Skip to content

Onboarding

The goal of this document is to:

  1. Outline the different scenarios for onboarding.
  2. Explain how to onboard accounts in different scenarios.
  3. Outline the consequences of the different methods of onboarding.

Terminology

Term Description
AWS Organizations An entity that you create to consolidate your AWS accounts so that you can administer them as a single unit. More information on terminology and concepts here.
Management Account An AWS account with an AWS Organization. The Management Account owns all billing-information of everything in the Organization.
Workload Account A "standard" AWS account. The account can not have AWS Organizations, as an account with AWS Organizations automatically becomes a Management Account.
Standalone An AWS account that does not manage or belong to an Organization.
Linked An AWS account that does not manage, but belongs to an Organization.

Scenario 1 - Workload Account (Standalone)

There is only one way to onboard a Standalone Account, and it's very simple:

  1. Order a new Crayon AWS Management Account in CloudIQ.
  2. Sign in to the account.
  3. Send an invitation from the Crayon AWS Management Account to the Standalone Account.
  4. Accept the invitation on the Standalone Account.

Workload Account (Standalone) - Illustration

The user logs in to the Crayon AWS Management Account using an IAM-user. The user sends an invitation.

Standalone Account 1

The invitation is accepted, and the account is onboarded.

Standalone Account 2

Scenario 2 - Workload Account (Linked)

Again, there is only one way to onboard this type of account.

  1. Order a new Crayon AWS Management Account in CloudIQ.
  2. Log in to the Workload Account and leave the Organization it is currently under.
  3. Sign in to the new Crayon AWS Management Account.
  4. Send an invitation from the Crayon AWS Management Account to the Standalone Account.
  5. Accept the invitation on the Standalone Account.

Workload Account (Linked) - Illustration

The account to be onboarded resides in a different Organization.

Linked-1

Customer leaves the Organization.

Linked-2

An invitation is sent from the new Crayon AWS Management Account.

Linked-3

The invitation is accepted.

Linked-4

Consequences - Workload Account (Linked)

Billing data

It's important to note that billing information is owned by the Management Account. This means that the following information will need to be backed up, if you wish to keep it:

  • Historical billing data.
  • Invoices

Cost Allocation Tags

Cost allocation tags are managed by the Management Account. When moving a Workload Account from one Management Account to another, you also move the management of the cost allocation tags.

You will most likely have to reactivate the cost allocation tags.

Scenario 3 - Management Account

There are two ways to onboard a Management Account:

  1. Delete the Organization on the Management Account, converting it to a Standalone Account. Onboard the account as you would a Standalone Account.

  2. Onboard the Management Account as-is, by performing a CTA.