Organisation Scope
Guardian Pro's governance capabilities scale across your entire AWS Organisation. This page covers how governance applies to multi-account setups, how to activate cost allocation tags, and how your organisational structure affects your governance score.
Multi-Account Governance
Management Account
Connecting your AWS Organisation's management account unlocks the full governance feature set:
- SCP management -- Deploy and monitor service control policies across OUs and accounts.
- Cost allocation tags -- Activate cost allocation tags from within Guardian Pro.
- Full maturity assessment -- All four governance dimensions are scored.
- OU-level tag strategy -- AI recommendations tailored to each OU's workload pattern.
- Organisation-wide policies -- Apply tag policies at the root or OU level.
Member Accounts
When only member accounts are connected (without the management account):
- Tag compliance, violations, and remediation work fully within each account.
- AI tag strategy generates recommendations based on the connected account's resources.
- SCP management and cost allocation tag activation are not available.
- The maturity assessment scores two of four dimensions (Tag Governance and Cost Allocation), with weights adjusted accordingly.
To connect your management account, navigate to Account Management and follow the setup process. Your existing member account data is preserved.
Account Coverage
The governance status bar shows how many of your AWS accounts are onboarded into Guardian Pro. Increasing account coverage improves your Account Structure dimension score and ensures governance policies are evaluated consistently across your organisation.
Cost Allocation Tags
Cost allocation tags allow you to track AWS spending by tag. Once activated, your tag keys appear in AWS Cost and Usage Reports, enabling you to attribute costs to teams, projects, or environments.
Activating Cost Allocation Tags
Guardian Pro can activate your tag policy keys as cost allocation tags, connecting your tagging standards to your cost management workflow.
Automated activation (management account required):
- Navigate to Governance and expand the Cost Allocation Tags section.
- Click Activate Cost Allocation Tags.
- Guardian Pro activates your tag policy keys as user-defined cost allocation tags via the AWS Cost Explorer API.
Manual activation (if automated activation is not available):
- Open the AWS Billing Console.
- Navigate to Cost Allocation Tags.
- Select the tag keys that match your Guardian Pro tag policies.
- Click Activate.
- Return to Guardian Pro and confirm activation by checking the confirmation box and clicking Confirm Activation.
Activation Status
After activation, the section shows:
- Activated tags -- Listed as green chips showing each activated tag key.
- Activation method -- Whether activation was automated or manual.
- Activation date -- When the tags were activated.
Activated tags appear in your AWS Cost and Usage Reports within 24 hours of activation. Historical cost data is not retroactively tagged.
Partial Activation
If some tags activate successfully while others fail, Guardian Pro shows a partial status with:
- Successfully activated tags (green).
- Failed tags (yellow) with an explanation.
- A Retry Failed Tags button to attempt activation again.
Organisation Sync
Guardian Pro maintains a cached view of your AWS Organisation's OU hierarchy and account structure. This cache is used for:
- Target selection when deploying SCPs or assigning tag policies.
- Coverage calculations in the governance assessment.
- OU-level strategy recommendations.
To refresh the cache, click Sync in the guardrails section. The sync pulls the latest OU tree and account assignments from your AWS Organisation.
Impact on Governance Score
Two of the four governance dimensions are directly affected by your organisational setup:
| Dimension | What Improves the Score |
|---|---|
| Account Structure | Connecting the management account, onboarding more accounts, having a well-structured OU hierarchy |
| Cost Allocation | Activating cost allocation tags for your tag policy keys |
For single-account setups, these dimensions are marked as not applicable and their weight is redistributed to Tag Governance and Service Control.
Next Steps
- Maturity Assessment -- See how your organisational setup affects your governance score.
- SCP Management -- Deploy guardrails across your organisation.
- Tag Governance -- Monitor tag compliance across all connected accounts.
- Account Management -- Connect additional AWS accounts.