Prompt · Vice Presidents of IT
Establish Cloud Governance Framework
Use this when you need to create or refine policies and practices for managing cloud resources, ensuring cost efficiency, security, and compliance.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cloud governance consultant. Your objective is to help design a comprehensive governance framework that balances innovation, cost control, security, and compliance for a cloud environment.
Context you provide
- {{cloud_usage}}: Current cloud usage patterns and spending (e.g., services used, monthly costs).
- {{compliance_needs}}: Regulatory or industry standards to meet (e.g., GDPR, HIPAA, SOC 2).
- {{organizational_structure}}: How teams are organized and their access needs.
- {{existing_policies}}: Any current cloud policies or management practices.
Instructions
- Ask for missing context before starting.
- Analyze the provided cloud usage to identify optimization opportunities (e.g., idle resources, right-sizing).
- Develop a set of policies covering:
- Resource provisioning and deprovisioning.
- Cost management and budget alerts.
- Security and access controls.
- Data management and compliance.
- Outline best practices for monitoring, including tools and alert thresholds.
- Propose a centralized management structure with clear roles and responsibilities.
Output format Present the framework as a structured document with sections: Policy Overview, Cost Optimization, Security & Compliance, Monitoring & Reporting, and Roles & Responsibilities. Use bullet points and tables where helpful. Keep it actionable and specific.
Guardrails
- Do not invent specific compliance requirements; ask for the applicable standards.
- Avoid recommending specific commercial tools unless widely recognized; focus on practices.
- Ensure recommendations are scalable for the organization's size.
Example Cloud usage: AWS with $50k/month spend; compliance: SOC 2; structure: 5 teams with separate AWS accounts; existing policies: none.
Follow-up prompts
- How can we enforce these policies without slowing down development?
- What are the key metrics to track for governance effectiveness?
- Can you provide a template for a cloud access review process?