Landing zones, networking, and identity baselines
Shared VPC or hub-spoke models, private service connect, and least-privilege project/folder structures. Federation to your IdP so data engineers do not hold standing admin keys.
Baseline modules for logging, backup, and break-glass are documented for auditors from day one.