Cloud WaypointFederal Cloud ServicesStart a conversation ↗
Cloud Waypoint · enterprise reference architecture

One operating model.
Room for different technology choices.

Connect mission teams, shared cloud foundations and existing enterprise services. Begin with clear ownership; add automation where it earns its place.

Illustrative advisory pattern

The enterprise context

These are capability groups, not a single authorization boundary or a required product stack. Services may be cloud-hosted, retained on premises or consumed through an approved agreement.

Shared guardrails

Identity · security · financial accountability · decision rights

Three connected responsibilities
1

Mission teams

Applications, dependencies and service outcomes.

Modern and legacy workloads. Teams retain their mission responsibilities.

Cloud foundation / GSS

Selected shared services and provider-specific operations.

Scope, inherited controls and operating ownership are established for the engagement.
3

Enterprise services

Service management, event analysis and agreed CSSP support.

Existing investments connect through defined interfaces and responsibilities.
Between these groups: requests, approved changes, selected events and evidence. Each path has an owner, permitted information and direction; this grouping grants no connectivity or action authority.
Discover → understand → improve

ADM supplies observed relationships. Operations validates changes and feeds learning back into the model.

First worked example

A Google-based GSS

Use the same enterprise relationships with Google as the first provider example. The interactive model explores provider scope, delivery capacity and tooling prerequisites. Exact services and authorization scope still need engagement-specific validation.

Choose the depth you need

The overview stays simple. Open a topic to compare an operating approach or trace a decision.

Delivery and automation choices

Approaches can coexist. This selection illustrates trade-offs; it does not calculate readiness or a delivery date.

ADM and configuration drift

Compare approved intent with observed dependencies and configuration. Discovery is evidence to investigate, not authority to overwrite a baseline.

  1. DiscoverCollect a scoped inventory and dependency evidence, with source and freshness.
  2. CompareReconcile observations with ownership, intended configuration and approved changes.
  3. AssessInvestigate differences and mission impact. Missing data is not proof of compliance.
  4. Approve and actUse the agreed change process. Automation executes only explicitly authorized actions.
  5. ValidateCheck the result and record the evidence. Update authoritative records through their governance process.
  6. ImproveUse recurring patterns to refine operations, dependencies and investment priorities.

Continuous discovery is an optional operating capability. Frequency, collection permissions, cost and ownership must fit the environment; it is not a managed service included with the study.

Telemetry, AIOps and FinOps

Useful signals

Preserve required security evidence. Scope optional telemetry by use case, retention and cost.

Decision support

Correlate events and highlight recurrent incidents or unreclaimed capacity. AIOps can begin with read-only recommendations.

Measured improvement

Owners validate mission needs and approve action. Verify service health and actual cost after a change.

Authorization and future tooling

Keep GSS scope, mission authorization and CSSP responsibilities explicit. Monitoring and evidence support authorization decisions; they do not continuously grant authorization.

Wiz for Government remains a possible external service to evaluate only after current target-IL authorization, permitted flows, service scope and mission acceptance are verified. No approval date is assumed. A classified environment requires its own design.

Provider examples can include AWS, Azure, Google, Oracle and retained on-premises services. None is mandatory; capabilities and constraints drive the choice.

Foundations supplies engagement context and variables. Enterprise architecture and operations connect the modular ADM, Zero Trust, FinOps and AIOps recommendations.

Strategy, reference architecture and sequencing guidance—not enterprise implementation, CSSP delivery or an authorization commitment. Illustrative reference only; no client data or operational actions.