Skip to main content

What you receive

You receive four things: the Baseline's Git repository customized for your organization, the documentation to run it, a complete multi-account AWS environment deployed into your accounts by the BuiltForProd team, and a handover after which your engineers own and change all of it. Blueprints, if you buy them, arrive the same way.

How delivery works

The Baseline is customized from BuiltForProd's base repositories, deployed directly into your AWS accounts by BuiltForProd engineers, and handed over ready for your teams to deploy workloads or customize further. The work is fully executed by BuiltForProd in every deployment tier.

The repositories

The core deliverable is the landing-zone repository, acme-aws-platform-baseline in the sample naming, where acme becomes your organization's abbreviation. It holds the whole foundation as code:

PartWhat it contains
Deployment treeOne folder per OU, account and region (or global), each with a stack file that lists the units deployed there
Unit definitionsOne definition per unit type, shared by every account that lists it
ModulesThe reusable building blocks, custom where needed and pinned community modules where they fit
Address planTwo VPC maps, one active; the only place IP ranges are defined
GuardrailsScripts that pre-commit and CI run before any plan
WorkflowsPlan, apply and drift detection for GitHub Actions, plus code-owner rules

Every value your deployment must set (namespace, domain, account email addresses, GitHub organization, SSO groups, CI secrets) is marked in the code with a TODO: comment, and every optional choice (feature switches, compliance packs, cost-bearing options) with an @optional: comment. Nothing deployment-specific is hidden in logic.

With the Full Deployment tier you also receive two blueprints, each as its own repositories: the Web App Blueprint (infrastructure, application code and GitOps repositories), the Data and ETL Blueprint (infrastructure and code repositories) or the Secrets Blueprint (one repository).

The documentation

The handover includes architecture decision records, how-to guides, troubleshooting manuals, FAQs and scaling guidance. In practice that is this documentation set, which covers the Baseline's architecture, accounts, security, networking, compliance, delivery pipelines and day-2 operation, plus the Platform documentation for the concepts behind it. Sign-in unlocks the full set for your organization, and pages show your own values (namespace, domain, account IDs) in place of the samples.

The deployed environment

When BuiltForProd finishes, your AWS Organization runs:

  • 14 accounts: a management account plus nine core accounts and four workload accounts (sandbox, dev, staging, prod), each with the account baseline applied.
  • The hub-and-spoke network: hub VPC with centralized NAT, Transit Gateway with isolation domains, IPAM, four spoke VPCs, private DNS and public DNS zones.
  • Security and compliance: SCPs and the tag policy, the organization CloudTrail, AWS Config with the SOC 2 baseline pack, GuardDuty, Security Hub, IAM Access Analyzer, Firewall Manager with a baseline WAF policy, automated remediation and the CIS alarms.
  • Identity: IAM Identity Center permission sets assigned to your groups.
  • Delivery: GitHub OIDC federation and deployer roles, the state bucket, and the three workflows in your GitHub organization.

Paid options such as Network Firewall, Shield Advanced, Inspector, Macie and the Client VPN endpoint are built into the code and switched on when your deployment needs them. The architecture overview shows how the pieces connect.

The handover

At handover you own the repositories and the environment. Changes go through pull requests: CI plans them, code owners approve changes to the organization, network and guardrails, and merging applies them. Console changes are reported as drift.

The repositories are licensed under the PolyForm Internal Use License. You may deploy, manage and scale your internal AWS infrastructure with the code, modify it, and share it with employees and contractors working for your organization. You may not resell or sub-license it, host it in a public repository, use it to provide managed services to third parties, or remove its notices. The full terms are summarized under purchasing and licensing.

Deployment tiers

TierWhat it includes
Standard DeploymentThe Baseline: the multi-account environment set up by BuiltForProd, the customized repositories and the documentation
Full Deployment with BlueprintsEverything in Standard, plus any two blueprints deployed and working
Blueprint DeploymentFor customers who already run the Baseline: additional blueprints deployed by BuiltForProd

Ongoing help after handover is a separate, optional service, BuiltForProd Managed, with on-demand, SLA-backed and team-augmentation tiers.