Skip to main content

AWS Organization Structure

Last Updated: 2026-03-06 Source: AWS Organizations API via .state/discovered-accounts.json, .state/org-ous.json, .state/org-roots.json Captured SHA: N/A (live AWS state)

Executive Summary

The NDX:Try AWS infrastructure operates within a single AWS Organization (o-4g8nrlnr9s) managed by CDDO under the Department for Science, Innovation and Technology (DSIT). The organization contains 247 accounts (7 infrastructure + 240 sandbox pool), governed by AWS Control Tower and Landing Zone Accelerator v1.1.0. The OU hierarchy implements a standard landing zone pattern with a dedicated Innovation Sandbox OU containing a 7-stage account lifecycle pool. Account pool health is monitored via CloudWatch custom metrics published by the OU metrics stop-gap service.


Organization Overview

PropertyValue
Organization IDo-4g8nrlnr9s
Feature SetALL
Root IDr-2laj
Management Account955063685555 (gds-ndx-try-aws-org-management)
Management Emailndx-try-provider+gds-ndx-try-aws@dsit.gov.uk
Total Accounts247
Infrastructure Accounts7
Pool Accounts240

Enabled Policy Types

Policy TypeStatus
SERVICE_CONTROL_POLICYEnabled
RESOURCE_CONTROL_POLICYEnabled
TAG_POLICYEnabled
BACKUP_POLICYEnabled
AISERVICES_OPT_OUT_POLICYEnabled
DECLARATIVE_POLICY_EC2Enabled
S3_POLICYEnabled

Organization Hierarchy


Infrastructure Accounts

Account NameAccount IDEmailOUPurpose
gds-ndx-try-aws-org-management955063685555ndx-try-provider+gds-ndx-try-aws@dsit.gov.ukRootOrganization root, Control Tower, LZA pipeline
Audit406429476767ndx-try-provider+gds-ndx-try-aws-audit@dsit.gov.ukSecuritySecurity Hub, Config aggregation
LogArchive408585017257ndx-try-provider+gds-ndx-try-aws-log-archive@dsit.gov.ukSecurityCentralized CloudWatch/S3 log storage
Network365117797655ndx-try-provider+gds-ndx-try-aws-network@dsit.gov.ukInfrastructureTransit Gateway, Route 53, VPC routing
Perimeter297552146292ndx-try-provider+gds-ndx-try-aws-perimeter@dsit.gov.ukInfrastructureWAF, Shield, edge security
SharedServices803319930943ndx-try-provider+gds-ndx-try-aws-shared-services@dsit.gov.ukInfrastructureECR, shared tooling
InnovationSandboxHub568672915267ndx-try-provider+gds-ndx-try-aws-isb-hub@dsit.gov.ukWorkloads/ProdISB control plane

Pool Accounts (240 Total)

The sandbox pool contains 240 accounts. All accounts follow the email pattern ndx-try-provider+gds-ndx-try-aws-pool-NNN@dsit.gov.uk.

Pool Account Distribution by OU (Live State)

OUAccount CountStatus
Available189Ready to be leased
Active3Currently leased to users
Frozen0Budget/duration breach
CleanUp0Resources being destroyed
Quarantine46Cleanup failed / billing cooldown
Entry0Being initialized
Exit0Being removed

Account Lifecycle State Machine

Pool accounts move through a 7-stage lifecycle managed by ISB via OU placement:

OUOU IDPurposeSCP Behaviour
Entryou-2laj-2by9v0srNew accounts awaiting LZA initializationLZA quarantine SCP blocks all non-LZA actions
Availableou-2laj-oihxgbtrAccounts ready for lease assignmentWrite-protected (read-only)
Activeou-2laj-sre4rnjsAccounts with active leasesCost avoidance SCPs applied
CleanUpou-2laj-x3o8lbk8Accounts being cleaned by aws-nukeISB control plane access only
Frozenou-2laj-jpffue7gBudget/duration breach -- frozenBaseline SCPs only
Quarantineou-2laj-mmagoakeFailed cleanup or billing cooldownWrite-protected (read-only)
Exitou-2laj-s1t02mrzAccounts pending removalLocked down

OU Hierarchy Detail

Root-Level OUs

OU NameOU IDChild OUsDirect Accounts
Securityou-2laj-8q61vv13None2 (Audit, LogArchive)
Infrastructureou-2laj-40z2mrlgNone3 (Network, Perimeter, SharedServices)
Workloadsou-2laj-4t1kuxouProd, Dev, Test, Sandbox0
InnovationSandboxou-2laj-lha5vsamndx_InnovationSandboxAccountPool0
Suspendedou-2laj-vn184pt1None0

Workloads Sub-OUs

OU NameOU IDAccounts
Prodou-2laj-bje756n21 (InnovationSandboxHub)
Devou-2laj-gjg1p2n20 (empty)
Testou-2laj-tkyylaag0 (empty)
Sandboxou-2laj-zei1pn6x0 (empty)

Innovation Sandbox Pool Sub-OUs

OU NameOU IDAccounts
ndx_InnovationSandboxAccountPoolou-2laj-4dyae1oa0 (parent only)
Entryou-2laj-2by9v0sr0
Availableou-2laj-oihxgbtr189
Activeou-2laj-sre4rnjs3
CleanUpou-2laj-x3o8lbk80
Frozenou-2laj-jpffue7g0
Quarantineou-2laj-mmagoake46
Exitou-2laj-s1t02mrz0

Note on current state: At the time of discovery (2026-03-06), 3 accounts have active leases and 46 accounts are in Quarantine (likely from billing separation cooldown periods). The pool has grown significantly from 110 to 240 accounts since the initial capture, indicating increased provisioning for anticipated demand.


Email Naming Convention

All accounts use email sub-addressing under a single DSIT domain:

ndx-try-provider+gds-ndx-try-aws-<purpose>@dsit.gov.uk
Purpose SuffixAccount
(none)Org management
auditAudit
log-archiveLogArchive
networkNetwork
perimeterPerimeter
shared-servicesSharedServices
isb-hubInnovationSandboxHub
pool-NNNPool accounts (001-240+)

Governance Stack

The organization is managed by three complementary governance systems:

See 05-service-control-policies.md for complete SCP analysis.



Generated from AWS Organizations state captured 2026-03-06. See 00-repo-inventory.md for full inventory.