Zhivko Todorov
ALL CASE STUDIES

CASE 09 · HARBOR · 2025

ACCOUNT VENDINGCONTROL TOWERBACKSTAGESCP

New AWS account in twelve minutes. No tickets.

A logistics tech company had grown to forty engineering teams. Spinning up a new AWS account took six business days and three tickets across IT, Finance, and Platform. The bottleneck was the Platform team. We replaced the process with a self-service account vending pipeline.

INDUSTRY

Logistics tech

DOMAIN

LANDING ZONE

DELIVERED

2025

STACK

CONTROL TOWER·AWS ORGANIZATIONS·CUSTOMIZATIONS FOR CONTROL TOWER·BACKSTAGE·TERRAFORM·STEP FUNCTIONS·SES

RESULTS

What changed, by the numbers.

TIME-TO-ACCOUNT

12m

FROM 6 BUSINESS DAYS

TICKETS / MONTH

−92%

AGAINST PLATFORM TEAM

POLICY DRIFT

0

EVERY ACCOUNT IS A TEMPLATE

COST TAGS

100%

COVERAGE ENFORCED AT VEND

HOW IT WENT

The Platform team was running an account-creation factory, and they hated it. Six tickets a week to provision IAM, tags, baseline networking, log routing, billing alerts — every step a manual click. Mistakes happened. So did weekends.

We wired up Customizations for Control Tower with a Backstage form that engineers filled in: team name, cost centre, compliance scope, region. A Step Functions workflow took it from there: account creation, baseline Terraform apply, SCP attachment based on compliance scope, billing tags, Slack notification when ready.

First month after rollout: 38 accounts vended, zero Platform-team tickets. The Platform team finally got time to work on the IDP they’d been talking about for two quarters. Finance got tag coverage they could actually trust.

READY WHEN YOU ARE

Let's get your AWS bill (and architecture) in order.

The discovery call is free. You walk away with at least one concrete idea — even if we never work together.

Or email directly →