VeUP
← All case studies
Cloud Operations Competency · Six-Pillar Well-Architected Review
An AI-powered frontline-workforce enablement platformIdentity protected

Workforce platform: a 45-finding six-pillar WAR charts its AWS roadmap

Well-Architected ReviewAdvisoryHigh-risk-issue remediation roadmapResilience-gap assessment (RTO/RPO)Observability-gap assessmentCost-optimization deep diveTarget-state architecture design & costed POCManaged billing & resellCommitment & RI optimizationStanding cost-optimization mechanism
45
risks ranked by severity — an evidence-based order of operations
20–30%
cost-savings opportunity routed into a FinOps cadence
6/6
pillars of the live environment assessed
AWS IAM Identity CenterAmazon GuardDutyAWS Security HubAWS Compute Optimizer

Shared anonymously — the customer’s name is held by VeUP and available on request.

VeUP ran a full six-pillar AWS Well-Architected Review of the customer’s live environment, surfacing 45 severity-ranked findings (26 high-risk / 19 medium-risk) and a target-state roadmap spanning identity, org-wide audit and threat detection, observability, multi-AZ + tiered DR, and a FinOps cadence flagging a 20–30% savings opportunity.

The challenge

The platform was live and growing across multiple industries, but the team needed an independent, rigorous read on whether its AWS foundation could carry that growth safely. They wanted more than a security spot-check — a full, all-pillar assessment that would surface the real risks, rank them by severity, and turn them into a sequenced plan of work. For a platform handling frontline-workforce data across regulated and operationally demanding industries, the priorities were provable identity and access controls, organization-wide audit and threat detection, observability that could explain an incident, and a disaster-recovery posture with defined recovery objectives.

The solution

A full AWS Well-Architected Review (WAR) across all six pillars — Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability — producing a prioritized findings overview with a severity heat-map and a remediation roadmap. Target state: identity and access via AWS IAM Identity Center with organization-wide MFA enforcement; audit and threat detection via organization-level AWS CloudTrail, Amazon GuardDuty, and AWS Security Hub, plus AWS KMS encryption by default; observability via AWS X-Ray / OpenTelemetry distributed tracing, SLO-based alerting, and AWS Systems Manager Incident Manager response playbooks; operational hygiene via AWS Systems Manager Patch Manager and Amazon ECR image scanning; resilience via multi-AZ deployment plus tiered disaster recovery (pilot-light / warm-standby) with defined RTO and RPO; and cost governance via a FinOps cadence on AWS Budgets, AWS Cost Anomaly Detection, and AWS Compute Optimizer right-sizing targeting a 20–30% savings opportunity.

Production outcomes

KPIResult
Production outcomesA complete six-pillar Well-Architected Review of the customer’s live AWS environment; 45 findings identified and ranked by severity — 26 high-risk and 19 medium-risk — distributed across the pillars (Reliability 11, Operational Excellence 10, Security 10, Cost Optimization 9, Sustainability 4, Performance Efficiency 1), giving the customer an evidence-based order of operations; and a target-state remediation roadmap spanning identity, audit, observability, resilience, and cost governance — turning the findings into a concrete hardening program with a 20–30% cost-savings opportunity flagged for the FinOps cadence.
Engagement windowThe platform has run live on AWS since September 2024. The six-pillar review, its 45-finding heat-map, and the target-state remediation roadmap were delivered in July 2025, and the engagement continues.
Cost / TCO postureThe Cost Optimization pillar flagged a 20–30% savings opportunity, routed into an ongoing FinOps cadence (AWS Budgets, Cost Anomaly Detection, Compute Optimizer right-sizing). The 20–30% is the opportunity the review identified, not yet a measured saving — the cadence exists to realize and measure it.
Lessons & continuationA full six-pillar WAR with a severity heat-map turns a vague "are we secure?" into an evidence-based order of operations — 45 ranked findings give the customer a defensible sequence rather than a flat checklist. The cost-savings range is an identified opportunity until realized; the roadmap routes it into a standing FinOps cadence so it can be measured.
AWS services in production
AWS IAM Identity CenterAWS CloudTrailAmazon GuardDutyAWS Security HubAWS KMSAWS X-RayAWS Systems Manager Incident ManagerAmazon ECRAWS BudgetsAWS Compute OptimizerAWS Well-Architected Tool
Delivered with
OpenTelemetry

Architecture

Target-state AWS architecture: AWS Control Tower landing zone with AWS Organizations SCPs, IAM Identity Center + org-wide MFA, org-level CloudTrail/GuardDuty/Security Hub/Config, multi-AZ VPC with KMS-encrypted RDS/Aurora, S3, and EBS, Route 53 + AWS Backup tiered DR, CloudWatch/X-Ray/OpenTelemetry observability, Systems Manager Incident Manager, and Budgets/Cost Anomaly Detection/Compute Optimizer FinOps.
The target state the Well-Architected Review charted — a multi-account AWS Control Tower landing zone with org-wide identity, detective controls, encryption by default, multi-AZ resilience with tiered DR, and a standing FinOps cadence.

Where it started

Assessed baseline · Well-Architected ReviewWorkforce-engagement SaaS · Live multi-account AWS estate · reviewed July 2025
Starting point
A live three-account estate

Production, staging, and shared-services accounts running a frontline-workforce SaaS — live throughout the review and remediation.

Gap
Identity was per-account

Local IAM users in each account with no centralized federated identity — pre–IAM Identity Center.

Gap
Inconsistent network segmentation

Security Group and NACL patterns varied across accounts, with unencrypted-storage gaps flagged by the Security pillar.

Gap
No org-wide detection

No organization-wide CloudTrail, GuardDuty, or Security Hub — visibility stopped at each account boundary.

Constraint
Single-AZ, undefined recovery

Application workloads ran single-AZ with no multi-AZ or DR posture and no RTO/RPO targets — the Reliability pillar's highest finding count.

The baseline as assessed by the six-pillar AWS Well-Architected Review — 45 findings (26 high, 19 medium) surfaced by the first full review.

What the review surfaced, pillar by pillar:

Operational Excellence
  • 10 findings
  • CloudWatch and X-Ray tracing, Incident Manager playbooks
  • IaC-provisioned guardrails, reviewed before production
Security
  • 10 findings
  • IAM Identity Center with org-wide MFA
  • Org-level CloudTrail, GuardDuty, Security Hub
  • KMS encryption by default across the data plane
Reliability
  • 11 findings — the largest concentration
  • Multi-AZ plus tiered DR: pilot-light, warm-standby
  • Defined RTO/RPO recovery path
Performance Efficiency
  • 1 finding — the smallest pillar
  • Compute Optimizer right-sizing feeds the efficiency review
Cost Optimization
  • 9 findings
  • FinOps cadence: Budgets, Cost Anomaly Detection, Compute Optimizer
  • 20–30% savings opportunity identified
Sustainability
  • 4 findings
  • Right-sizing and account-factory consistency cut redundant footprint