ENG-01
Cloud governance & landing-zone review
Your landing zones, RBAC, and policy-as-code assessed against the baseline you are actually held to — regulated or self-imposed.
You leave with
- + Gap analysis against your control baseline (CIS, NIST, or your own policy set)
- + A prioritized remediation backlog engineering can pick up the same week
- + An IaC-ready policy set — not a PDF that rots in a drive
Shape
2–4 weeks · fixed scope
Best for
Teams inheriting sprawl, prepping for an audit, or standing up a new landing zone.
Scope this engagement → ENG-02
Privileged-access migration
Retire standing admin. We move you to time-bounded, witnessed, per-scope access. Break-glass is designed in, and you leave with a cutover plan your team runs without us in the room.
You leave with
- + A current-state access map: who holds what, and what nobody can justify
- + A target just-in-time access model with break-glass designed in
- + A cutover plan your team runs without us in the room
Best for
Orgs carrying permanent Owner / Contributor grants that will not survive the next access review.
Scope this engagement → ENG-03
Agent-readiness assessment
Before you let agents touch production: the identity model, the blast-radius containment, and the cascade-revocation design that keep one bad loadout from becoming an incident.
You leave with
- + A non-human identity model — agents as first-class principals, never shared service accounts
- + Containment boundaries and a documented blast radius per capability
- + A revocation runbook that fires in seconds, not tickets
Best for
Teams putting AI agents anywhere near infrastructure, CI/CD, or the control plane.
Scope this engagement → ENG-04
On-prem to cloud migration
Lift, refactor, or rebuild — a migration grounded in what actually runs on-prem, not a vendor’s happy path. Hyper-V and VMware estates moved to Azure or AWS with co-existence designed in, not assumed away.
You leave with
- + A discovery and dependency map: what moves, what refactors, what retires
- + A wave plan with co-existence and rollback designed in, sequenced by risk
- + Landing zones and IaC to receive the workloads — not a hand-run portal migration
Shape
6–12 weeks · wave-based
Best for
Teams carrying Hyper-V / VMware or legacy datacenter workloads that have to reach the cloud without a big-bang cutover.
Scope this engagement → ENG-05
Cloud Adoption & Well-Architected alignment
Your estate assessed against the framework you are measured by — Azure’s Cloud Adoption Framework or the AWS Well-Architected Framework — with the gaps turned into an IaC-ready remediation plan, not a scorecard.
You leave with
- + A CAF / WAF assessment across the pillars — operations, security, cost, reliability, performance
- + A remediation roadmap mapped to the framework, ranked by risk and effort
- + Reference landing-zone modules and policy-as-code that encode the target state
Best for
Orgs standardizing on CAF or WAF for an audit, a cloud mandate, or their own governance bar.
Scope this engagement → ENG-06
Greenfield cloud enablement
A new cloud estate stood up right the first time — landing zones, identity, network, and guardrails in code — so the platform team inherits a foundation, not a cleanup job.
You leave with
- + A landing-zone architecture in Terraform — management groups, subscriptions/accounts, network, identity
- + Policy-as-code guardrails and a self-service consumption model from day one
- + Runbooks and enablement so your team operates it without us
Best for
Teams starting cloud from zero, or standing up a new tenant / account structure alongside an existing one.
Scope this engagement → ENG-07
Customer data platform build
The data platform behind the product — ingestion, storage, and governance — architected for scale and for the compliance regime the data actually lives under. Built in code, on Azure or AWS.
You leave with
- + A platform architecture: ingestion, lakehouse / warehouse, and serving layers
- + Access, lineage, and governance designed for the data’s compliance regime
- + IaC and CI/CD so the platform ships and evolves as code
Best for
Product and data teams building or replatforming a customer data platform under real scale or compliance pressure.
Scope this engagement → ENG-08
AI & RAG system build
A retrieval-augmented generation system taken from prototype to production — the retrieval, the guardrails, and the identity and blast-radius model — so an LLM feature ships without becoming an incident or a data leak.
You leave with
- + A RAG architecture — ingestion, embeddings, retrieval, and evaluation — grounded on your data
- + Identity, access, and blast-radius design for the model’s or agent’s privileges
- + A deployment and eval pipeline so quality and cost are measured, not guessed
Best for
Teams putting an LLM or RAG feature into production and needing it secure, grounded, and governable.
Scope this engagement → ENG-09
Fractional cloud architect
Senior architecture on call — design reviews, hard decisions, and the escalations a platform team hits before it can justify a full-time principal.
You leave with
- + A standing architecture review cadence
- + Written decision records — the reasoning, not just the verdict
- + On-call for design calls and vendor / migration decisions
Shape
Monthly retainer · capped hours
Best for
Platform teams without a senior architect in the seat, who need one more often than never but less than always.
Scope this engagement →