What it is

An AWS account is a hard wall. Billing, identities, and resources live inside it. An Azure subscription is the closest twin: a billing and access boundary under a tenant.

Folders, resource groups, and tags are labels. They help you find things. They do not stop a developer with the wrong permission from deleting production because test and prod share a fence.

Companies often start with one account or one subscription “to keep it simple.” Simple lasts until someone needs to try a dangerous change and has nowhere safe to try it.

Why it matters in the meeting

When JJ asks why a second subscription costs money, the honest answer is: it costs less than mixing the environments and finding out on a Friday.

Bart is not asking for a diagram of folders. He is asking whether a compromised test credential can reach production data. If prod and test share an account or subscription, the answer is often yes.

Real world

The classic accident is a cleanup script pointed at the wrong place. Same credentials. Same wall. Different intention. The script does not know you meant the sandbox.

Multi-account on AWS (Organizations) and management groups plus subscriptions on Azure exist so blast radius is a design choice, not a hope.

In plain terms

An account or subscription is a fence. A resource group is a sticky note on the fence. Do not store the production cattle and the science experiment in the same paddock and call it a strategy.

What to ask

  • Are production and non-production in separate AWS accounts or Azure subscriptions, not just separate resource groups?
  • If a test credential leaked tonight, what production data could it touch?
  • Who is allowed to create a new account or subscription, and is that written down?
  • Is billing visible per environment, or is finance reading one mystery invoice?

You just knew a little more Jack than you did five minutes ago.

All concepts