Case Studies


September 2026 Architecture Excellence

Cloud-First Reference Architecture for a National Professional Services Firm

Knowble designed a comprehensive cloud-first reference architecture for a national professional services firm, establishing governance, security, resilience, and operational foundations for scalable Azure adoption.

Cloud-first reference architecture design

Overview

A national Australian professional services firm had begun its migration to Azure in response to immediate infrastructure constraints, including hardware limitations and disaster recovery gaps. The initial uplift was executed rapidly, resulting in a flat architecture within a single subscription — a pragmatic decision that addressed urgent needs but introduced structural governance debt as cloud adoption expanded. A major incident reinforced the need for a more deliberate architectural foundation.

Knowble was engaged to design a comprehensive cloud-first future state reference architecture that would establish the governance, security, resilience, and operational foundations necessary to support the organisation's growth agenda and ongoing platform evolution. The scope encompassed six functional domains — structural governance, provisioning and automation, service management integration, compute and storage, security management, and resilience and disaster recovery — with the architecture informed by structured workshops involving subject matter experts from across the organisation's IT function.

The Challenge

The organisation's cloud environment had evolved organically from its initial rapid migration, and several material constraints were limiting the platform's ability to support scalable, governed operations.

  • Landing zone maturity remained at an emerging level, with policy enforcement and subscription segmentation applied on an ad-hoc basis rather than through a coherent management group strategy
  • Infrastructure provisioning relied heavily on manual configuration and portal-based operations, increasing drift risk and reducing repeatability as Azure usage expanded
  • No national monitoring strategy was in place — tooling was fragmented, manual checks were required, and a unified operational view across the hybrid estate had not been implemented
  • The enterprise ITSM platform was largely limited to incident and change workflows, with CMDB, service mapping, and asset management capabilities not yet operating as authoritative foundations
  • Resilience patterns across regions and availability zones were not consistently defined or applied, and disaster recovery runbooks lacked a consistent testing cadence and evidence base
  • Security management segregation, MFA coverage, and access auditability were inconsistent across workloads, with cloud threat modelling and risk appetite not formally defined
  • FinOps maturity was low — inconsistent tagging, ownership attribution, and cost allocation limited reliable budgeting, forecasting, and service-level cost transparency
  • Data and storage migration strategy required uplift, with no defined retention and disposal strategy in place, risking a "lift and shift" approach that would increase complexity and cost

Our Approach

Knowble applied a structured, workshop-driven architecture method to define the target state across all six functional domains, grounding each design decision in current-state analysis and operational usage scenarios developed with the organisation's teams. This engagement is a direct example of Knowble's Architecture Excellence practice — delivering comprehensive, standards-aligned architecture that provides a governed foundation for technology evolution.

  • Current state assessment — conducted a detailed analysis of the existing Azure environment, identifying material constraints, governance gaps, and operational pain points across each domain, drawing on both technical evidence and workshop outputs
  • Usage scenario development — facilitated structured workshops with subject matter experts to define twenty usage scenarios expressing the operational needs of the IT function, spanning governance, provisioning, monitoring, service management, security, and resilience
  • Domain architecture design — designed the future state architecture across all six domains, producing detailed specifications for management group hierarchy, landing zone segmentation, policy enforcement, monitoring and observability, ITSM integration, security controls, resilience patterns, and migration pathways
  • Transition pathway definition — defined the transitional architectural steps required to progressively evolve from the current hybrid operating model toward an Azure-aligned foundation, accounting for dependencies between domains and the need to operate in hybrid mode during migration
  • Governance framework — established architecture governance controls including change approval pathways through the Architecture Review Board and security assurance processes, with policy-as-code enforcement inherited through the management group hierarchy

The Solution

Knowble delivered a comprehensive cloud-first reference architecture that provided the organisation with a structured, governed foundation for scalable Azure adoption across all operational domains.

  • Structural governance and landing zones — designed a management group hierarchy with subscription segmentation aligned to platform, application workload, security, and business service line boundaries, with inherited policy controls enforcing tagging, diagnostics, compliance, and approved resource configurations
  • Policy-as-code guardrails — defined codified platform guardrails applied at management group and subscription scope, with continuous compliance monitoring, drift detection, and automated remediation to maintain control effectiveness at scale
  • Provisioning and automation — established Infrastructure-as-Code as the default operating model using pipeline-based delivery, with version control, rollback capability, change traceability, and segregation of duties to reduce manual intervention and configuration drift
  • Integrated monitoring and observability — designed an enterprise logging and monitoring strategy delivering a unified operational view across the hybrid landscape, with team-specific dashboards, automated threshold-based alerting, and integration with the ITSM platform for incident coordination
  • Service management integration — defined the integration architecture between the cloud platform and the enterprise ITSM platform, including automated cloud asset discovery, service mapping, event-to-incident workflows, and service catalogue provisioning for governed workload onboarding
  • Security management — designed a dedicated security management domain with segregated capabilities for posture management, baseline hardening, Zero Trust access controls, cloud application security, and security logging with operational separation from infrastructure monitoring
  • Resilience and disaster recovery — defined multi-region resilience patterns with tiered workload protection aligned to business criticality, including documented recovery scenarios, IaC-based rebuild procedures, and a framework for evidence-based disaster recovery testing
  • Compute, storage, and migration — established a governed compute standard mapping workload types to approved configurations, a tiered storage strategy with cost-optimised access patterns, and controlled migration pathways informed by inventory and classification inputs
  • FinOps and cost governance — designed a cost management framework incorporating standardised tagging, ownership attribution, budget alerting, spend forecasting, and service-level cost transparency to support showback and chargeback readiness

Outcomes

  • Governed cloud foundation — the organisation received a comprehensive reference architecture providing a structured, scalable foundation for Azure adoption, replacing the organic growth model with deliberate governance and policy enforcement
  • Reduced platform risk — the management group hierarchy, policy-as-code guardrails, and standardised provisioning patterns directly addressed the governance gaps that had contributed to a prior major incident
  • Operational maturity uplift — the integrated monitoring, ITSM integration, and service mapping designs established the foundations for measurable service outcomes, consistent incident coordination, and improved mean time to detection and resolution
  • Security posture alignment — the architecture aligned cloud security controls with the organisation's information security policy obligations and industry compliance requirements, establishing a clear path toward Zero Trust enforcement and audit readiness
  • Resilience confidence — defined resilience patterns and disaster recovery procedures provided testable, repeatable recovery scenarios with clear alignment between business criticality and workload protection
  • Cost visibility and control — the FinOps framework and tagging standard enabled accurate cost attribution by service and owner, supporting informed budgeting and investment decisions
  • Business agility — subscription vending, service catalogue integration, and IaC-based provisioning established governed pathways for rapid workload onboarding, enabling business service lines to develop their own systems within defined guardrails
  • Transition roadmap — the architecture included defined transition pathways enabling the organisation to progressively evolve from its current hybrid operating model while maintaining operational continuity

Is your cloud platform built on foundations that will scale with your organisation?

Learn more about our Architecture Excellence practice, or get in touch to discuss how we can help.