Nobody could say which subscriptions were compliant

A global tenant, hundreds of applications moving to Azure, and no single view of whether any of it met the standard.

Retail
Four years

A global retail group

Moving every global application from on-premises to Azure is the visible half of the job. The half that decides whether it holds is governance: agreeing what good looks like, then being able to see, at any moment, which parts of the estate actually meet it.

The challenge

A cloud migration at group scale is not one migration. It is dozens of product teams, each with their own deadlines, moving their own applications into a shared tenant.

Every one of those teams can do the right thing and the estate can still drift. Standards exist as documents rather than as checks. Compliance is asserted in a steering meeting rather than observed. And the honest answer to "how much of our estate meets the standard?" is that nobody knows, because nobody can see it.

That is not a tooling gap. It is an operating-model gap. The cloud platform worked. Consuming it consistently was the unsolved part.

What we did

01

Lead the teams doing the transformation

Product ownership across several technical teams driving the move from on-premises to Azure for the group's global applications, working alongside Microsoft on the cloud framework the estate would be built to.

02

Make the standard visible

A cloud governance dashboard giving an actual, current view of the compliance state of every subscription in the global tenant. Not a report compiled quarterly by hand, but the state as it is.

03

Turn product teams into adoption teams

Supporting the product clusters to act as cloud adoption teams, so consistent and secure use of the platform came from the teams themselves rather than from a central gatekeeper.

04

Give automation somewhere to run

A global platform for robotic process automation, built with the local RPA teams, with one expert platform team behind it and fully automated deployment and operations for the bot estate.

How it works

Compliance you can see

The dashboard reports the live state of the tenant. A standard that can be observed is a standard teams can act on.

Adoption from the teams outward

Product clusters were supported as cloud adoption teams. Consistency that comes from the consumers holds better than consistency imposed on them.

One framework to build to

A single global cloud framework, developed with Microsoft, so teams had one target rather than one per region.

On-premises to Azure, at group scale

Global applications moved across, run by several product teams working in parallel rather than as a single migration programme.

A home for automation

Global RPA infrastructure with automated deployment and operations, so bot processes had a supported platform instead of local improvisation.

One expert platform team

A central team holding the platform, with local development teams building on top of it. The split that lets both sides move at their own pace.

Technologies

Microsoft Azure Cloud governance Infrastructure as code RPA Microsoft Intune DevOps

Intended outcome

The lasting change was not the migration. It was that the group could answer a question it previously could not: which parts of the estate meet the standard, right now.

Once compliance is observable, the conversation changes. Teams stop debating whether they are compliant and start closing the specific gaps the dashboard shows them. Governance becomes evidence rather than assertion, and the platform can grow without the standard quietly eroding behind it.

The same pattern appears in the work that followed: measure the estate before redesigning it, and make the standard something people can see rather than something they are told.

The organisation is described by business area rather than named. This was an employed role rather than a client engagement of Hernandez Ortiz B.V. No internal figures, architecture detail, subscription data or colleague names are published.

Related work

Our own platform

Twenty-five containers, two nodes, and an AI agent with a key to all of it

Letting an AI operate production infrastructure is either reckless or well-governed. The difference is entirely in the boundaries.

Proxmox Docker Terraform
A Dutch sun-shading installer

We read seven months of quotes and found we were building the wrong thing

The roadmap was built on what was easy to read. Not on what the business actually sells.

TypeScript Node.js PDF parsing