Getting Started
From requesting a tenant to provisioning your first resource — the full onboarding journey on Global Infra Cloud.
How onboarding works
Getting started on Global Infra involves three roles working in sequence:
| Role | Who | What they do |
|---|---|---|
| Tenant Owner | The architect or tech lead who sponsors the project | Requests the tenant, attends the onboarding committee, manages environment access rights |
| GGO Owner | Team lead or line manager | Creates user groups (GGO), adds and removes team members |
| Team Member | Every engineer on the project | Sets up personal access (VPN, workspace, Console) and provisions resources |
For Tenant Owners
Pass the Architecture Review Board (ARB)
All cloud migrations require approval from the Architecture Review Board (ARB). The ARB validates your architecture against company standards and provides design support.
Submit your architecture for review — the ARB checks completion, compliance, and best practices.
Get approved and prepare for the Onboarding Committee
Once the ARB approves your request, contact the Global Infra team. They will:
- Create a Jira ticket with all onboarding details (do not create this yourself — it will be rejected)
- Invite your sponsoring architect to the GI Onboarding Committee, which meets every 2 weeks
The Onboarding Committee (GI management level) performs a final review to check coverage, suggest new services, verify cloud best practices, and plan capacity.
Have the following ready for the committee:
- ARB Jira ticket
- ARB Confluence page (with architecture diagram)
- Tenant owner name(s)
- Legal Entity Code (for billing)
- Sizing estimates (compute, databases, storage)
Receive your tenant
Once the committee gives the green light, your tenant is created. You will receive:
- Your tenant with sandbox, preproduction, and production environments
- A dedicated Slack channel (
#globalinfra-<tenantname>) where GI sends all communications - Access to the Console to manage your tenant’s access rights and assign roles to GGO groups
For Team Members
Once your tenant exists and your GGO owner has added you to a group, follow these steps to get up and running.
Get access
You need an OKTA user account and VPN access to connect to GI environments. Your GGO owner adds you to the group — you then set up NetBird for VPN connectivity.
Configure your workspace
Set up your DNS, proxy settings, certificates, and SSH keys for your environment.
Sign in to the Console
Navigate to the Global Infra Cloud Console and sign in with your OKTA credentials. Select the tenant and environment you want to work with.
Provision your first resource
Browse the service catalog, pick a service, and provision resources through the Console UI or via Terraform. Most resources are ready in minutes.
Identity & Access Management
Global Infra uses a group-based IAM model. Permissions are never assigned to individual accounts — they are assigned to GGO groups via roles.
Key concepts
| Concept | Description |
|---|---|
| GGO (Global Group Organisational) | A group of users matching an official organization structure. All members share the same roles and permissions. |
| GGO Owner | The team lead or manager who manages group membership — adds/removes users via the Console. |
| Environment Owner | The tenant owner who decides which GGO groups get which roles on each environment. |
| Role | A combination of platform (sandbox / preprod / prod), namespace, and privilege level. |
Available roles
| Role | Description |
|---|---|
| sysadmin | Full server administration — build, erase, admin access, manage infra code |
| apps | Application support team |
| dba | Database administration (tenant-managed engines) |
| security | Security officer — server access and audit log review |
| operators | Level 1 support |
| netadmin | Network administrator — connectivity checks and config review |
These roles apply when databases are provided by GI as Database as a Service. Each role includes the privileges of the ones below it.
| Role | Description |
|---|---|
| dbaas-adm | Full database operations including DDL (create tables, sequences, etc.) |
| dbaas-rw | Read and write data (insert, update) |
| dbaas-ro | Read-only access (select) |
| Role | Description |
|---|---|
| netonly | Network access to the environment without server access — useful for application admin portals |
| obs | Access to observability tools (telemetry, logs) without other permissions — for users depending on services outside their environment |
A user must belong to exactly one GGO group. Only the GGO owner can manage membership, and only the environment owner can assign roles. These constraints ensure auditability and separation of duties.