Multi-account landing zone architecture

Separate accounts per environment, one org-wide audit trail, archived logs and a budget guardrail on top.

AWSorganizationscloudtrailgovernanceaccounts
Organization rootManagement accountProduction workload…3 × 1 vCPU · 2 GBStaging workload1 vCPU · 2 GBOrg-wide trailfirst mgmt-event copyfree · S3 storageLog archive1 TB deep archiveBudget capguardrail
6 nodes — 5 infrastructure and 1 agent, on one graph. Drawn by the same layout the product uses.
What is in it

Every resource, and what it costs.

Projections from August 2026 list prices for always-on resources. Connect an account and these become the figures your provider actually bills.

Resources in the Multi-account landing zone template with projected monthly cost.
NodeTypeWhat it isProjected
Organization rootExternalManagement accountno direct cost
Production workloads ×3Compute3 × 1 vCPU · 2 GB$108/mo
Staging workloadCompute1 vCPU · 2 GB$36/mo
Org-wide trailExternalfirst mgmt-event copy free · S3 storagefrom $2.00/mo
Log archiveStorage1 TB deep archivefrom $1.00/mo
Budget capGuardrailHalts runs over $5000/moenforced at runtime

Agent steps are priced from provider-reported token usage once the agent runs, not estimated. Guardrails cost nothing and are the reason a runaway agent cannot. 2 rows show from because those services bill by usage, so the total is a scenario at the stated volumes, not a quote.

Open Multi-account landing zone on the canvas.

It loads as an editable graph. Connect an account or instrument an agent and the projected figures above become measured ones.