ITOM Visibility & Cloud Accelerate Series – How to seamlessly manage your Cloud Accounts with SN CAM
yeah I guess we can get started now so good morning good afternoon or good evening everyone and welcome to another amazing session of our service now uh live on service now webinar Series today we are going to go through an amazing topic this is one of the most important topics this year already this is just the first iteration of the iton visibility and Cloud acceler Academy for 2024 and um today we're uh going to talk about cloud account management before we get started uh please make sure to register for the live on service now webinar series as this event is part of the very same webinar series which helps you uh deploy and speed adoption and really achieve value faster with the uh service now Solutions and thanks Steve for sharing the link on the chat so please make sure to register for the entire session and a few housekeeping items for you all today as usual so please make sure that everyone is muted and we have the Q&A box for you for any questions or any comments please make sure to use that feature and uh whenever you're asking those questions feel free to introduce yourself we'll love to hear who you are and uh we'll have polls today as per the last session so we have seen great interaction in the previous sessions of this uh Academy so make sure you participate in those and this session is being recorded So this session will be available on YouTube and on the service now Community Forum after the session in a few days and right after the session please make sure you fill out a short a very short survey and that's very valuable for us so far you shared a amazing feedback with us so please make sure uh you provide us uh with feedback now for those of you that don't know me my name is John Mario deluigi and I'm going to be your host for today I'm part of the uh senior of the outbound uh product management team here for itm and today we have two guests one of which you might have uh seen before that is RAM and the other one is morly so Ram please start to introduce yourself sure thanks John um hello everybody uh RAM Devan here uh probably not a new phe to many of you uh I am the product manager inbound for uh the cloud accelerate product Set uh very happy to be talking to you about our latest capability offering called cam uh Mur ready Mur as we call him is our architect I would like to pass on the Baton to Mur to introduce himself go ahead mle thank you uh yeah yeah so I've been I think for most of you new phases for me uh right so yeah I've been with service now last three years and then this is my third product to be done from scratch and happy to be part of the team yeah thank perfect youor that's great to have you here thanks so before we get started today a safe hardboard notice we're talking about a new capability and its future today so um just make sure you're keeping that in mind throughout the presentation and you don't make any purchasing decisions uh based on the information that will be shared today now first things first um we would like to introduce you to the overall vision of how service now wants to help you to scale your Cloud transformation with the uh Suite of products that is called Cloud accelerat now typically we can distinguish different phases In This Cloud transfer information Journey we typically had the sort of day Zero The Landing phase whenever uh the application migration decision is being made so uh companies and businesses are deciding on which resources to migrate to the cloud and on the r disposition and then we have the creation of the cloud accounts the definition of the cloud policies for those accounts and in general for all the resources they will reside on the clouds then we have the day one activities which is the deploy phase where we actually go and create the uh a catalog of those Cloud offerings and then there's the actual request and deployment of those Cloud resources into different multioud environments and then we have the manage phase where we have security and governance checks that are being performed on top of those very same uh Cloud resources to make sure that they are compliant with the uh company policies and then there are the day-to-day operations such as um the uh addition of a particular uh hard drive to a particular resource on the cloud or the termination of the very same resources the different lease policies that play a role etc etc so these three main steps can summarize the cloud transformation Journey as it's seen from a cloud accelery perspective and as a matter of fact we have that cloud accelerate is offering you solutions for each of those steps we uh have presented already the new cloud services catalog in the in one of the recent episodes of this very same Academy and cloud services catalog is already available for GA together with the other capabilities that you see here that are Cloud migration assessment and Cloud configuration governance and Cloud action Library um in particular these set of capabil allows you to face most of these challenges but especially we have a new capability that is been launched as an innovation lab release which is cloud account management and that's exactly what we're going to talk about today because this new capability is going to guide you through the cloud account creation process and management of those very same accounts I want to make sure that it's clear that cloud account management is still an innovation la release is not part yet of the itone Cloud accelerate SK and the uh eventual packaging is still to be determined as you can see in this SL so um if there are no further questions and please make sure to use the Q&A feature I'm going to leave it over to you ram if you want to share your screen and I don't know if you're muted R maybe yeah no you're right let me go ahead and uh share my screen on my side in a moment here and we'll get started here so folks I hope everybody's able to see my screen and my audio is good because I want to talk for a little bit here I'll start by okay let me know if um the audio is good okay perfect thanks yeah let me start by making this important statement the cloud account creation process is is broken right how many of you feel that way in terms of um you know creating new Cloud accounts for use by by team members for use by developers right in in many ways a lot of our customers who I spoke to are coming back and saying that oh well you know it takes a long time to for the cloud account to get created uh or if it is created uh we don't know how to set up the right networking we don't know how to set up the right uh things or from a service now angle teams are always saying that oh it's very siloed we don't know what what's happening there and uh you know therefore uh we not able to set policies from a centralized perspective on the new the new environment the new Sandbox that has been created there which all basically leads to you know unauthorized cloud service use Shadow it kind of problems there uh prolonged account life that you know the account just continues to be used and uh nobody knows has any control over that and then there's the part about high costs obviously because you are setting up potentially without the central budgets uh getting uh being set in place there and and one very important thing especially if several of you are around um service now practices and you're familiar with csdm and setting up service connectivity is important right from the start right how are you going to be able to set that up right um why is this becoming more and more important there why urgency on the on the whole area there I mean a couple of years back if somebody had about 100 uh Cloud accounts in in AWS or in Azure they were considered like okay fine they're doing something big there but that's like 100 and 200 is like not even a small not even a large number anymore the large numbers are more around the thousands and the tens of thousands actually I'm hearing customers having tens of thousands of accounts large ones and then the minimum um the some medium siiz ones are like having 5,000 to 6,000 accounts uh subscriptions in Azure or Cloud accounts or just service accounts in uh not service accounts accounts in AWS and all that stuff so there is really a problem here if you have first take this problem cloud account creation process being broken and having a you know a controll less kind of an approach there one the second one is the fact that there's too many accounts also getting created right and that's exactly uh the problem that set us thinking about okay how can we enable our customers to do it better so that they can reduce the risk and actually better on the uh Cloud usage efficiency while ensuring that there a better OD option right that's kind of the idea there so I'll start by uh uh requesting John to make the first poll question here and please be ready to give your answers go ahead John absolutely thank you ram So today we're goingon to have three polls and this is the very first they were asking you to participate in so what is in general in your company the average lead time for a noal account cloud account creation from the very same request time to the actual provisioning of that account it's uh less than one day or about a week or less than a week or is it way too long we wanted to be provocative in this case so it takes multiple weeks I know it's tempting to choose the third option for sure but please make sure that we are compliant with the actual reality of how things work in your company so um we stopped the poll right now and we can uh share the results we can see that the vast majority of you the 52% is chosen the less than a week option and followed by the multiple weeks option so 35% of you takes multiple weeks to be provisioned which is um quite a good bit and only 133% of you have a streamline process for which it takes less than a day to get it provisioned so I'm going to stop sharing the results and back over to you ram perfect thanks for running that it's excellent to see that uh you know our hypothesis has been validated at least from this group here that um while it takes probably less than a week it's probably a few days four to five days there um quite a good number actually saying multiple weeks and it's way too long I I can understand the frustration that happens when uh it takes that long for accounts to get created there so what is you know I I want to Dive Right Now into talking about what is the vision of the app where are we headed towards although for the Innovation lab we've taken a small chunk of this and you'll you you'll see it when I when we show the demo here uh by the way mully comes from a very technical place and we can also take your additional technical questions there feel free to Poe your questions in the Q&A uh chat uh we'll keep answering those but very importantly here uh for the Innovation lab we've taken a small chunk of this but for the ga we are planning a lot more and over subsequent releases even more uh planned uh on this front but so you get a perspective of where the product is headed and what all we want to achieve with this first of all the onboarding and the automation existing accounts that you may have new accounts that you want to get created for the various environments how to set up the environment itself how to set up your Landing zones how to set up your vpcs how to set up your nsgs so all of those things is one part of the story there how to make it customizable so that you can meet your needs there you probably have multiple Tools in your tool set that you're using today maybe you're using um you know AF or you're using some kind of a cicd pipeline there who knows right so there's so many things that happens there um even within service now we have customized tools that are being used by our own it group and uh so very different set of tools are actually being used there and uh our our aim is to support that kind of a customizable process workflow and I'll show you how we actually doing that and how it's easy for you to integrate your process into that place there and and first of all the automated service account creation with the workflows itself that's that's a very key part of the uh story that we want to actually build there so let me just use the pointer here um visible anyway so yeah automated service account Creation with the workflows which will show you that in minutes your account can get created there going through approval going through all of that stuff there right so that's that's important uh uh part of the demo that will be showing there another thing that a lot of our customers in our initial validation our initial interviews with customers another customer another thing that came up was offboarding of accounts how do we bring a clean closure on the on the accounts themselves how do you ensure that accounts are not used the transfer of ownership is done uh you know um the budgeting is closed for that and then you know you take it forward in a meaningful way uh so that uh it can either be driven initially by a suspension and then going towards a deletion or should it be an altogether closure or should it be a temporary suspension for some budgeting needs and all that stuff there's so many so many angles to be looked into there and uh that's something that several of our customers actually uh that we spoke to had been struggling with especially when it came to handling certain personalized data and all that stuff right that was the third part that was the second part of the the whole discussion there onboarding and then offboarding while more importantly during the course of usage of the account over a period of time users owners of the account some specific uh teams may end up getting a lot of permissions for which were just probably given for temporary reasons but somebody forgot to take away those permissions back and so there's like permission creep that happens there um maybe the person who was owning the account has left the organization and there's no owner there so there's a need for attestation and enforcing leas prege and ensuring that in a zero trust environment there is nobody who's actually having you know excess permissions and that needed there so the continuous evaluation of the I permissions to be done there and of course a very important and uh um uh crucial part of the story is to just in time elevated axis for break the class kind of scenario so that uh at that point of time using some assume role kind of an approach uh in the AWS context how does uh additional processes additional powers or permissions be given for specific use and then pulled back immediately right after that so that angle also comes into place is there the idea behind uh you know this is how do we help you in all of the traditional activities with respect to uh Cloud subscri which are probably being done manually and they're taking days together but how do we make that simpler for you so that it can be driven through a process with change and with approvals and all that stuff it's kind of the idea um I want to talk a little bit about the typical uh equation uh between the team members uh in a in typical cam context right um I'll start by talking about a requestor uh the requestor as we see it in the cam as a role is a person who could be a team lead or just a representative of a of an application team they actually come from the application engineering team potentially look at that way look at it that way right they are coming in maybe it's a manager of a team maybe it's the lead of a team maybe it's the architect of a team of a product and uh which was on Prem and now they're moving that uh on premise application to the cloud and so they want to initiate a cloud uh creation request there right the intent is that um account creation does not necessarily have to be given to everybody the organization may choose to give it to certain people but if the organization wishes to make it more democratic and accounts uh account creation request creation can be done by anybody then the role can be given to more people no issues there but this is the role that will initiate the cloud account creation request provides a justification and gathers and you know gives additional information for the account creation like which department which Buu which uh what is the budget so all of those details will be given by the requestor then once the requestor provides that and please remember who the requestor is that's going to be important uh to understand the when you show the UI and all that then the approver comes in the approver primarily defines like um you know it's based on the approval policy um it's obviously a customizable approval policy that we use we Flo designer automation engine today so the the approval can be changed uh for multi- level and all that stuff I'll show you a single level approval as a simple approach for the time being but the approver does what he does right he or she does so they just go ahead and check the Val the values and all that if everything is fine go ahead and approve it and and then it brings us to the third role uh which is the provisioner the provisioner as we look at it is more of the centralized uh team member from the ccoe side or from a um you know uh traditional I would say it Ops Team um two two responsibilities for the provisioner would also look at the provisioner as a kind of the uh app admin also right because they set up the cam configurations I'll show you what the configuration looks like connecting with the necessary uh you know the uh terraform repositories and ensuring that uh you know this consistent configuration uh setup secure access management and all that is done on the one side by the provisioner another important thing that the provisioner does at least in The Innovation lamp as I'll show you in the demo is uh how they will uh assign the right organization units when the accounts are created there please do remember that organization units are something that when what I refer to here is something that is specific to AWS cloud and the aw oou is there right so setting the right OU becomes important on the service now s side because the request comes in without knowledge of what is happening on the uh on the on the AWS site there so the provisioner ensures that this is done but we are working on improving the story uh to so that this becomes automated in a better manner we looking at using uh you know uh a couple of our internal data Foundation components uh for actually driving this through uh policy driven approach there so that's another step there and of course provisioner also doubles up as or triples up I would say as a as a operator uh because he can also troubleshoot issues and uh fix uh uh certain provisioning problems and all that right so that's overall the three people requested approver provisioner right and we'll show you how they're uh how they participate in this whole process of the account creation then um which brings me to the next poll and it's pretty interesting given I've given you this background there I think it's a great segue for John to post the next poll question go ahead John thank you so much RAM yes so we want to investigate what area of cloud management is the most challenging for you for your team given all the challenges that we have seen that have been presented by Ram even before I want to investigate is it because of the account creation that you have such long lead times to get an account provisioned or do you have issues in the approval process itself or in the change management part otherwise you have issues in the decommissioning side of things or uh do you have any other specific problems in case uh you can specify them in the Q&A section so I see a lot of uh you are participating in the poll please make sure you give your contribution so uh in another five seconds or so we can terminate the poll thanks everyone by the way I see a greatly engaged audience today so it's fantastic to see all of your commitment to this uh successful Series right so in five 4 3 2 1 I'm going to end the poll and the these are the results so majority of you has issues with either decommissioning or change management we have respectively 30% and 29% of you that have chosen these options um we have followed by approval process issues and account creation about 20% each and we have other that uh will specify in the Q&A option so thanks everyone for this great participation in Ram you can keep going with this slides yeah very insightful uh information there especially around the decommissioning please do share additional feedback around what is uh what is the issues that you're facing around decommissioning that is taking time here uh which brings me uh uh you know to a view of the technology stack again not to get into a lot of details here but I just want to kind of impress upon you the investment that we have made in using the service now platform components in building this uh uh in building this app right we invested into uh cam is coming with um nice uib screens uh We've invested in a customizable Playbook oriented process uh for any of you who used our or seen our HR uh SD products you've seen the Playbook being used there a lot or even in our service operations workspace that's being used a lot so pad and Playbook uh join together in actually helping you to drive a customizable process workflow not just a single workflow there that's one thing pace is the other component that I was talking about in the policy uh as code engine part of it and of course underlying everything the basic orchestration is integration Hub one notable absentee here is the mid so we went to the Midas approach for this whole story there but we still continue to use um for the initial release at least we looking at using terraform and uh part of the demo will also make that clear there so on the client environment there'll be uh terraform the cloud terraform version not the open source version uh for the Innovation lb that's what we support terraform cloud and um even the free terraform Cloud uh user seat is enough for us and uh that'll eventually Drive the story on the on the cloud side so overall you know a great uh kind of coming together of uh the various capabilities inside of the platform uh to actually build uh this story there when you see the demo it'll become more clear there um from an application app uh app architecture perspective uh right the flow is something that looks like this uh terraforms Cloud API are uh are used to drive the creation of a let's say a new AWS account uh eventually this will expand into other clouds there but for Innovation lab again we just supported One Cloud so AWS is the only cloud provider for the Innovation lb available right now uh my my request is don't let that stop you from trying it out please do try it out still so that you can give us your feedback on on on the on the app and um we will definitely follow suit with uh more clouds supported there and um of course we've taken care of retries and uh ensuring that uh you know uh every time email notification is also sent after every change that happens there right so a rough idea is basically um terraform will be driving the actual orchestration process but before that of course there's a lot of checks and balances that we do on the service now side uh which brings me to um while talking of terraform and other things um the third poll talking about the tool sets that you use go ahead uh John yeah yeah thanks Ram so poll number three for today and right after this we can start to answer a few questions that I see there so um we want to know more about the tools that are currently involved in your current cloud account creation pipeline so do you actually have the manual option or do you leverage CI CD processes uh otherwise do you leverage either a terraform or template Automation in general or do you prefer uh sale points the is involved in the process or do you also leverage other tools please please please select all that apply right sometimes I might be using a combination of things so in this case uh I I feel like we have the single Choice selected so we'll have to go for the for oh my gosh okay okay okay so please um just make sure all you pop your answers there and I see again greatly engaged audience today it's fabulous so thank you all um in five 4 3 2 one we can end the poll and I will share the results so we can see that uh we definitely have a manual aspect to the current uh cloud account creation pipeline uh for 36% of you followed by uh either a cicd process or a terraform template automation for uh 25% respectively uh of those that chose these options and then we have 12% of you specified sale Point as a tool that has been involved in their current um uh cloud account creation Pipeline and only 3% selected other tools now uh thanks for sharing your feedback and I believe Ram we can answer some of these questions that that are still open yes so I see and thanks everyone for helping out here um is integration Hub required to use I believe this is in interest of most of these folks most of the Audi yes we are we are using integration Hub but you don't need a separate integration Hub subscription but the integration Hub calls that we make uh will obviously cost the transaction cost you know it's it's a few transactions not not a lot for each account you create there'll be a couple of API calls that we make there which are driven through integration rest API steps so but otherwise um you don't need to be on a integration Hub license of subcription cool and what type of item license is required when this is released it'll be part of U the item Enterprise uh capabilities so so all Cloud accelerate capabilities and the cam capabilities will be part of itom Enterprise licensing uh this will also be available uh in a standalone manner for customers with uh Discovery licenses so because that's a prerequisite Discovery or sorry visibility license not Discovery scratch that it's visibility item visibility licenses with enough visibility licenses uh you can add also add on um the cloud accelerate uh and the C license when it is released that's the plan thanks R I believe we can in interest of time we can keep going with the presentation gotcha gotcha thanks um I I I use this uh nice uh graphic to depict uh what is what is what is landing Zone and why is it important there so when you're actually uh you know going to land that helicopter there you want to be exactly right there in the center you can't be more to the right or left or anything like that it has to be exactly in the center of that place there otherwise your fan is going to get damaged or who knows right people might not be able to get off uh safely and all that so given all these things that's exactly the principle that is used for uh creation of uh Cloud uh Landing zones also what does that mean the landing zone is the place where uh a user of the cloud will will land they will they will get to a place right so inadvertently or willfully they cannot end up making mistakes there so put in the right uh you know necessary steps to ensure that the firewall is uh is is set up correctly the uh network security groups are set up correctly the uh Port groups are set up correctly the ports are you know not unnecessarily opened and all that so all of those uh necessary steps and then tagging policies are put in place budgetary controls are put in place so that's the whole idea behind Landing zones there and uh our our intent is to help you to get to a place where you're able to drive that in a in a in a better and a secure Manner and the way the landing zones are defined you're also able to go through change and uh you're able to ensure that um you know your your clients uh one don't make changes without going through the change process one second one is you know we also drive it through a a broader CC angle by bringing the policy concept there right this has been well uh acknowledged by uh several customers um I'll talk about one and a minute here uh one of the customers we spoke to in the initial time frame as as they were transforming and moving towards uh you know uh the the cloud in a in a bigger manner it's a large Bank um they were very keen about getting the landing zone right so the first Focus for them was just ensuring that the vanilla Landing Zone creation which they call the vanilla because it's a default for everybody if somebody had some very special needs uh some Special Steps were taken but the automated Landing Zone creation the vanilla Landing Zone creation is key for their uh better governance and simplified Cloud usage right that is the focus area for that uh specific it team which is also closely working with the cloud architecture and design there right uh I wanted to uh maybe U now switch into and go into a demo any questions to take before uh we go into a demo John I believe we can go ahead R most of them might be sounds good sounds good okay so I'm on the instance um uh I'm going to be you know log in first as admin but then I'll switch into the specific user roles that I talked about earlier uh there let me first um you know connect as the requestor here so impersonate and go in as okay I go as Beverly Beverly is a requester please remember Beverly's role is that of the the engineering lead or you know some important member of the team now Beverly is going to go to um the cloud account management request screen in the workspace you see that it's a very nice looking uh workspace where uh you know Beverly can already look at all her previous requests uh what has been approved what has been denied and uh also Beverly gets a very good breakdown of all of the accounts that she owns based on the services that they belong to so the payment service for which Beverly's team is in charge of they have several test accounts some development accounts and some production accounts similarly for the other services also right so in the same manner Beverly now is going to go and request uh for couple more accounts there uh let's see how this goes so clicking on the request button there uh Beverly is posted with first of all asking being asked the question like uh do you want an account for development do you want an account for production or for test um obviously uh Beverly is looking at creating initially a Dev account but she probably needs something for test also real quickly and maybe later she can actually create something for production here right so I going to uh click on when I click on next she's chosen multiple things so actually in the screen actually that's why it's very different from the regular catalog request here while underlying our request is handle and traditional approaches but the it's not the traditional catalog request here but because we wanted to give you the perspective that you're driving account creation from the point of view of the app from the point of view of the the Buu and the team and and the purpose right that's all very important to be brought in here so for development uh B can some now fill in details now she would always say what is my preferred cloud account what is my desired Cloud uh provider right account is a wrong term there I apologize for uh some cosmetic issues in this Innovation lab it's just as I said it's a protot type uh working prototype I would say still end to end working prototype for the creation aspects there but important to keep in mind is that some cosmetic issues we are working on improving those stories there so the desired cloud provider is what Beverly mentions here she would also set the date and the uh end date for uh this so we can set a uh you know uh date like uh let's say needed tomor today tomorrow onwards and uh we need it till maybe a month from now right and uh set the budget right 2,000 USD and then the project application which application it has to be connected into I'll say I'll go with Mobile Banking and uh who is the account owner I choose the account owner from my team uh from Beverly team basically and uh mention which engineering which department it is for and what is the bu bu uh where it is going to sit right so just just some points that Department business application all that and I will also put in the details of the uh you know uh tag that I want to add there which is the app ID that I want to add there right so that is in effect the small form that needs to be filled there uh that Beverly uh goes through and Beverly already sets up the connectivity with the application service so your csdm needs are kind of immediately getting made there the budget is also set there right now B can now set up the same uh similar kind of values for the uh test uh based account also um just go with you know maybe a shorter time frame here starting from tomorrow until end of the month right and uh after that it'll be suspended that's kind of the idea there and then I will set the same IDE as before whatever number I gave some random number I gave but whatever right so um and then account owner and all that can be set here it can be made uh also compulsory or mandatory here we just went with uh you know just for evaluation at this point of time we just went to this um the requester Beverly has the chance to edit and U modify certain things on on our last review level just check that everything is fine before she can go ahead and and clicking on the pencil will take back to the edit screen but go ahead and submit it now the requests have been uh given so coming here if I if I were to refresh this it's right now seven pending approvals but you'll see that it became nine because I added two more requests now and uh that's it Beverly's job is done she's come and she's given all the details there and uh we are looking at adding a few more Fields like okay give more details about what is application what is a project and all that stuff Let Me Maybe close this and uh let me impersonate as another user who is the next in the chain requestor approver right so I want to look at approver Mabel is the approver for these requests let me impersonate as Maybel and uh let me go into the tasks I have mayel so I'm now bill right so I'll go in I look at my tasks here I can take a look at all the tasks that have been created uh both of them uh have just come one is for test and one is for Dev I can go into this and I can see that immediately cost center is not mentioned okay that's a no no I'm not going to approve this but then this looks a little better 88 let me take a look at the request 88 uh and when I look at the request 88 um yeah all the data seems to be fail the budget is within limits if it was not it'll go through approval so everything seems to be okay there so my job simply is okay check and validate if everything is fine that's where we are also planning to use the data foundations component called policy es code and policy es code um is a component that um is allowed to drive the policy logic right and U Governor kind of a team governance kind of a team like the ccoe team uh who has that role policy admin role can set up the policies for automatic approval right that's kind of the idea that's coming as part of GA not it's not there in this Innovation lab release right now as I said it's manual more to show the you know power of the solution more than anything else now so now um mayel has approved that one request which was uh complete in pretty much every way and um that's it Mel's job is done let's now impersonate as the third uh role uh for um Kyle Kyle is the provisioner right and when I go in as Kyle uh uh I will be able to see um a little bit of different kind of uh menus here you see the role based access control is set up in such a way that uh for uh for the approver for instance only might as visible but for Kyle who's the provisioner because he has more permissions he can also set up the configuration and all that real quick if I show you the configuration and how it looks this is the account setup in the back end uh how the create request type is handled and what is the code that's being called for the ter from the terraform site what is the credentials used to connect in right so all of that is actually what is what has been set up here and this can be modified there right um but let me now go to my tasks and ask Kyle let me take a look at um you know the request that have come in there the last request that came in that was just approved is the request number 88 clicking on that um Kyle can now look at the request details and say okay it came from marketing it came from account owner U Anthony and it's for this cost center and it's for the project mobile banking so I know where to put this it's for development so I'm going to put it under the specific OU under o under AWS called the cam or and the cam or organization unit here so just based on some principles there again this is an area where we plan to use the policy as code engine to automate this decision making today as I said this is a little bit manual but uh practically in the back end everything works the same right so let me go ahead and uh provision this and when I provision this what happens in the back end is the request is started there you find here uh the request details it's it's got an approved and all that the provisioning is actually going on there the first step uh is is to is an instruction right series of activities so we can actually start off the process saying Mark that complete and when you click on that um The Playbook actually starts to work here it's preparing the execution flow and it'll go through the next steps here I can go back here and see that it's also now creating the workspace uh to look into a little more details here again thanks to the wonderful work done by the team here Mur enco uh you can actually see the request and uh it says the status is now is uh queued if I refresh it uh the status will change eventually to applying and applied and all that stuff so I can I can take a look even further I can go into the request ID uh sorry the execution ID and actually see more details of what's happening there right so all these uh you know interesting things are you know pretty much happening there so let me refresh once and see what's going on there okay it's now moved to status applying and if I come back to uh the the previous uh UI the previous page you will find that uh here it's moved into the next step when it is actually creating the account here right uh so basically uh you know in the back end cam is doing some pretty interesting stuff and this is where all the terraform related work and all that is is happening uh it's applying it it'll close shortly uh while that is happening any questions to take that are that are not already been answered thanks Ram yeah there are a couple so um they are asking about the customization of these flows how does that happen I I'll show that in a I'll show that in a minute I hold on that question right um uh while while while here by now just so you know the the account number is ready and the whole process has been created right and uh you can now go see this account number in the AWS organizations page uh for this account if I if I go in there right so please remember this was the same record that was running earlier and I refreshed it it's actually showing that as completed and the account number is here I'm taking that account number I'm going to paste it into uh the OU list here and uh you'll find that ah the same cam request 88 with their account number and and all those details is actually shown here this basically indicates that you actually have a working account that has now been created internally in the back end the tags as I mentioned there app ID and all that is actually set up here uh right and uh other details are also maybe I didn't set up ID I'm not sure but but yeah all those tags are uh set up here right that's actually pretty cool um so now if I go back to to this and I and I and I close this right um so the the request status is now completed and it should be showing huh the provisioned uh status has actually come in here and it's saying all these steps are actually completed here so basically uh in a very short time we were able to show that how the processes how the automation how the orchestration how the approvals everything ran quickly and uh we able to show uh the full process of the account creation there now if I end my impersonation uh I want to show you something very interesting about the uh usage of the uh process automation designer I'm back as admin now and I'm I'm going to quickly show you uh somebody was asking about the uh the process workflow and how to customize it so uh the whole thing is defined through the process automation designer pad in short and this pad is what is reflected as a playbook in the back end there so when you go to pad uh uh you know you are able to see all the steps in the in the in the in the pad process uh in a minute right now while this page loads so if I go into uh the process called so there are the default demo uh data kind of processes that are there but just take a look at the cam account creation process and we'll add more process cam account deletion cam account suspension all of those will become individual processes and this is the process with the multiple stages so it's very much like a vtb if you look at it that way it's like multiple lanes and multiple tasks in that lane this is the first instruction which needed to be uh set manually and then the rest of the steps actually come in there and each of the steps each of the lanes you can add additional steps you can basically say create workspace I want something more done here create account I want more something uh done here I can basically add any number of flow steps into the process and I can create as many number of new activities that I want and that's the way you customize the process a simple story right and uh once you've done everything you can go ahead and click on activate and you can you can try it out in fact uh the couple of things that I would like several of you who will be trying this out I will show the link to the app shortly please do try it out and uh please do reach out to us uh we'd love to engage with you in your custom steps that you're trying out so that uh we can think of more out of the box steps that we can provide one second one we want also validate with you how that customizable uh process actually works for you and if you're facing any issues in the process there so um hopefully that answers the question about the about the customizability and once you activate it the the new workflow will take over and R there right um so that's answering hopefully that question let me come back to uh the before I continue with the slides here any other questions uh folks I think there are there are many questions that we should answer so they're asking um if Camp can be deployed if there are existing Landing zones and uh if if it's possible to check for duplicates at this point of time yes that is definitely part of the plan we want to discover Landing zones and we want to bring it in into the topology itself we want to discover your and onboard your existing accounts that's part of the next steps here for GA itself will be discovering and uh providing a way to onboard your existing accounts uh and get them onto you know the the data certification aspects and all that so that's like the next part of the process there that we're looking at uh I would be very curious to know more about duplication of Landing zones um uh it'll be interesting to see uh what is the thinking around that feel free to reach out to me offline and we can have some more discussions about it uh any other important questions to go over yeah so for cloud account configuration and specifics of that how does the requestor know what will be created in terms of configuration the requestor does not need to know what ises it created in terms of configuration the requestor only passes the inputs to request flow the request flow will take care of using the configuration to connect into the right um you know terraform code or the CSD pipeline all of those uh details there right that's handled there it's a single request flow at this point of time um we can certainly look at um multiple request flows in the in the future based on maybe several configurations but right now in the first first in this lab release it's only a single request flow thanks R any was the next question yeah yeah um so account deactivation availability in come MH uh when is yeah there of course that plan that's for the that's for the ga as I mentioned uh sorry the not the ga it's it's it's planned for the Q2 time frame uh it's called um we we are looking at uh release uh either as controlled go to market or as a g it's not yet defined um either way please stay with us and work with us closely suspension is definitely in inactivation is is definitely planned as part of that uh story any other question we should take yeah yeah another one is for the level of permission that the user needs to have uh for the integration for the cloud provisioning so what type of security is given uh to the credential config for the integration um I probably uh mle you want to kind of touch upon the security aspects that are considered there uh while while M brings up the details on that I want to also go to the next slide here and leave this open so that you have time to uh use your uh cell phones or click that QR code and um go to that uh store and uh be able to get the link for the cam app so so go ahead M the question was about um permissions okay so let me bring it just give me one minute okay no you can talk through it for the time being because I'm keeping this screen open for uh the QR code you can just talk through high level permission ideas so here is what right so thing is uh the whole Assumption of this project is right we assume that you have a master or organization account already set up right and we are asking to create a uh service account for us right for us to do the complete job right the reason is uh so this is a create role it's not like say the discovery has only readly access right so this is actually creating a resource in your side right so what youve done is in our documentation we have given a step say okay we want a service account created with limited permissions right so we can do only certain jobs for creating the account nothing else say we cannot create an S3 bucket we cannot create an VPC at all right so if at all we want to do it in future where we need to work together in say customizing those roles right so in a nutshell we are asking for a very specific permissions and uh from your AWS administrator to give us a permission right so that we are doing that job so did you answer your question no no yeah no I I think that gives a very very good flow there so the permissions can be restricted to the service account from that standpoint right and um the standard permissions apply there it is all documented it's too long not too long but too detailed a list to go over at this point of time if you go to the store Page the Bas by click on this QR code and you go to the link in the store Page the PDF is available there on the right side because it's Innovation lab we don't have pages in The docs. Serv now.com but all documentation is in that PDF please download the PDF it'll give you all the details as to what permissions are needed there right so please do keep that in mind mind uh and and try it out again we are very conscious about what permissions are are needed there nothing in excess is actually asked there but what is needed is needed without it our product wouldn't function so that's an important uh discussion to be had there so there's a couple more questions uh that I can see here uh the process is not tied to service catalog or record producer uh yes we did not go with the traditional service catalog record producer because we are trying to keep this as a generic uh multi account account creation uh kind of a process there uh in the back end uh you know the records are all available in a in a traditional way and um I would be very keen and interested to know if that breaks anything badly for you but yeah certainly something we can actually look into uh Rand deep G thanks for your question if this looks repeated what level of Cloud knowledge is required to customize the process flows or to start using the cam tool um a certain amount of cloud knowledge is definitely needed uh in terms of uh being able to uh you know Drive uh certain aspects of uh you know the let's say the OU uh account setup and uh things like that but other than that we give you all the basic building blocks here right everything that will need customization is all about your integration to other tool chains like for instance some people mentioned that they have salepoint integrated into their workflow some people mentioned that they have a cicd pipeline integrated into their workflow there so your integration may not be so much with the cloud cloud but more to do with the tool sets that you might have because you want to integrate that into the process there which is flow designer frankly automation engine knowledge that you have anywhere you just need to know the rest apis to call and uh we are able to help you in that in that in that process there but most of the cloud part of the story like account creation account deletion account suspension um uh you know things like uh permission check checking and all that stuff we are giving it to you as building blocks so you don't have to invest time in creating those as part of the story which is where again please do keep us actually uh informed about where are the areas where uh you know you struggle because maybe Cloud knowledge is not adequate on your side and that's the area we'll strive to make the building blocks available to you as as you know jigsa pule pieces that you can actually fit into the story there that's kind of a thinking there so this has also been answered live and um last but not least I just want to kind of say you know please do try it out again as I said AWS is what is supported only the creation of the account is supported in this Innovation lab but we'll follow suit very quickly with more capabilities the inactivation is planned uh the inactivation of the account AWS account is planned and the and the and the uh data certification of the AWS account is planned so all of these are kind of uh coming as coming forth as next steps with the customizability and in built capabilities like running Discovery automatically as soon as a you know as soon as the creation is completed so all of that is planned as part of the next steps there please work with us on this journey we we'd love to uh get your feedback on that um if if you're facing any issues feel free to reach out to me and uh uh and John we'll open in the R&D as needed here but if you're facing any issues anywhere any questions anywhere please do uh feel free to reach out to us we'll help you in the in the process there um the next slide uh uh there's one more question and answer maybe we can go over real quick yeah absolutely Ram Bruno asked a question that when the link I received the application that you're looking for the the application is is is available worldwide uh from the store but it's hidden in the store so uh maybe we'll follow up uh with sending the the link actually is posted in the in the chat here so and it it it should uh Arab it should install on PDI also no issues right uh from PDI also it'll install because I I published it I set up very clearly that PDI uh install is supported there so it should work so if you have any issues feel free to reach out to um you know like I said uh me at this email ID I'll just post my email ID and then please feel to reach out to me I'll help you yeah you can post your email in the chat room so yeah I'm posting it I'm posting it but I fat fingered something I'll just type it again thank you that's my that's my email ID yeah there you go great fantastic thank you so much RAM and Morley it was great uh great content great presentation and a lot to cover today as usual and thanks everyone for participating in polls uh this was an amazing crowd an amazing audience today so we really appreciate your great feedback and uh curiosity for sure um we'll definitely make sure that you will be able to download the app and if the links are not working let us know Ram has just posted his email in the chat and for the next sessions we'll have another session on February already and once per month uh as uh usual that's what we we we're committing for this year as well for the um uh iton visibility and Cloud accelerat Academy so please make sure that you scan this QR code and you use the link in the chat uh if Steve you can post it or Ram then that would be great so um you can it's still the same link that we posted at the very beginning of the session and that's it for today thank you so much again Ramy mle and thank you Steve and uh everyone else uh thank you so much uh especially for the panelist so we're talking about Bill we're talking about do we're talking about Kim and everyone else really that has keep uh kept helping us in this amazing session this just the starting of the year so get excited for the next sessions we'll wait you um and we'll see you there soon have a great rest of your day and uh looking forward to see you soon
https://www.youtube.com/watch?v=vi5PCS3jEhA