Designs and implements AWS tag governance automation across Organizations TagPolicy JSON (allowed_values, case_sensitive, enforced_for cascade), EventBridge + Lambda auto-tagging on EC2/S3/Lambda creation (derive Owner from IAM identity, Environment from account map), Resource Groups Tagging API bulk operations (tag-resources, untag-resources, get-resources multi-region), Config required-tags managed rule + Security Hub finding aggregation, cost-allocation-tag activation via Billing API (user-defined vs AWS-generated), and ABAC IAM policy design with aws:ResourceTag and aws:PrincipalTag condition keys.