aws-account-and-organization-topology
Installation
SKILL.md
AWS Account and Organization Topology
When to use
Invoke when establishing a new AWS Organization, restructuring accounts/OUs, adding an environment to the account ladder, or auditing org-level guardrails before workloads land.
Do not use for: in-account network/identity foundation — VPC, IAM roles, KMS, Secrets Manager (use aws-network-and-identity-foundation), workload compute primitives (use aws-workload-runtime-and-deployment), observability/cost instrumentation (use aws-observability-and-cost-readiness), or DR/multi-region (use aws-dr-and-multi-region-readiness).
Inputs
Required:
- Approved
infrastructure-platform.mddeclaring the org topology intent and the environment ladder (which environments exist and how they isolate). - Approved
architecture/securitydecisions on the guardrail posture: required encryption, allowed regions, root-usage policy, and audit/logging centralization.
Optional: