AWS Control Tower customers can now programmatically manage controls, also known as guardrails, across their organization at scale. Customers can programmatically enable, disable, and view application status of controls available in the AWS Control Tower library. Control APIs include AWS CloudFormation support, allowing customers to manage AWS resources as infrastructure as code (IaC). AWS Control Tower provides optional preventive and detective controls that customers can use to express their policy intentions to an entire organizational unit (OU), and every AWS account within the OU. These rules remain in effect as customers create new accounts or make changes to their existing accounts.