Multi-account landing zone architecture

Separate accounts per environment, one org-wide audit trail, and archived logs.

AWSorganizationscloudtrailgovernanceaccounts
Organization rootManagement accountProduction workload…3 × 0.25 vCPU · 0.5 GBStaging workload0.25 vCPU · 0.5 GBOrg-wide trailfirst mgmt-event copyfree · S3 storageLog archive1 TB deep archive
5 nodes. Drawn by the same layout the product uses.
What is in it

Every resource, and what it costs.

Projections from August 2026 list prices for always-on resources. Connect an account and these become the figures your provider actually bills.

Resources in the Multi-account landing zone template with projected monthly cost.
NodeTypeWhat it isProjected
Organization rootExternalManagement accountno direct cost
Production workloads ×3Compute3 × 0.25 vCPU · 0.5 GB$27/mo
Staging workloadCompute0.25 vCPU · 0.5 GB$9.01/mo
Org-wide trailExternalfirst mgmt-event copy free · S3 storagefrom $2.00/mo
Log archiveStorage1 TB deep archivefrom $1.00/mo

Agent steps are priced from provider-reported token usage once the agent runs, not estimated. Guardrails cost nothing and are the reason a runaway agent cannot. 2 rows show from because those services bill by usage, so the total is a scenario at the stated volumes, not a quote.

Open Multi-account landing zone on the canvas.

It loads as an editable graph. Connect an account or instrument an agent and the projected figures above become measured ones.