VeUP
← All case studies
Production Engagement · Anonymized
A 45-finding six-pillar Well-Architected Review charts the AWS hardening roadmap for an AI workforce platform
Software & Internet (SaaS — frontline-workforce enablement across hospitality, manufacturing, real estate, healthcare, food services)
AWS IAM Identity CenterAmazon GuardDutyAWS Security HubAWS Compute Optimizer
AWS Well-Architected Service Delivery · Six-Pillar Well-Architected Review

An AI-powered frontline-workforce enablement platform

AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)

VeUP delivered the customer a full six-pillar AWS Well-Architected Review of its live environment, with 45 severity-ranked findings (26 high-risk / 19 medium-risk) and a target-state roadmap spanning identity, org-wide audit and threat detection, observability, multi-AZ + tiered DR, and a FinOps cadence flagging a 20–30% savings opportunity.

The challenge

the customer platform was live and growing across multiple industries, but the team needed an independent, rigorous read on whether its AWS foundation could carry that growth safely. They wanted more than a security spot-check — a full, all-pillar assessment that would surface the real risks, rank them by severity, and turn them into a sequenced plan of work. For a platform handling frontline-workforce data across regulated and operationally demanding industries, the priorities were provable identity and access controls, organization-wide audit and threat detection, observability that could explain an incident, and a disaster-recovery posture with defined recovery objectives.

The solution

A full AWS Well-Architected Review (WAR) across all six pillars — Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability — producing a prioritized findings overview with a severity heat-map and a remediation roadmap. Target state: identity and access via AWS IAM Identity Center with organization-wide MFA enforcement; audit and threat detection via organization-level AWS CloudTrail, Amazon GuardDuty, and AWS Security Hub, plus AWS KMS encryption by default; observability via AWS X-Ray / OpenTelemetry distributed tracing, SLO-based alerting, and AWS Systems Manager Incident Manager response playbooks; operational hygiene via AWS Systems Manager Patch Manager and Amazon ECR image scanning; resilience via multi-AZ deployment plus tiered disaster recovery (pilot-light / warm-standby) with documented RTO and RPO; and cost governance via a FinOps cadence on AWS Budgets, AWS Cost Anomaly Detection, and AWS Compute Optimizer right-sizing targeting a 20–30% savings opportunity.

Production outcomes

KPIResult
Production outcomesA complete six-pillar Well-Architected Review against the customer live AWS environment; 45 findings identified and ranked by severity — 26 high-risk and 19 medium-risk — distributed across the pillars (Reliability 11, Operational Excellence 10, Security 10, Cost Optimization 9, Sustainability 4, Performance Efficiency 1), giving the customer an evidence-based order of operations; and a target-state remediation roadmap spanning identity, audit, observability, resilience, and cost governance — turning the findings into a concrete hardening program with a 20–30% cost-savings opportunity flagged for the FinOps cadence. Finding split cross-verified against the WAR review record.
Engagement window2024-09-18 (Resell Customer Live); six-pillar WAR delivered July 2025 → Six-pillar WAR + 45-finding heat-map + target-state remediation roadmap delivered (July 2025); ongoing
Cost / TCO postureThe Cost Optimization pillar flagged a 20–30% savings opportunity, routed into an ongoing FinOps cadence (AWS Budgets, Cost Anomaly Detection, Compute Optimizer right-sizing). ~$103,584/yr AWS spend (~$8,632/mo) at review time. The 20–30% range is the opportunity identified by the review, not a measured realized saving.
Lessons & continuationA full six-pillar WAR with a severity heat-map turns a vague "are we secure?" into an evidence-based order of operations — 45 ranked findings give the customer a defensible sequence rather than a flat checklist. The cost-savings range is an identified opportunity until realized; the roadmap routes it into a standing FinOps cadence so it can be measured.
AWS services in production

AWS IAM Identity Center · AWS CloudTrail · Amazon GuardDuty · AWS Security Hub · AWS KMS · AWS X-Ray / OpenTelemetry · AWS Systems Manager Incident Manager · Amazon ECR · AWS Budgets · AWS Compute Optimizer · AWS Well-Architected Tool

Architecture

The six-pillar Well-Architected Review's target-state architecture: a multi-account AWS Control Tower landing zone with org-wide identity, detective controls, encryption-by-default, multi-AZ resilience with tiered DR, and a FinOps cadence — annotated against all six WAFR pillars.

Previous-state architecture: multi-account AWS estate with per-account local IAM, inconsistent Security Group / NACL segmentation, unencrypted-storage gaps, no org-wide CloudTrail / GuardDuty / Security Hub, no documented multi-AZ or DR, and uncontrolled spend prior to the six-pillar Well-Architected Review.
Previous state — the live multi-account AWS estate assessed by the six-pillar Well-Architected Review, before remediation.
Target-state AWS architecture: AWS Control Tower landing zone with AWS Organizations SCPs, IAM Identity Center + org-wide MFA, org-level CloudTrail/GuardDuty/Security Hub/Config, multi-AZ VPC with KMS-encrypted RDS/Aurora, S3, and EBS, Route 53 + AWS Backup tiered DR, CloudWatch/X-Ray/OpenTelemetry observability, Systems Manager Incident Manager, and Budgets/Cost Anomaly Detection/Compute Optimizer FinOps.
Target state on AWS — the WAR remediation architecture across network foundation, compute/application, data, security/observability, and data-path layers.
Animated layer-by-layer build-up of the target-state AWS architecture: network foundation, compute and application, data, security and observability, then the numbered data and network paths.
Layer-by-layer build-up — network foundation, compute/application, data, security/observability, and data & network paths.
WAFR-annotated architecture diagram: previous-state multi-account AWS estate with per-account IAM, no org-wide CloudTrail/GuardDuty/Security Hub, and no documented DR, migrating to a target-state AWS Control Tower landing zone with AWS Organizations SCPs, IAM Identity Center + org-wide MFA, org-level CloudTrail/GuardDuty/Security Hub/Config, multi-AZ VPC with KMS-encrypted RDS/Aurora, S3, and EBS, Route 53 + AWS Backup tiered DR, CloudWatch/X-Ray/OpenTelemetry observability, Systems Manager Incident Manager, and Budgets/Cost Anomaly Detection/Compute Optimizer FinOps — with all six Well-Architected pillars annotated against the 45 findings.
Full Well-Architected overview — previous state vs. Control Tower target state, VeUP-rendered from the six-pillar Well-Architected Review.