Four levels, and policy set anywhere flows to everything below it.
Folders exist purely for grouping and inheritance โ they hold no resources of their own.
OrganizationRoot node, tied to a verified domain
FoldersNestable grouping โ by environment or by team
ProjectsThe real isolation boundary
ResourcesVMs, buckets, tables, topics
Terminology across clouds
ConceptGCPAWS / Azure
Root nodeOrganizationOrg / Tenant
GroupingFolderOU / Mgmt Group
IsolationProjectAccount / Sub.
GuardrailOrg PolicySCP / Azure Policy
Design folders around what needs a different policy, not around the org chart โ matching policy on both sides adds depth with zero governance benefit.