Cloud Identity & Organization Bootstrap organization
Building a company-level cloud organization and identity layer to enable multi-client resource isolation.
When a one-person consultancy serves multiple clients, mixing all cloud resources under a single project leads to IAM sprawl, accidental deletions, and audit blind spots. Bootstrapped a company-level Organization with a 4-tier folder hierarchy (personal / clients / archive / sandbox) so every client's cloud resources inherit IAM policies once at the folder level. New client onboarding time drops from hours to minutes.
- All cloud resources scattered under personal account, no company-level structure
- Setting up IAM for new clients meant clicking through the same screens every time
- Old projects piled up because no one knew what was still in use
- Audits couldn't answer 'which resources belong to which client'
- OAuth clients and Service Accounts spread everywhere, rotation infeasible
- Company-level Organization activated, all resources under unified management
- 4-tier folder structure isolates clients, IAM inherits at folder level
- New client projects automatically inherit org policy when placed in folder
- Service Account Dependency Check SOP enforced before any project deletion
- Cloud Identity Free with 50 seats, smooth path to paid edition