Before You Deploy · Field Note 4 of 7

Undefined Subscription Strategy

Could finance produce an accurate cost breakdown today? Could an NZ auditor list which subscriptions process personal information?

SR
Steve Rackham
8 min read Guides

In Part 1 SELL! shipped a landing zone without mapping the workload. Part 2 rewrote governance after deny first. Part 3 put a second team on an untested path. This field note is the question that should have been answered before the first terraform apply: what is a subscription for?

SELL! is a fictional company. Any resemblance to a real platform team’s war story is the point.


Setting the Scene

Week sixteen at SELL!. Aroha, the CFO, wants cloud cost by product line for the board pack. Tui wants to know which subscriptions process personal information before the next agency questionnaire. Without a documented answer to what a subscription is for, teams had improvised.

Eighteen months of pre-migration improvisation came across with the estate: contractor subscriptions, shared Dev boxes, names that felt right in 2023. The landing zone is sixteen weeks old. The sprawl is not.

Sprint Plan: Clean Up Subscriptions

Name standards first. Strategy later. The board pack is Friday.

Week 16
  1. Rename the worst offenders.
  2. Ask owners to fix tags.
  3. Defer vending automation until "after the cleanup."
  4. Promise finance a reliable report next quarter.

The Pilot: The Rename Programme Works Perfectly

On paper, a naming pass and a tag reminder will fix the board pack. By Thursday the worst names look tidy. prod-lending-final-v2 is now prod-lending. The contractor’s subscription has an owner of record. Aroha has not opened Cost Management yet.

The inherited estate does not yield to a Friday cleanup. Renaming a box does not split the sandbox that still lives inside it.

End of Cleanup: Names Look Tidy

The rename programme closed its tickets. The boundaries did not move.

Week 16
  1. The worst display names are standardised.
  2. Tags are requested, not enforced.
  3. Shared Dev still holds forty resource groups.
  4. The board pack is tomorrow morning.

The Boundary Nobody Chose

The debate starts again in the platform channel: per application? Per environment? Per team? Per cost centre? Per compliance zone? Nobody had written the answer down before the first subscription existed, including the ones that predated the landing zone.

Board Pack Day: Finance Opens Cost Management

Friday. Aroha opens Cost Management with the auditor’s follow-up questions still in the thread. She finds:

  • prod-lending-final-v2 and prod-lending-final-v3 (the rename missed one)
  • A shared Dev subscription holding forty unrelated resource groups
  • A subscription still owned by a contractor who left in 2023
  • Tags that match nobody’s chart of accounts

The pack goes to the board with a footnote: cost attribution partial. Tui’s list of subscriptions that process personal information is a hallway guess.

Post-Sprawl: The Cracks Widen

The names look tidier. Then the first real cost conversation begins, and the cracks widen.

Cost Issues

SELL! runs lean. An unattributable slice of cloud spend triggers real conversations. Subscription boundaries are the primary cost isolation mechanism; tags are secondary and weaker.

Compliance Issues

Credit information under the Privacy Act 2020 and the Credit Reporting Privacy Code, plus NZISM scoped agency work, needs clear edges. Mixing regulated and non-regulated workloads in one subscription makes every control apply to everything, and gives auditors a reason to scope more, not less.

Blast Radius Issues

Quota and blast radius matter even at SELL!‘s scale. Last month a rogue load test in the shared Dev subscription exhausted the region’s vCPU quota and blocked a production scale-out on the lending app. Subscription-level separation would have contained that. Concentrating workloads in Azure New Zealand North is still rational. Sharing a quota envelope with a sandbox is not.

Symptom What to do instead
Teams improvise names and boundaries until you have sprawl, shared environments with no cost attribution, and years of unwind. Define isolation around blast radius, compliance, billing, and quota. Document it, automate subscription vending, and enforce tagging against the finance codes the business actually uses.

References: Why Landing Zones Fail · CAF: Subscription design · CAF: Subscription vending · WAF: Reliability

The Lessons We Can Learn

Do not try to satisfy every axis. Choose primary boundaries and use other mechanisms for the rest.

Primary: compliance and regulatory scope. Separate subscriptions where the regulatory treatment differs: NZISM scoped agency work versus commercial, personal or credit information processing versus not.

Secondary: cost accountability. If two workloads have different owners of the money, they generally belong in different subscriptions. Budgets and chargeback become correct instead of tag archaeology.

Not boundaries by default: environments, and subscriptions created because a team asked nicely. Environments within an application often sit under management group, RBAC, and resource groups. Do not vend a subscription because someone wanted their own box. Exception: when a regulated environment must be technically isolated from a non-regulated one.

Unwind the Inherited Estate

Renaming prod-lending-final-v2 does not fix that it still shares a subscription with a sandbox. For a lean NZ organisation the unwind is attrition, not a twenty subscription migration. Vend new work onto the documented boundaries. Sunset the inherited subscriptions as workloads move. Lift anything that processes personal or credit information out of a shared box first. That is the only in-place move worth the capacity.

Operations: The Missing Vending Pipeline

Once the strategy is documented, automate it:

  • A vending pipeline that takes app name, owner, environment, data classification, and budget, then places the subscription in the right management group with the right policies and tags
  • A request form that asks whether personal or credit information will be processed, because that question determines placement
  • Naming and tagging standards enforced by policy, aligned to cost centre and product codes finance already reports on

Cleanup first, automation later, is how the estate outruns the rename programme.

Symptom What to do instead
Cleanup first, automation later. The estate grows faster than the rename programme. Stand up vending from the start. A two week build beats a six month retrofit onto years of inherited drift, and NZ organisations rarely have six months of platform capacity to spare.

References: CAF: Subscription vending · CAF: Platform automation and DevOps · WAF: Cost Optimisation

What they did Should have done
Created subscriptions as projects arrived, with names that felt right at the time. Published a one page strategy naming the primary isolation boundary before the first vend.
Relied on tags for cost attribution after the fact. Aligned subscription ownership to money owners, then used tags as enrichment, not the source of truth.
Mixed credit information workloads with sandboxes in shared subscriptions. Separated regulatory scopes so Privacy Act and NZISM evidence had a clean edge.
Deferred vending until after a manual cleanup. Automated placement, policy, budget, and tags at request time.

The Moral

Subscriptions are cheap. Wrong boundaries are expensive. SELL! treated subscription creation as a chore, then discovered it was the billing system, the compliance boundary, and the blast radius control in one.

The test: could finance, unaided, produce an accurate cloud cost breakdown by business unit today? Could your auditor list which subscriptions process personal or credit information? If either answer is no, the strategy is undefined, whatever the diagram says.

A one page strategy and a two week vending build are a fractional deliverable. See Fractional Cloud Architecture and Advisory.

One Block

Write a one page subscription strategy that names your primary isolation boundary (compliance, cost, or blast radius). Share it with finance and one workload team before you create the next subscription.
See all articles