14 accounts, 2 OUs, 3 SCPs
- A management account, 9 core accounts (security, audit, identity, network, dns, artifacts, auto, corp, public) and 4 identical workload accounts (sandbox, dev, staging, prod) from one template
- Three service control policies: no IAM users or access keys, allowed regions only, and audit logging that cannot be stopped or deleted
- A tag policy with six required tags, report-only by default and enforced with one flag
- A new account is a map entry and a folder — two pull requests