When one AWS account stops being a good idea
Separating production, security and development creates real boundaries for access, impact and cost.
Server count is not the signal
One account becomes limiting when permissions, billing and changes in one environment affect the others. Separate accounts reduce blast radius and allow distinct controls without unmaintainable IAM policies.
The minimum foundation
- A management account without business workloads.
- Separate production and non-production accounts.
- Centralized logging and security with restricted access.
- Identity Center, SCPs, backup and budgets applied from the organization.
A landing zone does not end at account creation
It also needs account vending, network baselines, roles, logs, detection, tagging and a path for teams to deploy. If a new account takes weeks, governance pushes teams outside the model.
Move in stages
Start with identity and organization, create foundational accounts and move workloads by risk. You do not need to stop everything or redesign every application at once.
Sources reviewed
This article is an original Nubent synthesis. The sources let you inspect the basis and explore each subject further.