In Part 1 SELL! shipped a landing zone without mapping the workload. Part 2 rewrote governance after deny first. Part 3 put a second team on an untested path. This field note is the question that should have been answered before the first terraform apply: what is a subscription for?
SELL! is a fictional company. Any resemblance to a real platform team’s war story is the point.
Setting the Scene
Week sixteen at SELL!. Aroha, the CFO, wants cloud cost by product line for the board pack. Tui wants to know which subscriptions process personal information before the next agency questionnaire. Without a documented answer to what a subscription is for, teams had improvised.
Eighteen months of pre-migration improvisation came across with the estate: contractor subscriptions, shared Dev boxes, names that felt right in 2023. The landing zone is sixteen weeks old. The sprawl is not.
Name standards first. Strategy later. The board pack is Friday.
- Rename the worst offenders.
- Ask owners to fix tags.
- Defer vending automation until "after the cleanup."
- Promise finance a reliable report next quarter.
The Pilot: The Rename Programme Works Perfectly
On paper, a naming pass and a tag reminder will fix the board pack. By Thursday the worst names look tidy. prod-lending-final-v2 is now prod-lending. The contractor’s subscription has an owner of record. Aroha has not opened Cost Management yet.
The inherited estate does not yield to a Friday cleanup. Renaming a box does not split the sandbox that still lives inside it.
The rename programme closed its tickets. The boundaries did not move.
- The worst display names are standardised.
- Tags are requested, not enforced.
- Shared Dev still holds forty resource groups.
- The board pack is tomorrow morning.
The Boundary Nobody Chose
The debate starts again in the platform channel: per application? Per environment? Per team? Per cost centre? Per compliance zone? Nobody had written the answer down before the first subscription existed, including the ones that predated the landing zone.
Board Pack Day: Finance Opens Cost Management
Friday. Aroha opens Cost Management with the auditor’s follow-up questions still in the thread. She finds:
prod-lending-final-v2andprod-lending-final-v3(the rename missed one)- A shared Dev subscription holding forty unrelated resource groups
- A subscription still owned by a contractor who left in 2023
- Tags that match nobody’s chart of accounts
The pack goes to the board with a footnote: cost attribution partial. Tui’s list of subscriptions that process personal information is a hallway guess.
Post-Sprawl: The Cracks Widen
The names look tidier. Then the first real cost conversation begins, and the cracks widen.
Cost Issues
SELL! runs lean. An unattributable slice of cloud spend triggers real conversations. Subscription boundaries are the primary cost isolation mechanism; tags are secondary and weaker.
Compliance Issues
Credit information under the Privacy Act 2020 and the Credit Reporting Privacy Code, plus NZISM scoped agency work, needs clear edges. Mixing regulated and non-regulated workloads in one subscription makes every control apply to everything, and gives auditors a reason to scope more, not less.
Blast Radius Issues
Quota and blast radius matter even at SELL!‘s scale. Last month a rogue load test in the shared Dev subscription exhausted the region’s vCPU quota and blocked a production scale-out on the lending app. Subscription-level separation would have contained that. Concentrating workloads in Azure New Zealand North is still rational. Sharing a quota envelope with a sandbox is not.
| Symptom | What to do instead |
|---|---|
| Teams improvise names and boundaries until you have sprawl, shared environments with no cost attribution, and years of unwind. | Define isolation around blast radius, compliance, billing, and quota. Document it, automate
subscription vending, and enforce tagging against the finance codes the business actually uses. References: Why Landing Zones Fail · CAF: Subscription design · CAF: Subscription vending · WAF: Reliability |
The Lessons We Can Learn
Do not try to satisfy every axis. Choose primary boundaries and use other mechanisms for the rest.
Primary: compliance and regulatory scope. Separate subscriptions where the regulatory treatment differs: NZISM scoped agency work versus commercial, personal or credit information processing versus not.
Secondary: cost accountability. If two workloads have different owners of the money, they generally belong in different subscriptions. Budgets and chargeback become correct instead of tag archaeology.
Not boundaries by default: environments, and subscriptions created because a team asked nicely. Environments within an application often sit under management group, RBAC, and resource groups. Do not vend a subscription because someone wanted their own box. Exception: when a regulated environment must be technically isolated from a non-regulated one.
Unwind the Inherited Estate
Renaming prod-lending-final-v2 does not fix that it still shares a subscription with a sandbox. For a lean NZ organisation the unwind is attrition, not a twenty subscription migration. Vend new work onto the documented boundaries. Sunset the inherited subscriptions as workloads move. Lift anything that processes personal or credit information out of a shared box first. That is the only in-place move worth the capacity.
Operations: The Missing Vending Pipeline
Once the strategy is documented, automate it:
- A vending pipeline that takes app name, owner, environment, data classification, and budget, then places the subscription in the right management group with the right policies and tags
- A request form that asks whether personal or credit information will be processed, because that question determines placement
- Naming and tagging standards enforced by policy, aligned to cost centre and product codes finance already reports on
Cleanup first, automation later, is how the estate outruns the rename programme.
| Symptom | What to do instead |
|---|---|
| Cleanup first, automation later. The estate grows faster than the rename programme. | Stand up vending from the start. A two week build beats a six month retrofit onto years of inherited
drift, and NZ organisations rarely have six months of platform capacity to spare. References: CAF: Subscription vending · CAF: Platform automation and DevOps · WAF: Cost Optimisation |
| What they did | Should have done |
|---|---|
| Created subscriptions as projects arrived, with names that felt right at the time. | Published a one page strategy naming the primary isolation boundary before the first vend. |
| Relied on tags for cost attribution after the fact. | Aligned subscription ownership to money owners, then used tags as enrichment, not the source of truth. |
| Mixed credit information workloads with sandboxes in shared subscriptions. | Separated regulatory scopes so Privacy Act and NZISM evidence had a clean edge. |
| Deferred vending until after a manual cleanup. | Automated placement, policy, budget, and tags at request time. |
The Moral
Subscriptions are cheap. Wrong boundaries are expensive. SELL! treated subscription creation as a chore, then discovered it was the billing system, the compliance boundary, and the blast radius control in one.
The test: could finance, unaided, produce an accurate cloud cost breakdown by business unit today? Could your auditor list which subscriptions process personal or credit information? If either answer is no, the strategy is undefined, whatever the diagram says.
A one page strategy and a two week vending build are a fractional deliverable. See Fractional Cloud Architecture and Advisory.
One Block · build from here