Skip to content
/consulting · the practice

Senior cloud architecture.
Delivered by the architect, not a bench.

The consultancy came first — and it still funds the studio. We run privileged-access, governance, and agent-readiness engagements for regulated teams. Azure is the certified specialty; AWS and GCP are delivered in practice; hybrid is on the table. No junior layer, no procurement gauntlet, no findings you can’t act on.

in production since 2019 · founder-led · senior-only · multi-cloud

engagements

Two practices. One senior architect.

Privileged access, governance, and agent-readiness is the specialty — the work the practice leads with and writes about. Cloud build and transformation is the range behind it: migrations, greenfield estates, data platforms, and AI systems, proven across regulated Fortune 500s. Every engagement is scoped to a deliverable your team can execute — not a slide deck.

Select an engagement to see the deliverables, shape, and who it’s for.

Access, governance & agent-readiness

Cloud build & transformation

Ongoing

ENG-01

Cloud governance & landing-zone review

Your landing zones, RBAC, and policy-as-code assessed against the baseline you are actually held to — regulated or self-imposed.

You leave with

  • Gap analysis against your control baseline (CIS, NIST, or your own policy set)
  • A prioritized remediation backlog engineering can pick up the same week
  • An IaC-ready policy set — not a PDF that rots in a drive

Shape

2–4 weeks · fixed scope

Best for

Teams inheriting sprawl, prepping for an audit, or standing up a new landing zone.

Scope this engagement

ENG-02

Privileged-access migration

Retire standing admin. We move you to time-bounded, witnessed, per-scope access. Break-glass is designed in, and you leave with a cutover plan your team runs without us in the room.

You leave with

  • A current-state access map: who holds what, and what nobody can justify
  • A target just-in-time access model with break-glass designed in
  • A cutover plan your team runs without us in the room

Shape

4–8 week sprint

Best for

Orgs carrying permanent Owner / Contributor grants that will not survive the next access review.

Scope this engagement

ENG-03

Agent-readiness assessment

Before you let agents touch production: the identity model, the blast-radius containment, and the cascade-revocation design that keep one bad loadout from becoming an incident.

You leave with

  • A non-human identity model — agents as first-class principals, never shared service accounts
  • Containment boundaries and a documented blast radius per capability
  • A revocation runbook that fires in seconds, not tickets

Shape

1–2 weeks

Best for

Teams putting AI agents anywhere near infrastructure, CI/CD, or the control plane.

Scope this engagement

ENG-04

On-prem to cloud migration

Lift, refactor, or rebuild — a migration grounded in what actually runs on-prem, not a vendor’s happy path. Hyper-V and VMware estates moved to Azure or AWS with co-existence designed in, not assumed away.

You leave with

  • A discovery and dependency map: what moves, what refactors, what retires
  • A wave plan with co-existence and rollback designed in, sequenced by risk
  • Landing zones and IaC to receive the workloads — not a hand-run portal migration

Shape

6–12 weeks · wave-based

Best for

Teams carrying Hyper-V / VMware or legacy datacenter workloads that have to reach the cloud without a big-bang cutover.

Scope this engagement

ENG-05

Cloud Adoption & Well-Architected alignment

Your estate assessed against the framework you are measured by — Azure’s Cloud Adoption Framework or the AWS Well-Architected Framework — with the gaps turned into an IaC-ready remediation plan, not a scorecard.

You leave with

  • A CAF / WAF assessment across the pillars — operations, security, cost, reliability, performance
  • A remediation roadmap mapped to the framework, ranked by risk and effort
  • Reference landing-zone modules and policy-as-code that encode the target state

Shape

3–5 weeks

Best for

Orgs standardizing on CAF or WAF for an audit, a cloud mandate, or their own governance bar.

Scope this engagement

ENG-06

Greenfield cloud enablement

A new cloud estate stood up right the first time — landing zones, identity, network, and guardrails in code — so the platform team inherits a foundation, not a cleanup job.

You leave with

  • A landing-zone architecture in Terraform — management groups, subscriptions/accounts, network, identity
  • Policy-as-code guardrails and a self-service consumption model from day one
  • Runbooks and enablement so your team operates it without us

Shape

4–10 weeks

Best for

Teams starting cloud from zero, or standing up a new tenant / account structure alongside an existing one.

Scope this engagement

ENG-07

Customer data platform build

The data platform behind the product — ingestion, storage, and governance — architected for scale and for the compliance regime the data actually lives under. Built in code, on Azure or AWS.

You leave with

  • A platform architecture: ingestion, lakehouse / warehouse, and serving layers
  • Access, lineage, and governance designed for the data’s compliance regime
  • IaC and CI/CD so the platform ships and evolves as code

Shape

8–16 weeks

Best for

Product and data teams building or replatforming a customer data platform under real scale or compliance pressure.

Scope this engagement

ENG-08

AI & RAG system build

A retrieval-augmented generation system taken from prototype to production — the retrieval, the guardrails, and the identity and blast-radius model — so an LLM feature ships without becoming an incident or a data leak.

You leave with

  • A RAG architecture — ingestion, embeddings, retrieval, and evaluation — grounded on your data
  • Identity, access, and blast-radius design for the model’s or agent’s privileges
  • A deployment and eval pipeline so quality and cost are measured, not guessed

Shape

4–10 weeks

Best for

Teams putting an LLM or RAG feature into production and needing it secure, grounded, and governable.

Scope this engagement

ENG-09

Fractional cloud architect

Senior architecture on call — design reviews, hard decisions, and the escalations a platform team hits before it can justify a full-time principal.

You leave with

  • A standing architecture review cadence
  • Written decision records — the reasoning, not just the verdict
  • On-call for design calls and vendor / migration decisions

Shape

Monthly retainer · capped hours

Best for

Platform teams without a senior architect in the seat, who need one more often than never but less than always.

Scope this engagement

selected engagements

Done under NDA. Described anyway.

Client names stay out of the marketing; sectors and scope don’t. A sample of the practice’s work since 2019, anonymized to the industry level — specifics come out in conversation, references on request.

A national mortgage-servicing platform

Azure enterprise rebuilt to a zero-trust baseline — every resource deployed through Terraform and Azure DevOps pipelines, nothing by hand in the portal. PCI-DSS aligned, with the architecture documentation written to be read by auditors and C-level stakeholders, not just engineers.

ENG-01ENG-02ENG-04

A top-10 US insurance brokerage, mid-acquisition

Identity and privileged-access governance while the enterprise refactored to meet acquisition requirements: Entra ID operations driven through Graph API — stale-account cleanup, MFA enforcement — Defender policy remediation as policy-as-code, and Azure PIM administration.

ENG-02

A US defense prime

Azure commercial and GCC High, multi-tenant and multi-subscription, under NIST compliance controls. Designed a self-service cloud consumption model integrated with ServiceNow to replace manual provisioning.

ENG-01ENG-05

A major US health system

Cloud Adoption Framework alignment with Azure Policy and Blueprints customized to HIPAA / HITRUST. Left behind a repository of repeatable Terraform landing-zone modules — and an OpenShift-on-Azure proof of concept automated end to end.

ENG-05ENG-06

A Big Four professional-services firm

Led the AWS-to-Azure migration of a customer data platform: AKS with Windows and Linux node pools, container registry behind private endpoints, Terraform and Terragrunt, GitHub Actions CI/CD — landed in a spoke landing-zone topology.

ENG-04ENG-07

A US state motor-vehicle agency

Greenfield Azure enablement aligned to the Cloud Adoption Framework — the enterprise stood up in Terraform, Sentinel deployed as code with playbooks and automation rules, and 100/200-level workshops that left the agency’s own leads running it.

ENG-05ENG-06ENG-09

Before the practice: senior consultant at Microsoft itself (2016–2018), and a decade of enterprise infrastructure before that — from United States Senate operations to Fortune 500 estates across banking, logistics, and government.

where we work

Azure-certified. Multi-cloud in practice.

The specialty is Azure and the certifications are current. But privileged access, governance, and agent-readiness are the same discipline on every control plane — so the work carries across.

Azure

certified specialty

The deepest bench. AZ-104 / AZ-400 / AZ-500 / AI-102, in production since 2019. ARM, Entra ID, AKS, policy-as-code, landing zones.

AWS

delivered in practice

IAM, Organizations, and multi-account landing zones. Privileged-access and governance patterns carried across from the Azure work.

GCP

delivered in practice

IAM, the resource hierarchy, and org-policy guardrails. The same access discipline, a different control plane.

Hybrid

cloud + on-prem

On-prem Hyper-V and VMware alongside cloud — real migration and co-existence experience across regulated estates.

how we work

The way the work actually runs.

Scope honesty

We quote what we will do, not what we hope to. The estimate is the ceiling, not the pitch — and fixed-scope wherever the work allows it.

Senior-only, no junior layer

The architect who scopes the work is the architect who delivers it. You are not funding someone else’s training on your production tenant.

Receipts, not decks

You leave with artifacts engineering can execute — maps, backlogs, IaC, runbooks — not a slide deck and an invoice.

the thinking

The patterns come from the work. The writing shows the reasoning.

The durable privileged-access patterns come out of engagements, one at a time — and we write them up. If you want to see how we think about agent-native privileged access before you talk to us, start with the essay.

Bring in senior architecture without the headcount.

A scoped engagement, founder-led, with artifacts your team can execute. The founder reads every email.