Zhivko Todorov
ALL CASE STUDIES

CASE 90 · EMBER · 2026

SCPBEDROCKAI GOVERNANCEMODEL ACCESS

AI model access, scoped to who is allowed to use which.

An AI products company let any engineer call any Bedrock model in any region. Compliance was uncomfortable; finance was alarmed at the spend per individual experiment. We rolled out SCPs that scoped model access per OU, with named-model approvals and region restrictions.

INDUSTRY

AI products

DOMAIN

LANDING ZONE

DELIVERED

2026

STACK

AWS ORGANIZATIONS·SCP·BEDROCK·IAM IDENTITY CENTER·COST CATEGORIES·AUDIT MANAGER

RESULTS

What changed, by the numbers.

AI BILL VOLATILITY

−72%

MONTH-OVER-MONTH

GOVERNED MODEL ACCESS

100%

OF PRODUCTION CALLS

REGIONS RESTRICTED

17 → 3

PER-COMPLIANCE OU

ETHICS-REVIEW SLA

INTEGRATED

NEW MODELS GATED

HOW IT WENT

A single unsupervised Claude Opus run during a weekend hackathon had cost more than a junior engineer’s monthly salary. The CFO had a conversation about it. Nobody wanted to slow legitimate experimentation, but the floor had to come up.

SCPs scoped Bedrock access at the OU level. The production OU allowed only approved models in approved regions. The experimentation OU allowed broader access with monthly caps. The legal/compliance OU allowed only models that had cleared ethics review.

AI bill volatility dropped 72% month-over-month — predictable spend means predictable budgets. Production model access is 100% governed; ethics review is gated into the model-approval workflow. Engineers can still experiment, but the experimentation has guardrails.

READY WHEN YOU ARE

Let's get your AWS bill (and architecture) in order.

The discovery call is free. You walk away with at least one concrete idea — even if we never work together.

Or email directly →