Organization policy
Wishful thinking is not sound policy
An organization policy is a restriction or constraint that you can set over the use of a service. For example, you may want to restrict the use of public IPs to some specifics VMs only (or none). The restriction is set on a resource hierarchy node, meaning you set it at the organization, folder, or project level. The types of restrictions and how inheritance is applied is well explained in the public documentation.
Organization policies are of major importance as those allow you to enforce and propagate governance rules across all your entire Google Cloud organization. Those policies can be set up quickly and will prevent your company from undesired wrong practices taken by your different teams. Organization policies also help being compliant with different regulatory policies. For example, you can limit sharing with external parties or determine where to deploy cloud resources geographically.
Here is a list of some key organizational policies we usually recommend companies to activate:
There are close to hundred organization policies that can be set up and while we insist on a few ones, we will check with your team what other policies make sense for your company.
At this stage it's also important to assign someone as "Organization Policy Adminsitrator" within your company. This person will be responsible for activating and guardkeeping Google Clodu organization policies for your company. The following diagram gives a good context about the implication of this role:
Last updated