Cloud platforms that pass the audit and survive the incident.

494 Group builds cloud platforms and the software that runs on them: applications, APIs and the integrations between systems, with compliance, logging, monitoring and automated updates designed in rather than bolted on afterwards. Operated through the audits and the outages, then handed over documented and running. Led by one principal engineer, with specialists brought in when the work calls for it.

3 weeksdeployment path, down from nine months
45+data centers, every region but two
700corporate tenants migrated, four waves
AWSGoogle CloudAzureIBM Cloud TerraformKubernetesDatabricks HIPAAHITRUSTSOC 2PCI-DSSFedRAMP

The numbers

Three engagements, measured the way the client measured them.

3 weeks
down from nine months

Automating the deployment path let a global cloud service expand into new regions on a quarterly cadence instead of an annual one.

45+
data centers, every region but two

Object storage and key management built out across a global public cloud, reaching every region worldwide except two single-campus locations.

700
corporate tenants, four waves, six months

An installed base migrated to the cloud one database per tenant, each wave cut over inside a Friday-to-Monday window with a rollback plan written for it.


What I get called for

Usually before the planning starts. Sometimes after something has gone sideways.

  • A platform that has to pass an audit

    Compliance designed into the platform rather than assembled at audit time: policy scanning before infrastructure exists, a security review every new capability clears, and a platform that produces its own evidence.

  • A product to build, not just a platform to run it on

    Cloud applications, APIs and the integrations that connect them to systems somebody else owns. Compliance, logging, monitoring and unattended updates are part of the design rather than a later phase, because retrofitting them costs more than building them in and usually lands just before an audit.

  • Critical workloads that cannot break during the move

    A migration is only as safe as your ability to rehearse it, and nothing hand-assembled can be rehearsed. Automating the build, test and deploy path comes first; that is what turns a seven-hundred-tenant move into something you can practice, wave by wave, inside a window the business agreed in advance.

  • Build, test and deploy still done by hand

    Replacing manual deployments with an automated path from build through test to production, so a release stops depending on who is available to run it and a second environment costs hours instead of weeks.

  • Software built with AI agents, without shipping the wrong thing

    Coding agents run under defined roles with automated gates and independent verification, and engineers brought onto that way of working rather than left to discover it.

  • More to deliver than the team can carry

    An executive with a mandate, and architects already building new capability while keeping the existing platforms running and extended. Both at once is what runs a good team out of room. I add senior capacity alongside them rather than oversight above them, come up to speed quickly on what is already built, and work with the architects and the executive together toward what they are trying to achieve.

  • A team that has to own it after I leave

    Hiring, onboarding and technical leadership for the group that inherits the platform. On one engagement I mentored a senior engineer through taking the architecture on; he is now that company's principal architect for it, hired directly by them. The handover is the deliverable.


Regulated is the normal case here, not a specialism

Most of the last decade has been platforms someone else has to certify.

HIPAA, HITRUST

A compliant Databricks platform for a national healthcare payer: every environment provisioned as code through one pipeline, policy scanning catching misconfiguration before infrastructure exists, and a standing security review each new capability clears before anyone can use it.

SOC 2

Five years leading SOC 2 audits for a key management platform inside a global public cloud, and deciding what evidence the platform itself should produce rather than assembling it by hand each year.

FedRAMP, PCI-DSS, ISO 27001

Took part in those audits for the same platform, and planned the architecture and product features that made the service auditable in the first place.

Continuity

Business-continuity and disaster-recovery runbooks written at design time and exercised annually, deliberately without the people who built each service, because the point is to find the steps that exist only in someone's head.


Scott Rooke

One principal, nearly thirty years in.

I am Scott Rooke. 494 Group, Inc. is a Minnesota S-corporation, incorporated in 2017, and I have been taking work through my own company since 2006. The work is led and delivered by one principal engineer, which is why the estimate is honest and the person who scoped it is the person who builds it.

I have been consulting since 1997. Eight of those years, beginning in 2015, were spent inside a global public cloud, where I built out and then ran the key management and object storage services other companies had built their businesses on. Both went to every region worldwide except two, past 45 data centers. If the key management service is down, nothing encrypts or decrypts. If object storage is down, nothing can write a log. You design differently once that is your problem, and you find out quickly what it costs to get it wrong.

When an engagement needs more hands than one, I bring in specialists I have worked with directly. There is no bench to keep busy and no handover to someone you have not met. I have built the large version of this: one engagement grew from a team of one to more than seventy engineers across thirteen product teams, and I did the hiring, the onboarding and the technical leadership for it.


How engagements work

Entity
  • 494 Group, Inc., a Minnesota S-corporation since 2017
Contracting
  • Corp-to-corp through my company
  • Or as a subcontractor through a consulting partner
Work
  • Architecture and design, through to the running system
  • Hands-on build: application code, infrastructure, pipelines, automation
  • Migration planning and delivery leadership
  • Compliance and audit readiness
  • Senior capacity alongside architects already stretched between new capability and the platforms they are keeping running

Most engagements are a mix, and which one leads changes as the work moves.

Location
  • Minneapolis, Minnesota
  • On site across the Twin Cities metro
  • Travel as the engagement needs it
  • Remote otherwise

Kick-offs and working sessions tend to go better in person.

Scale
  • One principal by default
  • Specialists I have worked with, added per engagement when the scope needs them

Field notes

The parts of the work that will not fit in a résumé bullet, written up at the length they take to say properly.


Tell me what you are up against, and I will tell you what I would do about it.

Useful to include: what you are building or moving, what regulatory regime it sits under if any, roughly when it needs to happen, and whether you need someone to design it, to lead the team building it, or both.

Start a conversation