enterprise frame