Workforce platform: a 45-finding six-pillar WAR charts its AWS roadmap
Shared anonymously — the customer’s name is held by VeUP and available on request.
VeUP ran a full six-pillar AWS Well-Architected Review of the customer’s live environment, surfacing 45 severity-ranked findings (26 high-risk / 19 medium-risk) and a target-state roadmap spanning identity, org-wide audit and threat detection, observability, multi-AZ + tiered DR, and a FinOps cadence flagging a 20–30% savings opportunity.
The challenge
The platform was live and growing across multiple industries, but the team needed an independent, rigorous read on whether its AWS foundation could carry that growth safely. They wanted more than a security spot-check — a full, all-pillar assessment that would surface the real risks, rank them by severity, and turn them into a sequenced plan of work. For a platform handling frontline-workforce data across regulated and operationally demanding industries, the priorities were provable identity and access controls, organization-wide audit and threat detection, observability that could explain an incident, and a disaster-recovery posture with defined recovery objectives.
The solution
A full AWS Well-Architected Review (WAR) across all six pillars — Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability — producing a prioritized findings overview with a severity heat-map and a remediation roadmap. Target state: identity and access via AWS IAM Identity Center with organization-wide MFA enforcement; audit and threat detection via organization-level AWS CloudTrail, Amazon GuardDuty, and AWS Security Hub, plus AWS KMS encryption by default; observability via AWS X-Ray / OpenTelemetry distributed tracing, SLO-based alerting, and AWS Systems Manager Incident Manager response playbooks; operational hygiene via AWS Systems Manager Patch Manager and Amazon ECR image scanning; resilience via multi-AZ deployment plus tiered disaster recovery (pilot-light / warm-standby) with defined RTO and RPO; and cost governance via a FinOps cadence on AWS Budgets, AWS Cost Anomaly Detection, and AWS Compute Optimizer right-sizing targeting a 20–30% savings opportunity.
Production outcomes
| KPI | Result |
|---|---|
| Production outcomes | A complete six-pillar Well-Architected Review of the customer’s live AWS environment; 45 findings identified and ranked by severity — 26 high-risk and 19 medium-risk — distributed across the pillars (Reliability 11, Operational Excellence 10, Security 10, Cost Optimization 9, Sustainability 4, Performance Efficiency 1), giving the customer an evidence-based order of operations; and a target-state remediation roadmap spanning identity, audit, observability, resilience, and cost governance — turning the findings into a concrete hardening program with a 20–30% cost-savings opportunity flagged for the FinOps cadence. |
| Engagement window | The platform has run live on AWS since September 2024. The six-pillar review, its 45-finding heat-map, and the target-state remediation roadmap were delivered in July 2025, and the engagement continues. |
| Cost / TCO posture | The Cost Optimization pillar flagged a 20–30% savings opportunity, routed into an ongoing FinOps cadence (AWS Budgets, Cost Anomaly Detection, Compute Optimizer right-sizing). The 20–30% is the opportunity the review identified, not yet a measured saving — the cadence exists to realize and measure it. |
| Lessons & continuation | A full six-pillar WAR with a severity heat-map turns a vague "are we secure?" into an evidence-based order of operations — 45 ranked findings give the customer a defensible sequence rather than a flat checklist. The cost-savings range is an identified opportunity until realized; the roadmap routes it into a standing FinOps cadence so it can be measured. |
Architecture

Where it started
Assessed baseline · Well-Architected ReviewWorkforce-engagement SaaS · Live multi-account AWS estate · reviewed July 2025Production, staging, and shared-services accounts running a frontline-workforce SaaS — live throughout the review and remediation.
Local IAM users in each account with no centralized federated identity — pre–IAM Identity Center.
Security Group and NACL patterns varied across accounts, with unencrypted-storage gaps flagged by the Security pillar.
No organization-wide CloudTrail, GuardDuty, or Security Hub — visibility stopped at each account boundary.
Application workloads ran single-AZ with no multi-AZ or DR posture and no RTO/RPO targets — the Reliability pillar's highest finding count.
The baseline as assessed by the six-pillar AWS Well-Architected Review — 45 findings (26 high, 19 medium) surfaced by the first full review.
What the review surfaced, pillar by pillar:
- 10 findings
- CloudWatch and X-Ray tracing, Incident Manager playbooks
- IaC-provisioned guardrails, reviewed before production
- 10 findings
- IAM Identity Center with org-wide MFA
- Org-level CloudTrail, GuardDuty, Security Hub
- KMS encryption by default across the data plane
- 11 findings — the largest concentration
- Multi-AZ plus tiered DR: pilot-light, warm-standby
- Defined RTO/RPO recovery path
- 1 finding — the smallest pillar
- Compute Optimizer right-sizing feeds the efficiency review
- 9 findings
- FinOps cadence: Budgets, Cost Anomaly Detection, Compute Optimizer
- 20–30% savings opportunity identified
- 4 findings
- Right-sizing and account-factory consistency cut redundant footprint