Skip to content
Aviato Consulting
Cloud Foundations

The landing zone every later workload inherits.

Org hierarchy, identity, policy and guardrails on Google Cloud, built once and properly, all in Terraform in your repositories. Fixed price, with a fixed date agreed at scoping.

Straight to a senior GCP architect. No SDR, no slide deck.

Who it is for

A good fit if

  • You are starting on Google Cloud, or moving onto it, and want the base right before workloads land.
  • You already run on Google Cloud but projects were created by hand and nobody is sure what the policies are.
  • You need an environment you can show an auditor or a security team.

Probably not a fit if

  • You need a single project for a proof of concept. A landing zone is more than that needs.
What you get

Deliverables, not effort.

The base module covers the organisation, identity and policy layer. Networking and VPC Service Controls are separate modules, priced below.

01

Organisation hierarchy

Folders, projects and environments structured around how your teams and workloads are actually organised, with naming and labelling conventions.

02

Identity and access

Federation with your identity provider, groups mapped to roles, and break glass access documented and tested.

03

Organisation policy and guardrails

Organisation policies that stop the common misconfigurations before they happen, applied at the right level of the hierarchy.

04

Logging and audit

Central audit and log sinks, with retention set to what you need to keep.

05

Billing and cost visibility

Billing export, budgets and alerts, with costs attributable to the team or workload that incurs them.

06

Terraform and a pipeline

Every piece in Terraform in your repositories, with a deployment pipeline, so the next change goes through review rather than the console.

Pricing

Pay for the modules you need.

Foundations

Always included

Organisation hierarchy, identity, policy and guardrails, logging, billing and the Terraform pipeline.

A$45,000

Networking

Optional

Shared VPC, subnets and firewall policy, Cloud NAT and private access, and connectivity to on premises or other clouds over VPN or Interconnect.

+ A$25,000

VPC Service Controls

Optional

Service perimeters around sensitive data services, run in dry run mode first so nothing legitimate breaks when they are enforced.

+ A$20,000

Floors for scoping, not a quote. The price for your organisation is fixed in writing at scoping.

How it runs

No surprises on the way.

The date is fixed at scoping, once we know the hierarchy and modules involved.

  1. Scoping

    Decisions and a date

    We work through the design decisions with you, confirm the modules, and fix the price and the delivery date in writing.

  2. Design

    A written design

    A short design record covering the hierarchy, identity, policy and any network choices, reviewed with your team before anything is built.

  3. Build

    Built in your repositories

    We build in Terraform in your repositories and your organisation, with your engineers able to review every change as it lands.

  4. Handover

    Your team runs it

    A walkthrough with the engineers who will own it, and documentation for adding the next project, team or environment.

Not included

  • Migrating or deploying workloads into the landing zone. See the migration offer for that.
  • Ongoing operation after handover.
  • Google Cloud usage, Interconnect circuits and third party licences.

What we need from you

  • An owner with authority over the Google Cloud organisation and billing account.
  • Administrator access to your identity provider for federation.
  • Time from security and networking contacts during design.
FAQ

Questions we get asked

We already have projects on Google Cloud. Can you work with that?

Yes. Scoping covers what exists today and how it moves into the new hierarchy. Moving existing projects is planned so running workloads are not interrupted.

Why is the date set at scoping rather than published?

The date depends on the modules, the size of the hierarchy and how quickly identity and network decisions can be made on your side. We fix it in writing once we know those, and hold to it.

Do we need the networking module?

If your workloads need private networking, shared VPCs or connectivity back to an office, data centre or another cloud, yes. Serverless workloads with no private connectivity often do not.

Does it meet our compliance requirements?

Tell us at scoping which framework you report against, for example APRA CPS 234 or ISO 27001, and the design will reference the relevant controls. The landing zone supports compliance; it does not replace your own assessment.

Other engagements

Fixed price, fixed date, before you sign.

Prices are set in AUD; other currencies are fixed conversions as at 15 September 2026, shown for guidance, with the contracted currency confirmed before you sign.

Fixed price, fixed date

Talk to an architect who has done this before.

Bring your current setup and the outcome you need. You will get a view on the approach, the risks and roughly what it costs.

Book a 20-min architecture call

Straight to a senior GCP architect. No SDR, no slide deck.

Not ready to talk? See how we migrated Hapana off AWS →

Or call +61 2 8359 9507 · Hello@aviato.consulting

Call us Book a call