The layer every project ran on
Four years building the foundation TrustSoft delivered all its cloud work from. Fifteen-plus enterprise estates, Partners Bank among them.
The problem
Every new client meant a fresh cloud estate — their whole cloud, end to end: accounts, permissions, security rules, audit trails. Done by hand each time, it took days and no two came out the same.
For a bank, "no two the same" is not an inconvenience. It is a finding in an audit.
What existed already
AWS Control Tower — Amazon's own product for governing many accounts at once. It was new then, and thin on the parts a firm running cloud for many clients actually needs.
I adopted and mastered Control Tower in its early releases, mapping out its architecture, operational constraints, and the missing layers needed for multi-client operations.
What I built on top of it
Every one of them set up the same way, because of the row above.
What changed
A new client estate went from a week of careful manual setup to repeatable provisioning in hours.
Average cloud infrastructure cost reduction across the estates I managed, through automated right-sizing and policy enforcement.
The layer became TrustSoft’s flagship product of that name. Every project they deliver still runs on it.
What did not go well
- Control Tower was new and thin, and I was an early adopter. A good share of the first year went into working around gaps in a product I did not control — utilities that a later release made unnecessary. That taught me early to build lightweight abstractions that gracefully make way for platform updates.
- The EPH dashboard: presented at their headquarters, liked, and never shipped there, because the decision to move to Azure had already been made above the people I was presenting to. TrustSoft kept the work and turned the prototype into a FinOps dashboard it went on to sell to other customers — so the lesson is not that it was wasted.
What it taught me
- The part that survives is the part other people depend on. The layer survived because every project ran on it; the dashboard survived only once it found customers who did.
- Write it down before you build the next thing. The documentation outlived several of the utilities it described — and it was the reason the standard was adopted company-wide instead of staying mine.
- Find out who is actually deciding before you build for the people in the room.
Where it went
I was in touch with AWS about Control Tower directly, sending back what running it at this scale actually taught us.
I later presented the governance approach in Switzerland.
And the layer outlived my time there: Silviu Cosma, TrustSoft’s Head of DevOps, wrote in his recommendation: “the backbone of our flagship product, Cloud Foundation … part of every single project we deliver.”
What it left me with
Inside a company, this made me the person people came to first on anything in that territory.
It is also why the multi-tenant side of Glow is familiar ground: many customers run from one place, with hard walls between them.