---
title: Platform Landing Zone
description: The platform landing zone defines the enterprise cloud baseline for governance, security, networking, identity, cost controls, and infrastructure automation.
sidebar:
  label: Platform Landing Zone
  order: 1
source_url: "https://framework.stackit.cloud/migration/design-and-mobilize/landing-zones/platform-landing-zone/"
source_file: "docs/migration/design-and-mobilize/landing-zones/platform-landing-zone.mdx"
---

## Understanding Platform Landing Zones

A platform landing zone is the company-wide target operating baseline for cloud adoption on STACKIT.
It defines the cross-cutting controls and platform guardrails that every product team must inherit.

Without this baseline, migration teams usually face inconsistent controls, duplicated design decisions,
and delayed approvals.

## Core capability areas

<CardGrid>
  <Card title="Account governance">
    Structure organizations, projects, and environments with clear ownership boundaries.
  </Card>
  <Card title="Identity and access">
    Define IAM model, role patterns, least-privilege principles, and separation of duties.
  </Card>
  <Card title="Security and compliance">
    Implement mandatory controls, logging, evidence pathways, and policy enforcement.
  </Card>
  <Card title="Network architecture">
    Define segmentation, connectivity patterns, and secure communication standards.
  </Card>
  <Card title="Cost management">
    Establish tagging, budget controls, chargeback/showback, and cost transparency.
  </Card>
  <Card title="Automation">
    Provision and evolve the baseline through OpenTofu/Terraform-based Infrastructure as Code.
  </Card>
</CardGrid>

## Typical inputs and prerequisites

- **Organizational model**: Business units, ownership boundaries, and environment strategy.
- **Regulatory constraints**: Industry requirements, audit scope, and evidence obligations.
- **Security standards**: Identity model, encryption standards, secrets handling, and incident response.
- **Connectivity requirements**: On-prem, partner, internet, and service integration needs.
- **Operating model constraints**: Roles, escalation paths, and handover boundaries.

## Delivery sequence

<Steps>

1. Define governance and control objectives with enterprise stakeholders.
2. Design platform baseline patterns for identity, networking, security, and cost control.
3. Implement baseline automation and policy guardrails as reusable modules.
4. Validate controls with pilot workloads and close architecture/compliance gaps.
5. Operationalize with ownership model, runbook standards, and change process.

</Steps>

## Design principles

- **Standardize first, then allow exceptions**: Keep exceptions explicit, approved, and time-bound.
- **Automate controls**: Treat policy and baseline setup as code to reduce manual drift.
- **Shift evidence left**: Build compliance evidence generation into day-1 platform design.
- **Design for scale**: Assume multiple teams and application archetypes from the start.
