diff --git a/LICENSE b/LICENSE
new file mode 100644
--- /dev/null
+++ b/LICENSE
@@ -0,0 +1,367 @@
+Mozilla Public License Version 2.0
+==================================
+
+1. Definitions
+--------------
+
+1.1. "Contributor"
+    means each individual or legal entity that creates, contributes to
+    the creation of, or owns Covered Software.
+
+1.2. "Contributor Version"
+    means the combination of the Contributions of others (if any) used
+    by a Contributor and that particular Contributor's Contribution.
+
+1.3. "Contribution"
+    means Covered Software of a particular Contributor.
+
+1.4. "Covered Software"
+    means Source Code Form to which the initial Contributor has attached
+    the notice in Exhibit A, the Executable Form of such Source Code
+    Form, and Modifications of such Source Code Form, in each case
+    including portions thereof.
+
+1.5. "Incompatible With Secondary Licenses"
+    means
+
+    (a) that the initial Contributor has attached the notice described
+        in Exhibit B to the Covered Software; or
+
+    (b) that the Covered Software was made available under the terms of
+        version 1.1 or earlier of the License, but not also under the
+        terms of a Secondary License.
+
+1.6. "Executable Form"
+    means any form of the work other than Source Code Form.
+
+1.7. "Larger Work"
+    means a work that combines Covered Software with other material, in
+    a separate file or files, that is not Covered Software.
+
+1.8. "License"
+    means this document.
+
+1.9. "Licensable"
+    means having the right to grant, to the maximum extent possible,
+    whether at the time of the initial grant or subsequently, any and
+    all of the rights conveyed by this License.
+
+1.10. "Modifications"
+    means any of the following:
+
+    (a) any file in Source Code Form that results from an addition to,
+        deletion from, or modification of the contents of Covered
+        Software; or
+
+    (b) any new file in Source Code Form that contains any Covered
+        Software.
+
+1.11. "Patent Claims" of a Contributor
+    means any patent claim(s), including without limitation, method,
+    process, and apparatus claims, in any patent Licensable by such
+    Contributor that would be infringed, but for the grant of the
+    License, by the making, using, selling, offering for sale, having
+    made, import, or transfer of either its Contributions or its
+    Contributor Version.
+
+1.12. "Secondary License"
+    means either the GNU General Public License, Version 2.0, the GNU
+    Lesser General Public License, Version 2.1, the GNU Affero General
+    Public License, Version 3.0, or any later versions of those
+    licenses.
+
+1.13. "Source Code Form"
+    means the form of the work preferred for making modifications.
+
+1.14. "You" (or "Your")
+    means an individual or a legal entity exercising rights under this
+    License. For legal entities, "You" includes any entity that
+    controls, is controlled by, or is under common control with You. For
+    purposes of this definition, "control" means (a) the power, direct
+    or indirect, to cause the direction or management of such entity,
+    whether by contract or otherwise, or (b) ownership of more than
+    fifty percent (50%) of the outstanding shares or beneficial
+    ownership of such entity.
+
+2. License Grants and Conditions
+--------------------------------
+
+2.1. Grants
+
+Each Contributor hereby grants You a world-wide, royalty-free,
+non-exclusive license:
+
+(a) under intellectual property rights (other than patent or trademark)
+    Licensable by such Contributor to use, reproduce, make available,
+    modify, display, perform, distribute, and otherwise exploit its
+    Contributions, either on an unmodified basis, with Modifications, or
+    as part of a Larger Work; and
+
+(b) under Patent Claims of such Contributor to make, use, sell, offer
+    for sale, have made, import, and otherwise transfer either its
+    Contributions or its Contributor Version.
+
+2.2. Effective Date
+
+The licenses granted in Section 2.1 with respect to any Contribution
+become effective for each Contribution on the date the Contributor first
+distributes such Contribution.
+
+2.3. Limitations on Grant Scope
+
+The licenses granted in this Section 2 are the only rights granted under
+this License. No additional rights or licenses will be implied from the
+distribution or licensing of Covered Software under this License.
+Notwithstanding Section 2.1(b) above, no patent license is granted by a
+Contributor:
+
+(a) for any code that a Contributor has removed from Covered Software;
+    or
+
+(b) for infringements caused by: (i) Your and any other third party's
+    modifications of Covered Software, or (ii) the combination of its
+    Contributions with other software (except as part of its Contributor
+    Version); or
+
+(c) under Patent Claims infringed by Covered Software in the absence of
+    its Contributions.
+
+This License does not grant any rights in the trademarks, service marks,
+or logos of any Contributor (except as may be necessary to comply with
+the notice requirements in Section 3.4).
+
+2.4. Subsequent Licenses
+
+No Contributor makes additional grants as a result of Your choice to
+distribute the Covered Software under a subsequent version of this
+License (see Section 10.2) or under the terms of a Secondary License (if
+permitted under the terms of Section 3.3).
+
+2.5. Representation
+
+Each Contributor represents that the Contributor believes its
+Contributions are its original creation(s) or it has sufficient rights
+to grant the rights to its Contributions conveyed by this License.
+
+2.6. Fair Use
+
+This License is not intended to limit any rights You have under
+applicable copyright doctrines of fair use, fair dealing, or other
+equivalents.
+
+2.7. Conditions
+
+Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
+in Section 2.1.
+
+3. Responsibilities
+-------------------
+
+3.1. Distribution of Source Form
+
+All distribution of Covered Software in Source Code Form, including any
+Modifications that You create or to which You contribute, must be under
+the terms of this License. You must inform recipients that the Source
+Code Form of the Covered Software is governed by the terms of this
+License, and how they can obtain a copy of this License. You may not
+attempt to alter or restrict the recipients' rights in the Source Code
+Form.
+
+3.2. Distribution of Executable Form
+
+If You distribute Covered Software in Executable Form then:
+
+(a) such Covered Software must also be made available in Source Code
+    Form, as described in Section 3.1, and You must inform recipients of
+    the Executable Form how they can obtain a copy of such Source Code
+    Form by reasonable means in a timely manner, at a charge no more
+    than the cost of distribution to the recipient; and
+
+(b) You may distribute such Executable Form under the terms of this
+    License, or sublicense it under different terms, provided that the
+    license for the Executable Form does not attempt to limit or alter
+    the recipients' rights in the Source Code Form under this License.
+
+3.3. Distribution of a Larger Work
+
+You may create and distribute a Larger Work under terms of Your choice,
+provided that You also comply with the requirements of this License for
+the Covered Software. If the Larger Work is a combination of Covered
+Software with a work governed by one or more Secondary Licenses, and the
+Covered Software is not Incompatible With Secondary Licenses, this
+License permits You to additionally distribute such Covered Software
+under the terms of such Secondary License(s), so that the recipient of
+the Larger Work may, at their option, further distribute the Covered
+Software under the terms of either this License or such Secondary
+License(s).
+
+3.4. Notices
+
+You may not remove or alter the substance of any license notices
+(including copyright notices, patent notices, disclaimers of warranty,
+or limitations of liability) contained within the Source Code Form of
+the Covered Software, except that You may alter any license notices to
+the extent required to remedy known factual inaccuracies.
+
+3.5. Application of Additional Terms
+
+You may choose to offer, and to charge a fee for, warranty, support,
+indemnity or liability obligations to one or more recipients of Covered
+Software. However, You may do so only on Your own behalf, and not on
+behalf of any Contributor. You must make it absolutely clear that any
+such warranty, support, indemnity, or liability obligation is offered by
+You alone, and You hereby agree to indemnify every Contributor for any
+liability incurred by such Contributor as a result of warranty, support,
+indemnity or liability terms You offer. You may include additional
+disclaimers of warranty and limitations of liability specific to any
+jurisdiction.
+
+4. Inability to Comply Due to Statute or Regulation
+---------------------------------------------------
+
+If it is impossible for You to comply with any of the terms of this
+License with respect to some or all of the Covered Software due to
+statute, judicial order, or regulation then You must: (a) comply with
+the terms of this License to the maximum extent possible; and (b)
+describe the limitations and the code they affect. Such description must
+be placed in a text file included with all distributions of the Covered
+Software under this License. Except to the extent prohibited by statute
+or regulation, such description must be sufficiently detailed for a
+recipient of ordinary skill to be able to understand it.
+
+5. Termination
+--------------
+
+5.1. The rights granted under this License will terminate automatically
+if You fail to comply with any of its terms. However, if You become
+compliant, then the rights granted under this License from a particular
+Contributor are reinstated (a) provisionally, unless and until such
+Contributor explicitly and finally terminates Your grants, and (b) on an
+ongoing basis, if such Contributor fails to notify You of the
+non-compliance by some reasonable means prior to 60 days after You have
+come back into compliance. Moreover, Your grants from a particular
+Contributor are reinstated on an ongoing basis if such Contributor
+notifies You of the non-compliance by some reasonable means, this is the
+first time You have received notice of non-compliance with this License
+from such Contributor, and You become compliant prior to 30 days after
+Your receipt of the notice.
+
+5.2. If You initiate litigation against any entity by asserting a patent
+infringement claim (excluding declaratory judgment actions,
+counter-claims, and cross-claims) alleging that a Contributor Version
+directly or indirectly infringes any patent, then the rights granted to
+You by any and all Contributors for the Covered Software under Section
+2.1 of this License shall terminate.
+
+5.3. In the event of termination under Sections 5.1 or 5.2 above, all
+end user license agreements (excluding distributors and resellers) which
+have been validly granted by You or Your distributors under this License
+prior to termination shall survive termination.
+
+************************************************************************
+*                                                                      *
+*  6. Disclaimer of Warranty                                           *
+*  -------------------------                                           *
+*                                                                      *
+*  Covered Software is provided under this License on an "as is"       *
+*  basis, without warranty of any kind, either expressed, implied, or  *
+*  statutory, including, without limitation, warranties that the       *
+*  Covered Software is free of defects, merchantable, fit for a        *
+*  particular purpose or non-infringing. The entire risk as to the     *
+*  quality and performance of the Covered Software is with You.        *
+*  Should any Covered Software prove defective in any respect, You     *
+*  (not any Contributor) assume the cost of any necessary servicing,   *
+*  repair, or correction. This disclaimer of warranty constitutes an   *
+*  essential part of this License. No use of any Covered Software is   *
+*  authorized under this License except under this disclaimer.         *
+*                                                                      *
+************************************************************************
+
+************************************************************************
+*                                                                      *
+*  7. Limitation of Liability                                          *
+*  --------------------------                                          *
+*                                                                      *
+*  Under no circumstances and under no legal theory, whether tort      *
+*  (including negligence), contract, or otherwise, shall any           *
+*  Contributor, or anyone who distributes Covered Software as          *
+*  permitted above, be liable to You for any direct, indirect,         *
+*  special, incidental, or consequential damages of any character      *
+*  including, without limitation, damages for lost profits, loss of    *
+*  goodwill, work stoppage, computer failure or malfunction, or any    *
+*  and all other commercial damages or losses, even if such party      *
+*  shall have been informed of the possibility of such damages. This   *
+*  limitation of liability shall not apply to liability for death or   *
+*  personal injury resulting from such party's negligence to the       *
+*  extent applicable law prohibits such limitation. Some               *
+*  jurisdictions do not allow the exclusion or limitation of           *
+*  incidental or consequential damages, so this exclusion and          *
+*  limitation may not apply to You.                                    *
+*                                                                      *
+************************************************************************
+
+8. Litigation
+-------------
+
+Any litigation relating to this License may be brought only in the
+courts of a jurisdiction where the defendant maintains its principal
+place of business and such litigation shall be governed by laws of that
+jurisdiction, without reference to its conflict-of-law provisions.
+Nothing in this Section shall prevent a party's ability to bring
+cross-claims or counter-claims.
+
+9. Miscellaneous
+----------------
+
+This License represents the complete agreement concerning the subject
+matter hereof. If any provision of this License is held to be
+unenforceable, such provision shall be reformed only to the extent
+necessary to make it enforceable. Any law or regulation which provides
+that the language of a contract shall be construed against the drafter
+shall not be used to construe this License against a Contributor.
+
+10. Versions of the License
+---------------------------
+
+10.1. New Versions
+
+Mozilla Foundation is the license steward. Except as provided in Section
+10.3, no one other than the license steward has the right to modify or
+publish new versions of this License. Each version will be given a
+distinguishing version number.
+
+10.2. Effect of New Versions
+
+You may distribute the Covered Software under the terms of the version
+of the License under which You originally received the Covered Software,
+or under the terms of any subsequent version published by the license
+steward.
+
+10.3. Modified Versions
+
+If you create software not governed by this License, and you want to
+create a new license for such software, you may create and use a
+modified version of this License if you rename the license and remove
+any references to the name of the license steward (except to note that
+such modified license differs from this License).
+
+10.4. Distributing Source Code Form that is Incompatible With Secondary
+Licenses
+
+If You choose to distribute Source Code Form that is Incompatible With
+Secondary Licenses under the terms of this version of the License, the
+notice described in Exhibit B of this License must be attached.
+
+Exhibit A - Source Code Form License Notice
+-------------------------------------------
+
+  This Source Code Form is subject to the terms of the Mozilla Public
+  License, v. 2.0. If a copy of the MPL was not distributed with this
+  file, You can obtain one at http://mozilla.org/MPL/2.0/.
+
+If it is not possible or desirable to put the notice in a particular
+file, then You may include the notice in a location (such as a LICENSE
+file in a relevant directory) where a recipient would be likely to look
+for such a notice.
+
+You may add additional accurate notices of copyright ownership.
diff --git a/README.md b/README.md
new file mode 100644
--- /dev/null
+++ b/README.md
@@ -0,0 +1,44 @@
+# Amazon Control Tower SDK
+
+* [Version](#version)
+* [Description](#description)
+* [Contribute](#contribute)
+* [Licence](#licence)
+
+
+## Version
+ 
+`2.0` - Derived from API version @2018-05-10@ of the AWS service descriptions, licensed under Apache 2.0.
+
+## Description
+
+Documentation is available via [Hackage](http://hackage.haskell.org/package/amazonka-controltower)
+and the [AWS API Reference](https://aws.amazon.com/documentation/).
+
+The types from this library are intended to be used with [amazonka](http://hackage.haskell.org/package/amazonka),
+which provides mechanisms for specifying AuthN/AuthZ information, sending requests,
+and receiving responses.
+
+Lenses are used for constructing and manipulating types,
+due to the depth of nesting of AWS types and transparency regarding
+de/serialisation into more palatable Haskell values.
+The provided lenses should be compatible with any of the major lens libraries
+[lens](http://hackage.haskell.org/package/lens) or [lens-family-core](http://hackage.haskell.org/package/lens-family-core).
+
+See [Amazonka.ControlTower](http://hackage.haskell.org/package/amazonka-controltower/docs/Amazonka-ControlTower.html)
+or [the AWS documentation](https://aws.amazon.com/documentation/) to get started.
+
+
+## Contribute
+
+For any problems, comments, or feedback please create an issue [here on GitHub](https://github.com/brendanhay/amazonka/issues).
+
+> _Note:_ this library is an auto-generated Haskell package. Please see `amazonka-gen` for more information.
+
+
+## Licence
+
+`amazonka-controltower` is released under the [Mozilla Public License Version 2.0](http://www.mozilla.org/MPL/).
+
+Parts of the code are derived from AWS service descriptions, licensed under Apache 2.0.
+Source files subject to this contain an additional licensing clause in their header.
diff --git a/amazonka-controltower.cabal b/amazonka-controltower.cabal
new file mode 100644
--- /dev/null
+++ b/amazonka-controltower.cabal
@@ -0,0 +1,91 @@
+cabal-version:      2.2
+name:               amazonka-controltower
+version:            2.0
+synopsis:           Amazon Control Tower SDK.
+homepage:           https://github.com/brendanhay/amazonka
+bug-reports:        https://github.com/brendanhay/amazonka/issues
+license:            MPL-2.0
+license-file:       LICENSE
+author:             Brendan Hay
+maintainer:
+  Brendan Hay <brendan.g.hay+amazonka@gmail.com>, Jack Kelly <jack@jackkelly.name>
+
+copyright:          Copyright (c) 2013-2023 Brendan Hay
+category:           AWS
+build-type:         Simple
+extra-source-files:
+  fixture/*.proto
+  fixture/*.yaml
+  README.md
+  src/.gitkeep
+
+description:
+  Derived from API version @2018-05-10@ of the AWS service descriptions, licensed under Apache 2.0.
+  .
+  The types from this library are intended to be used with <http://hackage.haskell.org/package/amazonka amazonka>,
+  which provides mechanisms for specifying AuthN/AuthZ information, sending requests, and receiving responses.
+  .
+  It is recommended to use generic lenses or optics from packages such as <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify optional fields and deconstruct responses.
+  .
+  Generated lenses can be found in "Amazonka.ControlTower.Lens" and are
+  suitable for use with a lens package such as <http://hackage.haskell.org/package/lens lens> or <http://hackage.haskell.org/package/lens-family-core lens-family-core>.
+  .
+  See "Amazonka.ControlTower" and the <https://aws.amazon.com/documentation/ AWS documentation> to get started.
+
+source-repository head
+  type:     git
+  location: git://github.com/brendanhay/amazonka.git
+  subdir:   amazonka-controltower
+
+library
+  default-language: Haskell2010
+  hs-source-dirs:   src gen
+  ghc-options:
+    -Wall -fwarn-incomplete-uni-patterns
+    -fwarn-incomplete-record-updates -funbox-strict-fields
+
+  exposed-modules:
+    Amazonka.ControlTower
+    Amazonka.ControlTower.DisableControl
+    Amazonka.ControlTower.EnableControl
+    Amazonka.ControlTower.GetControlOperation
+    Amazonka.ControlTower.Lens
+    Amazonka.ControlTower.ListEnabledControls
+    Amazonka.ControlTower.Types
+    Amazonka.ControlTower.Types.ControlOperation
+    Amazonka.ControlTower.Types.ControlOperationStatus
+    Amazonka.ControlTower.Types.ControlOperationType
+    Amazonka.ControlTower.Types.EnabledControlSummary
+    Amazonka.ControlTower.Waiters
+
+  build-depends:
+    , amazonka-core  >=2.0  && <2.1
+    , base           >=4.12 && <5
+
+test-suite amazonka-controltower-test
+  type:             exitcode-stdio-1.0
+  default-language: Haskell2010
+  hs-source-dirs:   test
+  main-is:          Main.hs
+  ghc-options:      -Wall -threaded
+
+  -- This section is encoded by the template and any modules added by
+  -- hand outside these namespaces will not correctly be added to the
+  -- distribution package.
+  other-modules:
+    Test.Amazonka.ControlTower
+    Test.Amazonka.ControlTower.Internal
+    Test.Amazonka.Gen.ControlTower
+
+  build-depends:
+    , amazonka-controltower
+    , amazonka-core          >=2.0 && <2.1
+    , amazonka-test          >=2.0 && <2.1
+    , base
+    , bytestring
+    , case-insensitive
+    , tasty
+    , tasty-hunit
+    , text
+    , time
+    , unordered-containers
diff --git a/fixture/DisableControl.yaml b/fixture/DisableControl.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/DisableControl.yaml
@@ -0,0 +1,10 @@
+---
+method: POST
+headers:
+  Authorization:         AWS4-HMAC-SHA256 Credential=access/20091028/us-east-1/controltower/aws4_request, SignedHeaders=content-type;host;x-amz-content-sha256;x-amz-date, Signature=?
+  Host:                  controltower.us-east-1.amazonaws.com
+  Content-Type:          application/x-www-form-urlencoded; charset=utf-8
+  X-Amz-Content-SHA256:  abcdef
+  X-Amz-Date:            20091028T223200Z
+body:
+  ''
diff --git a/fixture/DisableControlResponse.proto b/fixture/DisableControlResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/DisableControlResponse.proto
diff --git a/fixture/EnableControl.yaml b/fixture/EnableControl.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/EnableControl.yaml
@@ -0,0 +1,10 @@
+---
+method: POST
+headers:
+  Authorization:         AWS4-HMAC-SHA256 Credential=access/20091028/us-east-1/controltower/aws4_request, SignedHeaders=content-type;host;x-amz-content-sha256;x-amz-date, Signature=?
+  Host:                  controltower.us-east-1.amazonaws.com
+  Content-Type:          application/x-www-form-urlencoded; charset=utf-8
+  X-Amz-Content-SHA256:  abcdef
+  X-Amz-Date:            20091028T223200Z
+body:
+  ''
diff --git a/fixture/EnableControlResponse.proto b/fixture/EnableControlResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/EnableControlResponse.proto
diff --git a/fixture/GetControlOperation.yaml b/fixture/GetControlOperation.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/GetControlOperation.yaml
@@ -0,0 +1,10 @@
+---
+method: POST
+headers:
+  Authorization:         AWS4-HMAC-SHA256 Credential=access/20091028/us-east-1/controltower/aws4_request, SignedHeaders=content-type;host;x-amz-content-sha256;x-amz-date, Signature=?
+  Host:                  controltower.us-east-1.amazonaws.com
+  Content-Type:          application/x-www-form-urlencoded; charset=utf-8
+  X-Amz-Content-SHA256:  abcdef
+  X-Amz-Date:            20091028T223200Z
+body:
+  ''
diff --git a/fixture/GetControlOperationResponse.proto b/fixture/GetControlOperationResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/GetControlOperationResponse.proto
diff --git a/fixture/ListEnabledControls.yaml b/fixture/ListEnabledControls.yaml
new file mode 100644
--- /dev/null
+++ b/fixture/ListEnabledControls.yaml
@@ -0,0 +1,10 @@
+---
+method: POST
+headers:
+  Authorization:         AWS4-HMAC-SHA256 Credential=access/20091028/us-east-1/controltower/aws4_request, SignedHeaders=content-type;host;x-amz-content-sha256;x-amz-date, Signature=?
+  Host:                  controltower.us-east-1.amazonaws.com
+  Content-Type:          application/x-www-form-urlencoded; charset=utf-8
+  X-Amz-Content-SHA256:  abcdef
+  X-Amz-Date:            20091028T223200Z
+body:
+  ''
diff --git a/fixture/ListEnabledControlsResponse.proto b/fixture/ListEnabledControlsResponse.proto
new file mode 100644
--- /dev/null
+++ b/fixture/ListEnabledControlsResponse.proto
diff --git a/gen/Amazonka/ControlTower.hs b/gen/Amazonka/ControlTower.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower.hs
@@ -0,0 +1,185 @@
+{-# OPTIONS_GHC -fno-warn-duplicate-exports #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+
+-- |
+-- Module      : Amazonka.ControlTower
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- Derived from API version @2018-05-10@ of the AWS service descriptions, licensed under Apache 2.0.
+--
+-- These interfaces allow you to apply the AWS library of pre-defined
+-- /controls/ to your organizational units, programmatically. In this
+-- context, controls are the same as AWS Control Tower guardrails.
+--
+-- To call these APIs, you\'ll need to know:
+--
+-- -   the @ControlARN@ for the control--that is, the guardrail--you are
+--     targeting,
+--
+-- -   and the ARN associated with the target organizational unit (OU).
+--
+-- __To get the @ControlARN@ for your AWS Control Tower guardrail:__
+--
+-- The @ControlARN@ contains the control name which is specified in each
+-- guardrail. For a list of control names for /Strongly recommended/ and
+-- /Elective/ guardrails, see
+-- <https://docs.aws.amazon.com/controltower/latest/userguide/control-identifiers.html.html Resource identifiers for APIs and guardrails>
+-- in the
+-- <https://docs.aws.amazon.com/controltower/latest/userguide/automating-tasks.html Automating tasks section>
+-- of the AWS Control Tower User Guide. Remember that /Mandatory/
+-- guardrails cannot be added or removed.
+--
+-- __ARN format:__ @arn:aws:controltower:{REGION}::control\/{CONTROL_NAME}@
+--
+-- __Example:__
+--
+-- @arn:aws:controltower:us-west-2::control\/AWS-GR_AUTOSCALING_LAUNCH_CONFIG_PUBLIC_IP_DISABLED@
+--
+-- __To get the ARN for an OU:__
+--
+-- In the AWS Organizations console, you can find the ARN for the OU on the
+-- __Organizational unit details__ page associated with that OU.
+--
+-- __OU ARN format:__
+--
+-- @arn:${Partition}:organizations::${MasterAccountId}:ou\/o-${OrganizationId}\/ou-${OrganizationalUnitId}@
+--
+-- __Details and examples__
+--
+-- -   <https://docs.aws.amazon.com/controltower/latest/userguide/control-identifiers.html List of resource identifiers for APIs and guardrails>
+--
+-- -   <https://docs.aws.amazon.com/controltower/latest/userguide/guardrail-api-examples-short.html Guardrail API examples (CLI)>
+--
+-- -   <https://docs.aws.amazon.com/controltower/latest/userguide/enable-controls.html Enable controls with AWS CloudFormation>
+--
+-- -   <https://docs.aws.amazon.com/controltower/latest/userguide/creating-resources-with-cloudformation.html Creating AWS Control Tower resources with AWS CloudFormation>
+--
+-- To view the open source resource repository on GitHub, see
+-- <https://github.com/aws-cloudformation/aws-cloudformation-resource-providers-controltower aws-cloudformation\/aws-cloudformation-resource-providers-controltower>
+--
+-- __Recording API Requests__
+--
+-- AWS Control Tower supports AWS CloudTrail, a service that records AWS
+-- API calls for your AWS account and delivers log files to an Amazon S3
+-- bucket. By using information collected by CloudTrail, you can determine
+-- which requests the AWS Control Tower service received, who made the
+-- request and when, and so on. For more about AWS Control Tower and its
+-- support for CloudTrail, see
+-- <https://docs.aws.amazon.com/controltower/latest/userguide/logging-using-cloudtrail.html Logging AWS Control Tower Actions with AWS CloudTrail>
+-- in the AWS Control Tower User Guide. To learn more about CloudTrail,
+-- including how to turn it on and find your log files, see the AWS
+-- CloudTrail User Guide.
+module Amazonka.ControlTower
+  ( -- * Service Configuration
+    defaultService,
+
+    -- * Errors
+    -- $errors
+
+    -- ** AccessDeniedException
+    _AccessDeniedException,
+
+    -- ** ConflictException
+    _ConflictException,
+
+    -- ** InternalServerException
+    _InternalServerException,
+
+    -- ** ResourceNotFoundException
+    _ResourceNotFoundException,
+
+    -- ** ServiceQuotaExceededException
+    _ServiceQuotaExceededException,
+
+    -- ** ThrottlingException
+    _ThrottlingException,
+
+    -- ** ValidationException
+    _ValidationException,
+
+    -- * Waiters
+    -- $waiters
+
+    -- * Operations
+    -- $operations
+
+    -- ** DisableControl
+    DisableControl (DisableControl'),
+    newDisableControl,
+    DisableControlResponse (DisableControlResponse'),
+    newDisableControlResponse,
+
+    -- ** EnableControl
+    EnableControl (EnableControl'),
+    newEnableControl,
+    EnableControlResponse (EnableControlResponse'),
+    newEnableControlResponse,
+
+    -- ** GetControlOperation
+    GetControlOperation (GetControlOperation'),
+    newGetControlOperation,
+    GetControlOperationResponse (GetControlOperationResponse'),
+    newGetControlOperationResponse,
+
+    -- ** ListEnabledControls (Paginated)
+    ListEnabledControls (ListEnabledControls'),
+    newListEnabledControls,
+    ListEnabledControlsResponse (ListEnabledControlsResponse'),
+    newListEnabledControlsResponse,
+
+    -- * Types
+
+    -- ** ControlOperationStatus
+    ControlOperationStatus (..),
+
+    -- ** ControlOperationType
+    ControlOperationType (..),
+
+    -- ** ControlOperation
+    ControlOperation (ControlOperation'),
+    newControlOperation,
+
+    -- ** EnabledControlSummary
+    EnabledControlSummary (EnabledControlSummary'),
+    newEnabledControlSummary,
+  )
+where
+
+import Amazonka.ControlTower.DisableControl
+import Amazonka.ControlTower.EnableControl
+import Amazonka.ControlTower.GetControlOperation
+import Amazonka.ControlTower.Lens
+import Amazonka.ControlTower.ListEnabledControls
+import Amazonka.ControlTower.Types
+import Amazonka.ControlTower.Waiters
+
+-- $errors
+-- Error matchers are designed for use with the functions provided by
+-- <http://hackage.haskell.org/package/lens/docs/Control-Exception-Lens.html Control.Exception.Lens>.
+-- This allows catching (and rethrowing) service specific errors returned
+-- by 'ControlTower'.
+
+-- $operations
+-- Some AWS operations return results that are incomplete and require subsequent
+-- requests in order to obtain the entire result set. The process of sending
+-- subsequent requests to continue where a previous request left off is called
+-- pagination. For example, the 'ListObjects' operation of Amazon S3 returns up to
+-- 1000 objects at a time, and you must send subsequent requests with the
+-- appropriate Marker in order to retrieve the next page of results.
+--
+-- Operations that have an 'AWSPager' instance can transparently perform subsequent
+-- requests, correctly setting Markers and other request facets to iterate through
+-- the entire result set of a truncated API operation. Operations which support
+-- this have an additional note in the documentation.
+--
+-- Many operations have the ability to filter results on the server side. See the
+-- individual operation parameters for details.
+
+-- $waiters
+-- Waiters poll by repeatedly sending a request until some remote success condition
+-- configured by the 'Wait' specification is fulfilled. The 'Wait' specification
+-- determines how many attempts should be made, in addition to delay and retry strategies.
diff --git a/gen/Amazonka/ControlTower/DisableControl.hs b/gen/Amazonka/ControlTower/DisableControl.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/DisableControl.hs
@@ -0,0 +1,204 @@
+{-# LANGUAGE DeriveGeneric #-}
+{-# LANGUAGE DuplicateRecordFields #-}
+{-# LANGUAGE NamedFieldPuns #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE RecordWildCards #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE TypeFamilies #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.DisableControl
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- This API call turns off a control. It starts an asynchronous operation
+-- that deletes AWS resources on the specified organizational unit and the
+-- accounts it contains. The resources will vary according to the control
+-- that you specify.
+module Amazonka.ControlTower.DisableControl
+  ( -- * Creating a Request
+    DisableControl (..),
+    newDisableControl,
+
+    -- * Request Lenses
+    disableControl_controlIdentifier,
+    disableControl_targetIdentifier,
+
+    -- * Destructuring the Response
+    DisableControlResponse (..),
+    newDisableControlResponse,
+
+    -- * Response Lenses
+    disableControlResponse_httpStatus,
+    disableControlResponse_operationIdentifier,
+  )
+where
+
+import Amazonka.ControlTower.Types
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Core.Lens.Internal as Lens
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
+import qualified Amazonka.Request as Request
+import qualified Amazonka.Response as Response
+
+-- | /See:/ 'newDisableControl' smart constructor.
+data DisableControl = DisableControl'
+  { -- | The ARN of the control. Only __Strongly recommended__ and __Elective__
+    -- controls are permitted, with the exception of the __Region deny__
+    -- guardrail.
+    controlIdentifier :: Prelude.Text,
+    -- | The ARN of the organizational unit.
+    targetIdentifier :: Prelude.Text
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'DisableControl' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'controlIdentifier', 'disableControl_controlIdentifier' - The ARN of the control. Only __Strongly recommended__ and __Elective__
+-- controls are permitted, with the exception of the __Region deny__
+-- guardrail.
+--
+-- 'targetIdentifier', 'disableControl_targetIdentifier' - The ARN of the organizational unit.
+newDisableControl ::
+  -- | 'controlIdentifier'
+  Prelude.Text ->
+  -- | 'targetIdentifier'
+  Prelude.Text ->
+  DisableControl
+newDisableControl
+  pControlIdentifier_
+  pTargetIdentifier_ =
+    DisableControl'
+      { controlIdentifier =
+          pControlIdentifier_,
+        targetIdentifier = pTargetIdentifier_
+      }
+
+-- | The ARN of the control. Only __Strongly recommended__ and __Elective__
+-- controls are permitted, with the exception of the __Region deny__
+-- guardrail.
+disableControl_controlIdentifier :: Lens.Lens' DisableControl Prelude.Text
+disableControl_controlIdentifier = Lens.lens (\DisableControl' {controlIdentifier} -> controlIdentifier) (\s@DisableControl' {} a -> s {controlIdentifier = a} :: DisableControl)
+
+-- | The ARN of the organizational unit.
+disableControl_targetIdentifier :: Lens.Lens' DisableControl Prelude.Text
+disableControl_targetIdentifier = Lens.lens (\DisableControl' {targetIdentifier} -> targetIdentifier) (\s@DisableControl' {} a -> s {targetIdentifier = a} :: DisableControl)
+
+instance Core.AWSRequest DisableControl where
+  type
+    AWSResponse DisableControl =
+      DisableControlResponse
+  request overrides =
+    Request.postJSON (overrides defaultService)
+  response =
+    Response.receiveJSON
+      ( \s h x ->
+          DisableControlResponse'
+            Prelude.<$> (Prelude.pure (Prelude.fromEnum s))
+            Prelude.<*> (x Data..:> "operationIdentifier")
+      )
+
+instance Prelude.Hashable DisableControl where
+  hashWithSalt _salt DisableControl' {..} =
+    _salt
+      `Prelude.hashWithSalt` controlIdentifier
+      `Prelude.hashWithSalt` targetIdentifier
+
+instance Prelude.NFData DisableControl where
+  rnf DisableControl' {..} =
+    Prelude.rnf controlIdentifier
+      `Prelude.seq` Prelude.rnf targetIdentifier
+
+instance Data.ToHeaders DisableControl where
+  toHeaders =
+    Prelude.const
+      ( Prelude.mconcat
+          [ "Content-Type"
+              Data.=# ( "application/x-amz-json-1.1" ::
+                          Prelude.ByteString
+                      )
+          ]
+      )
+
+instance Data.ToJSON DisableControl where
+  toJSON DisableControl' {..} =
+    Data.object
+      ( Prelude.catMaybes
+          [ Prelude.Just
+              ("controlIdentifier" Data..= controlIdentifier),
+            Prelude.Just
+              ("targetIdentifier" Data..= targetIdentifier)
+          ]
+      )
+
+instance Data.ToPath DisableControl where
+  toPath = Prelude.const "/disable-control"
+
+instance Data.ToQuery DisableControl where
+  toQuery = Prelude.const Prelude.mempty
+
+-- | /See:/ 'newDisableControlResponse' smart constructor.
+data DisableControlResponse = DisableControlResponse'
+  { -- | The response's http status code.
+    httpStatus :: Prelude.Int,
+    -- | The ID of the asynchronous operation, which is used to track status. The
+    -- operation is available for 90 days.
+    operationIdentifier :: Prelude.Text
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'DisableControlResponse' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'httpStatus', 'disableControlResponse_httpStatus' - The response's http status code.
+--
+-- 'operationIdentifier', 'disableControlResponse_operationIdentifier' - The ID of the asynchronous operation, which is used to track status. The
+-- operation is available for 90 days.
+newDisableControlResponse ::
+  -- | 'httpStatus'
+  Prelude.Int ->
+  -- | 'operationIdentifier'
+  Prelude.Text ->
+  DisableControlResponse
+newDisableControlResponse
+  pHttpStatus_
+  pOperationIdentifier_ =
+    DisableControlResponse'
+      { httpStatus = pHttpStatus_,
+        operationIdentifier = pOperationIdentifier_
+      }
+
+-- | The response's http status code.
+disableControlResponse_httpStatus :: Lens.Lens' DisableControlResponse Prelude.Int
+disableControlResponse_httpStatus = Lens.lens (\DisableControlResponse' {httpStatus} -> httpStatus) (\s@DisableControlResponse' {} a -> s {httpStatus = a} :: DisableControlResponse)
+
+-- | The ID of the asynchronous operation, which is used to track status. The
+-- operation is available for 90 days.
+disableControlResponse_operationIdentifier :: Lens.Lens' DisableControlResponse Prelude.Text
+disableControlResponse_operationIdentifier = Lens.lens (\DisableControlResponse' {operationIdentifier} -> operationIdentifier) (\s@DisableControlResponse' {} a -> s {operationIdentifier = a} :: DisableControlResponse)
+
+instance Prelude.NFData DisableControlResponse where
+  rnf DisableControlResponse' {..} =
+    Prelude.rnf httpStatus
+      `Prelude.seq` Prelude.rnf operationIdentifier
diff --git a/gen/Amazonka/ControlTower/EnableControl.hs b/gen/Amazonka/ControlTower/EnableControl.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/EnableControl.hs
@@ -0,0 +1,204 @@
+{-# LANGUAGE DeriveGeneric #-}
+{-# LANGUAGE DuplicateRecordFields #-}
+{-# LANGUAGE NamedFieldPuns #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE RecordWildCards #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE TypeFamilies #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.EnableControl
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- This API call activates a control. It starts an asynchronous operation
+-- that creates AWS resources on the specified organizational unit and the
+-- accounts it contains. The resources created will vary according to the
+-- control that you specify.
+module Amazonka.ControlTower.EnableControl
+  ( -- * Creating a Request
+    EnableControl (..),
+    newEnableControl,
+
+    -- * Request Lenses
+    enableControl_controlIdentifier,
+    enableControl_targetIdentifier,
+
+    -- * Destructuring the Response
+    EnableControlResponse (..),
+    newEnableControlResponse,
+
+    -- * Response Lenses
+    enableControlResponse_httpStatus,
+    enableControlResponse_operationIdentifier,
+  )
+where
+
+import Amazonka.ControlTower.Types
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Core.Lens.Internal as Lens
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
+import qualified Amazonka.Request as Request
+import qualified Amazonka.Response as Response
+
+-- | /See:/ 'newEnableControl' smart constructor.
+data EnableControl = EnableControl'
+  { -- | The ARN of the control. Only __Strongly recommended__ and __Elective__
+    -- controls are permitted, with the exception of the __Region deny__
+    -- guardrail.
+    controlIdentifier :: Prelude.Text,
+    -- | The ARN of the organizational unit.
+    targetIdentifier :: Prelude.Text
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'EnableControl' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'controlIdentifier', 'enableControl_controlIdentifier' - The ARN of the control. Only __Strongly recommended__ and __Elective__
+-- controls are permitted, with the exception of the __Region deny__
+-- guardrail.
+--
+-- 'targetIdentifier', 'enableControl_targetIdentifier' - The ARN of the organizational unit.
+newEnableControl ::
+  -- | 'controlIdentifier'
+  Prelude.Text ->
+  -- | 'targetIdentifier'
+  Prelude.Text ->
+  EnableControl
+newEnableControl
+  pControlIdentifier_
+  pTargetIdentifier_ =
+    EnableControl'
+      { controlIdentifier =
+          pControlIdentifier_,
+        targetIdentifier = pTargetIdentifier_
+      }
+
+-- | The ARN of the control. Only __Strongly recommended__ and __Elective__
+-- controls are permitted, with the exception of the __Region deny__
+-- guardrail.
+enableControl_controlIdentifier :: Lens.Lens' EnableControl Prelude.Text
+enableControl_controlIdentifier = Lens.lens (\EnableControl' {controlIdentifier} -> controlIdentifier) (\s@EnableControl' {} a -> s {controlIdentifier = a} :: EnableControl)
+
+-- | The ARN of the organizational unit.
+enableControl_targetIdentifier :: Lens.Lens' EnableControl Prelude.Text
+enableControl_targetIdentifier = Lens.lens (\EnableControl' {targetIdentifier} -> targetIdentifier) (\s@EnableControl' {} a -> s {targetIdentifier = a} :: EnableControl)
+
+instance Core.AWSRequest EnableControl where
+  type
+    AWSResponse EnableControl =
+      EnableControlResponse
+  request overrides =
+    Request.postJSON (overrides defaultService)
+  response =
+    Response.receiveJSON
+      ( \s h x ->
+          EnableControlResponse'
+            Prelude.<$> (Prelude.pure (Prelude.fromEnum s))
+            Prelude.<*> (x Data..:> "operationIdentifier")
+      )
+
+instance Prelude.Hashable EnableControl where
+  hashWithSalt _salt EnableControl' {..} =
+    _salt
+      `Prelude.hashWithSalt` controlIdentifier
+      `Prelude.hashWithSalt` targetIdentifier
+
+instance Prelude.NFData EnableControl where
+  rnf EnableControl' {..} =
+    Prelude.rnf controlIdentifier
+      `Prelude.seq` Prelude.rnf targetIdentifier
+
+instance Data.ToHeaders EnableControl where
+  toHeaders =
+    Prelude.const
+      ( Prelude.mconcat
+          [ "Content-Type"
+              Data.=# ( "application/x-amz-json-1.1" ::
+                          Prelude.ByteString
+                      )
+          ]
+      )
+
+instance Data.ToJSON EnableControl where
+  toJSON EnableControl' {..} =
+    Data.object
+      ( Prelude.catMaybes
+          [ Prelude.Just
+              ("controlIdentifier" Data..= controlIdentifier),
+            Prelude.Just
+              ("targetIdentifier" Data..= targetIdentifier)
+          ]
+      )
+
+instance Data.ToPath EnableControl where
+  toPath = Prelude.const "/enable-control"
+
+instance Data.ToQuery EnableControl where
+  toQuery = Prelude.const Prelude.mempty
+
+-- | /See:/ 'newEnableControlResponse' smart constructor.
+data EnableControlResponse = EnableControlResponse'
+  { -- | The response's http status code.
+    httpStatus :: Prelude.Int,
+    -- | The ID of the asynchronous operation, which is used to track status. The
+    -- operation is available for 90 days.
+    operationIdentifier :: Prelude.Text
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'EnableControlResponse' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'httpStatus', 'enableControlResponse_httpStatus' - The response's http status code.
+--
+-- 'operationIdentifier', 'enableControlResponse_operationIdentifier' - The ID of the asynchronous operation, which is used to track status. The
+-- operation is available for 90 days.
+newEnableControlResponse ::
+  -- | 'httpStatus'
+  Prelude.Int ->
+  -- | 'operationIdentifier'
+  Prelude.Text ->
+  EnableControlResponse
+newEnableControlResponse
+  pHttpStatus_
+  pOperationIdentifier_ =
+    EnableControlResponse'
+      { httpStatus = pHttpStatus_,
+        operationIdentifier = pOperationIdentifier_
+      }
+
+-- | The response's http status code.
+enableControlResponse_httpStatus :: Lens.Lens' EnableControlResponse Prelude.Int
+enableControlResponse_httpStatus = Lens.lens (\EnableControlResponse' {httpStatus} -> httpStatus) (\s@EnableControlResponse' {} a -> s {httpStatus = a} :: EnableControlResponse)
+
+-- | The ID of the asynchronous operation, which is used to track status. The
+-- operation is available for 90 days.
+enableControlResponse_operationIdentifier :: Lens.Lens' EnableControlResponse Prelude.Text
+enableControlResponse_operationIdentifier = Lens.lens (\EnableControlResponse' {operationIdentifier} -> operationIdentifier) (\s@EnableControlResponse' {} a -> s {operationIdentifier = a} :: EnableControlResponse)
+
+instance Prelude.NFData EnableControlResponse where
+  rnf EnableControlResponse' {..} =
+    Prelude.rnf httpStatus
+      `Prelude.seq` Prelude.rnf operationIdentifier
diff --git a/gen/Amazonka/ControlTower/GetControlOperation.hs b/gen/Amazonka/ControlTower/GetControlOperation.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/GetControlOperation.hs
@@ -0,0 +1,177 @@
+{-# LANGUAGE DeriveGeneric #-}
+{-# LANGUAGE DuplicateRecordFields #-}
+{-# LANGUAGE NamedFieldPuns #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE RecordWildCards #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE TypeFamilies #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.GetControlOperation
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- Returns the status of a particular @EnableControl@ or @DisableControl@
+-- operation. Displays a message in case of error. Details for an operation
+-- are available for 90 days.
+module Amazonka.ControlTower.GetControlOperation
+  ( -- * Creating a Request
+    GetControlOperation (..),
+    newGetControlOperation,
+
+    -- * Request Lenses
+    getControlOperation_operationIdentifier,
+
+    -- * Destructuring the Response
+    GetControlOperationResponse (..),
+    newGetControlOperationResponse,
+
+    -- * Response Lenses
+    getControlOperationResponse_httpStatus,
+    getControlOperationResponse_controlOperation,
+  )
+where
+
+import Amazonka.ControlTower.Types
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Core.Lens.Internal as Lens
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
+import qualified Amazonka.Request as Request
+import qualified Amazonka.Response as Response
+
+-- | /See:/ 'newGetControlOperation' smart constructor.
+data GetControlOperation = GetControlOperation'
+  { -- | The ID of the asynchronous operation, which is used to track status. The
+    -- operation is available for 90 days.
+    operationIdentifier :: Prelude.Text
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'GetControlOperation' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'operationIdentifier', 'getControlOperation_operationIdentifier' - The ID of the asynchronous operation, which is used to track status. The
+-- operation is available for 90 days.
+newGetControlOperation ::
+  -- | 'operationIdentifier'
+  Prelude.Text ->
+  GetControlOperation
+newGetControlOperation pOperationIdentifier_ =
+  GetControlOperation'
+    { operationIdentifier =
+        pOperationIdentifier_
+    }
+
+-- | The ID of the asynchronous operation, which is used to track status. The
+-- operation is available for 90 days.
+getControlOperation_operationIdentifier :: Lens.Lens' GetControlOperation Prelude.Text
+getControlOperation_operationIdentifier = Lens.lens (\GetControlOperation' {operationIdentifier} -> operationIdentifier) (\s@GetControlOperation' {} a -> s {operationIdentifier = a} :: GetControlOperation)
+
+instance Core.AWSRequest GetControlOperation where
+  type
+    AWSResponse GetControlOperation =
+      GetControlOperationResponse
+  request overrides =
+    Request.postJSON (overrides defaultService)
+  response =
+    Response.receiveJSON
+      ( \s h x ->
+          GetControlOperationResponse'
+            Prelude.<$> (Prelude.pure (Prelude.fromEnum s))
+            Prelude.<*> (x Data..:> "controlOperation")
+      )
+
+instance Prelude.Hashable GetControlOperation where
+  hashWithSalt _salt GetControlOperation' {..} =
+    _salt `Prelude.hashWithSalt` operationIdentifier
+
+instance Prelude.NFData GetControlOperation where
+  rnf GetControlOperation' {..} =
+    Prelude.rnf operationIdentifier
+
+instance Data.ToHeaders GetControlOperation where
+  toHeaders =
+    Prelude.const
+      ( Prelude.mconcat
+          [ "Content-Type"
+              Data.=# ( "application/x-amz-json-1.1" ::
+                          Prelude.ByteString
+                      )
+          ]
+      )
+
+instance Data.ToJSON GetControlOperation where
+  toJSON GetControlOperation' {..} =
+    Data.object
+      ( Prelude.catMaybes
+          [ Prelude.Just
+              ("operationIdentifier" Data..= operationIdentifier)
+          ]
+      )
+
+instance Data.ToPath GetControlOperation where
+  toPath = Prelude.const "/get-control-operation"
+
+instance Data.ToQuery GetControlOperation where
+  toQuery = Prelude.const Prelude.mempty
+
+-- | /See:/ 'newGetControlOperationResponse' smart constructor.
+data GetControlOperationResponse = GetControlOperationResponse'
+  { -- | The response's http status code.
+    httpStatus :: Prelude.Int,
+    controlOperation :: ControlOperation
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'GetControlOperationResponse' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'httpStatus', 'getControlOperationResponse_httpStatus' - The response's http status code.
+--
+-- 'controlOperation', 'getControlOperationResponse_controlOperation' -
+newGetControlOperationResponse ::
+  -- | 'httpStatus'
+  Prelude.Int ->
+  -- | 'controlOperation'
+  ControlOperation ->
+  GetControlOperationResponse
+newGetControlOperationResponse
+  pHttpStatus_
+  pControlOperation_ =
+    GetControlOperationResponse'
+      { httpStatus =
+          pHttpStatus_,
+        controlOperation = pControlOperation_
+      }
+
+-- | The response's http status code.
+getControlOperationResponse_httpStatus :: Lens.Lens' GetControlOperationResponse Prelude.Int
+getControlOperationResponse_httpStatus = Lens.lens (\GetControlOperationResponse' {httpStatus} -> httpStatus) (\s@GetControlOperationResponse' {} a -> s {httpStatus = a} :: GetControlOperationResponse)
+
+getControlOperationResponse_controlOperation :: Lens.Lens' GetControlOperationResponse ControlOperation
+getControlOperationResponse_controlOperation = Lens.lens (\GetControlOperationResponse' {controlOperation} -> controlOperation) (\s@GetControlOperationResponse' {} a -> s {controlOperation = a} :: GetControlOperationResponse)
+
+instance Prelude.NFData GetControlOperationResponse where
+  rnf GetControlOperationResponse' {..} =
+    Prelude.rnf httpStatus
+      `Prelude.seq` Prelude.rnf controlOperation
diff --git a/gen/Amazonka/ControlTower/Lens.hs b/gen/Amazonka/ControlTower/Lens.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/Lens.hs
@@ -0,0 +1,61 @@
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-duplicate-exports #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.Lens
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Amazonka.ControlTower.Lens
+  ( -- * Operations
+
+    -- ** DisableControl
+    disableControl_controlIdentifier,
+    disableControl_targetIdentifier,
+    disableControlResponse_httpStatus,
+    disableControlResponse_operationIdentifier,
+
+    -- ** EnableControl
+    enableControl_controlIdentifier,
+    enableControl_targetIdentifier,
+    enableControlResponse_httpStatus,
+    enableControlResponse_operationIdentifier,
+
+    -- ** GetControlOperation
+    getControlOperation_operationIdentifier,
+    getControlOperationResponse_httpStatus,
+    getControlOperationResponse_controlOperation,
+
+    -- ** ListEnabledControls
+    listEnabledControls_maxResults,
+    listEnabledControls_nextToken,
+    listEnabledControls_targetIdentifier,
+    listEnabledControlsResponse_nextToken,
+    listEnabledControlsResponse_httpStatus,
+    listEnabledControlsResponse_enabledControls,
+
+    -- * Types
+
+    -- ** ControlOperation
+    controlOperation_endTime,
+    controlOperation_operationType,
+    controlOperation_startTime,
+    controlOperation_status,
+    controlOperation_statusMessage,
+
+    -- ** EnabledControlSummary
+    enabledControlSummary_controlIdentifier,
+  )
+where
+
+import Amazonka.ControlTower.DisableControl
+import Amazonka.ControlTower.EnableControl
+import Amazonka.ControlTower.GetControlOperation
+import Amazonka.ControlTower.ListEnabledControls
+import Amazonka.ControlTower.Types.ControlOperation
+import Amazonka.ControlTower.Types.EnabledControlSummary
diff --git a/gen/Amazonka/ControlTower/ListEnabledControls.hs b/gen/Amazonka/ControlTower/ListEnabledControls.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/ListEnabledControls.hs
@@ -0,0 +1,244 @@
+{-# LANGUAGE DeriveGeneric #-}
+{-# LANGUAGE DuplicateRecordFields #-}
+{-# LANGUAGE NamedFieldPuns #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE RecordWildCards #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE TypeFamilies #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-binds #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.ListEnabledControls
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+--
+-- Lists the controls enabled by AWS Control Tower on the specified
+-- organizational unit and the accounts it contains.
+--
+-- This operation returns paginated results.
+module Amazonka.ControlTower.ListEnabledControls
+  ( -- * Creating a Request
+    ListEnabledControls (..),
+    newListEnabledControls,
+
+    -- * Request Lenses
+    listEnabledControls_maxResults,
+    listEnabledControls_nextToken,
+    listEnabledControls_targetIdentifier,
+
+    -- * Destructuring the Response
+    ListEnabledControlsResponse (..),
+    newListEnabledControlsResponse,
+
+    -- * Response Lenses
+    listEnabledControlsResponse_nextToken,
+    listEnabledControlsResponse_httpStatus,
+    listEnabledControlsResponse_enabledControls,
+  )
+where
+
+import Amazonka.ControlTower.Types
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Core.Lens.Internal as Lens
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
+import qualified Amazonka.Request as Request
+import qualified Amazonka.Response as Response
+
+-- | /See:/ 'newListEnabledControls' smart constructor.
+data ListEnabledControls = ListEnabledControls'
+  { -- | How many results to return per API call.
+    maxResults :: Prelude.Maybe Prelude.Natural,
+    -- | The token to continue the list from a previous API call with the same
+    -- parameters.
+    nextToken :: Prelude.Maybe Prelude.Text,
+    -- | The ARN of the organizational unit.
+    targetIdentifier :: Prelude.Text
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'ListEnabledControls' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'maxResults', 'listEnabledControls_maxResults' - How many results to return per API call.
+--
+-- 'nextToken', 'listEnabledControls_nextToken' - The token to continue the list from a previous API call with the same
+-- parameters.
+--
+-- 'targetIdentifier', 'listEnabledControls_targetIdentifier' - The ARN of the organizational unit.
+newListEnabledControls ::
+  -- | 'targetIdentifier'
+  Prelude.Text ->
+  ListEnabledControls
+newListEnabledControls pTargetIdentifier_ =
+  ListEnabledControls'
+    { maxResults = Prelude.Nothing,
+      nextToken = Prelude.Nothing,
+      targetIdentifier = pTargetIdentifier_
+    }
+
+-- | How many results to return per API call.
+listEnabledControls_maxResults :: Lens.Lens' ListEnabledControls (Prelude.Maybe Prelude.Natural)
+listEnabledControls_maxResults = Lens.lens (\ListEnabledControls' {maxResults} -> maxResults) (\s@ListEnabledControls' {} a -> s {maxResults = a} :: ListEnabledControls)
+
+-- | The token to continue the list from a previous API call with the same
+-- parameters.
+listEnabledControls_nextToken :: Lens.Lens' ListEnabledControls (Prelude.Maybe Prelude.Text)
+listEnabledControls_nextToken = Lens.lens (\ListEnabledControls' {nextToken} -> nextToken) (\s@ListEnabledControls' {} a -> s {nextToken = a} :: ListEnabledControls)
+
+-- | The ARN of the organizational unit.
+listEnabledControls_targetIdentifier :: Lens.Lens' ListEnabledControls Prelude.Text
+listEnabledControls_targetIdentifier = Lens.lens (\ListEnabledControls' {targetIdentifier} -> targetIdentifier) (\s@ListEnabledControls' {} a -> s {targetIdentifier = a} :: ListEnabledControls)
+
+instance Core.AWSPager ListEnabledControls where
+  page rq rs
+    | Core.stop
+        ( rs
+            Lens.^? listEnabledControlsResponse_nextToken
+            Prelude.. Lens._Just
+        ) =
+        Prelude.Nothing
+    | Core.stop
+        ( rs
+            Lens.^. listEnabledControlsResponse_enabledControls
+        ) =
+        Prelude.Nothing
+    | Prelude.otherwise =
+        Prelude.Just
+          Prelude.$ rq
+          Prelude.& listEnabledControls_nextToken
+          Lens..~ rs
+          Lens.^? listEnabledControlsResponse_nextToken
+          Prelude.. Lens._Just
+
+instance Core.AWSRequest ListEnabledControls where
+  type
+    AWSResponse ListEnabledControls =
+      ListEnabledControlsResponse
+  request overrides =
+    Request.postJSON (overrides defaultService)
+  response =
+    Response.receiveJSON
+      ( \s h x ->
+          ListEnabledControlsResponse'
+            Prelude.<$> (x Data..?> "nextToken")
+            Prelude.<*> (Prelude.pure (Prelude.fromEnum s))
+            Prelude.<*> ( x
+                            Data..?> "enabledControls"
+                            Core..!@ Prelude.mempty
+                        )
+      )
+
+instance Prelude.Hashable ListEnabledControls where
+  hashWithSalt _salt ListEnabledControls' {..} =
+    _salt
+      `Prelude.hashWithSalt` maxResults
+      `Prelude.hashWithSalt` nextToken
+      `Prelude.hashWithSalt` targetIdentifier
+
+instance Prelude.NFData ListEnabledControls where
+  rnf ListEnabledControls' {..} =
+    Prelude.rnf maxResults
+      `Prelude.seq` Prelude.rnf nextToken
+      `Prelude.seq` Prelude.rnf targetIdentifier
+
+instance Data.ToHeaders ListEnabledControls where
+  toHeaders =
+    Prelude.const
+      ( Prelude.mconcat
+          [ "Content-Type"
+              Data.=# ( "application/x-amz-json-1.1" ::
+                          Prelude.ByteString
+                      )
+          ]
+      )
+
+instance Data.ToJSON ListEnabledControls where
+  toJSON ListEnabledControls' {..} =
+    Data.object
+      ( Prelude.catMaybes
+          [ ("maxResults" Data..=) Prelude.<$> maxResults,
+            ("nextToken" Data..=) Prelude.<$> nextToken,
+            Prelude.Just
+              ("targetIdentifier" Data..= targetIdentifier)
+          ]
+      )
+
+instance Data.ToPath ListEnabledControls where
+  toPath = Prelude.const "/list-enabled-controls"
+
+instance Data.ToQuery ListEnabledControls where
+  toQuery = Prelude.const Prelude.mempty
+
+-- | /See:/ 'newListEnabledControlsResponse' smart constructor.
+data ListEnabledControlsResponse = ListEnabledControlsResponse'
+  { -- | Retrieves the next page of results. If the string is empty, the current
+    -- response is the end of the results.
+    nextToken :: Prelude.Maybe Prelude.Text,
+    -- | The response's http status code.
+    httpStatus :: Prelude.Int,
+    -- | Lists the controls enabled by AWS Control Tower on the specified
+    -- organizational unit and the accounts it contains.
+    enabledControls :: [EnabledControlSummary]
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'ListEnabledControlsResponse' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'nextToken', 'listEnabledControlsResponse_nextToken' - Retrieves the next page of results. If the string is empty, the current
+-- response is the end of the results.
+--
+-- 'httpStatus', 'listEnabledControlsResponse_httpStatus' - The response's http status code.
+--
+-- 'enabledControls', 'listEnabledControlsResponse_enabledControls' - Lists the controls enabled by AWS Control Tower on the specified
+-- organizational unit and the accounts it contains.
+newListEnabledControlsResponse ::
+  -- | 'httpStatus'
+  Prelude.Int ->
+  ListEnabledControlsResponse
+newListEnabledControlsResponse pHttpStatus_ =
+  ListEnabledControlsResponse'
+    { nextToken =
+        Prelude.Nothing,
+      httpStatus = pHttpStatus_,
+      enabledControls = Prelude.mempty
+    }
+
+-- | Retrieves the next page of results. If the string is empty, the current
+-- response is the end of the results.
+listEnabledControlsResponse_nextToken :: Lens.Lens' ListEnabledControlsResponse (Prelude.Maybe Prelude.Text)
+listEnabledControlsResponse_nextToken = Lens.lens (\ListEnabledControlsResponse' {nextToken} -> nextToken) (\s@ListEnabledControlsResponse' {} a -> s {nextToken = a} :: ListEnabledControlsResponse)
+
+-- | The response's http status code.
+listEnabledControlsResponse_httpStatus :: Lens.Lens' ListEnabledControlsResponse Prelude.Int
+listEnabledControlsResponse_httpStatus = Lens.lens (\ListEnabledControlsResponse' {httpStatus} -> httpStatus) (\s@ListEnabledControlsResponse' {} a -> s {httpStatus = a} :: ListEnabledControlsResponse)
+
+-- | Lists the controls enabled by AWS Control Tower on the specified
+-- organizational unit and the accounts it contains.
+listEnabledControlsResponse_enabledControls :: Lens.Lens' ListEnabledControlsResponse [EnabledControlSummary]
+listEnabledControlsResponse_enabledControls = Lens.lens (\ListEnabledControlsResponse' {enabledControls} -> enabledControls) (\s@ListEnabledControlsResponse' {} a -> s {enabledControls = a} :: ListEnabledControlsResponse) Prelude.. Lens.coerced
+
+instance Prelude.NFData ListEnabledControlsResponse where
+  rnf ListEnabledControlsResponse' {..} =
+    Prelude.rnf nextToken
+      `Prelude.seq` Prelude.rnf httpStatus
+      `Prelude.seq` Prelude.rnf enabledControls
diff --git a/gen/Amazonka/ControlTower/Types.hs b/gen/Amazonka/ControlTower/Types.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/Types.hs
@@ -0,0 +1,185 @@
+{-# LANGUAGE DisambiguateRecordFields #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.Types
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Amazonka.ControlTower.Types
+  ( -- * Service Configuration
+    defaultService,
+
+    -- * Errors
+    _AccessDeniedException,
+    _ConflictException,
+    _InternalServerException,
+    _ResourceNotFoundException,
+    _ServiceQuotaExceededException,
+    _ThrottlingException,
+    _ValidationException,
+
+    -- * ControlOperationStatus
+    ControlOperationStatus (..),
+
+    -- * ControlOperationType
+    ControlOperationType (..),
+
+    -- * ControlOperation
+    ControlOperation (..),
+    newControlOperation,
+    controlOperation_endTime,
+    controlOperation_operationType,
+    controlOperation_startTime,
+    controlOperation_status,
+    controlOperation_statusMessage,
+
+    -- * EnabledControlSummary
+    EnabledControlSummary (..),
+    newEnabledControlSummary,
+    enabledControlSummary_controlIdentifier,
+  )
+where
+
+import Amazonka.ControlTower.Types.ControlOperation
+import Amazonka.ControlTower.Types.ControlOperationStatus
+import Amazonka.ControlTower.Types.ControlOperationType
+import Amazonka.ControlTower.Types.EnabledControlSummary
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Core.Lens.Internal as Lens
+import qualified Amazonka.Prelude as Prelude
+import qualified Amazonka.Sign.V4 as Sign
+
+-- | API version @2018-05-10@ of the Amazon Control Tower SDK configuration.
+defaultService :: Core.Service
+defaultService =
+  Core.Service
+    { Core.abbrev = "ControlTower",
+      Core.signer = Sign.v4,
+      Core.endpointPrefix = "controltower",
+      Core.signingName = "controltower",
+      Core.version = "2018-05-10",
+      Core.s3AddressingStyle = Core.S3AddressingStyleAuto,
+      Core.endpoint = Core.defaultEndpoint defaultService,
+      Core.timeout = Prelude.Just 70,
+      Core.check = Core.statusSuccess,
+      Core.error = Core.parseJSONError "ControlTower",
+      Core.retry = retry
+    }
+  where
+    retry =
+      Core.Exponential
+        { Core.base = 5.0e-2,
+          Core.growth = 2,
+          Core.attempts = 5,
+          Core.check = check
+        }
+    check e
+      | Lens.has (Core.hasStatus 502) e =
+          Prelude.Just "bad_gateway"
+      | Lens.has (Core.hasStatus 504) e =
+          Prelude.Just "gateway_timeout"
+      | Lens.has (Core.hasStatus 500) e =
+          Prelude.Just "general_server_error"
+      | Lens.has (Core.hasStatus 509) e =
+          Prelude.Just "limit_exceeded"
+      | Lens.has
+          ( Core.hasCode "RequestThrottledException"
+              Prelude.. Core.hasStatus 400
+          )
+          e =
+          Prelude.Just "request_throttled_exception"
+      | Lens.has (Core.hasStatus 503) e =
+          Prelude.Just "service_unavailable"
+      | Lens.has
+          ( Core.hasCode "ThrottledException"
+              Prelude.. Core.hasStatus 400
+          )
+          e =
+          Prelude.Just "throttled_exception"
+      | Lens.has
+          ( Core.hasCode "Throttling"
+              Prelude.. Core.hasStatus 400
+          )
+          e =
+          Prelude.Just "throttling"
+      | Lens.has
+          ( Core.hasCode "ThrottlingException"
+              Prelude.. Core.hasStatus 400
+          )
+          e =
+          Prelude.Just "throttling_exception"
+      | Lens.has
+          ( Core.hasCode
+              "ProvisionedThroughputExceededException"
+              Prelude.. Core.hasStatus 400
+          )
+          e =
+          Prelude.Just "throughput_exceeded"
+      | Lens.has (Core.hasStatus 429) e =
+          Prelude.Just "too_many_requests"
+      | Prelude.otherwise = Prelude.Nothing
+
+-- | User does not have sufficient access to perform this action.
+_AccessDeniedException :: (Core.AsError a) => Lens.Fold a Core.ServiceError
+_AccessDeniedException =
+  Core._MatchServiceError
+    defaultService
+    "AccessDeniedException"
+    Prelude.. Core.hasStatus 403
+
+-- | Updating or deleting a resource can cause an inconsistent state.
+_ConflictException :: (Core.AsError a) => Lens.Fold a Core.ServiceError
+_ConflictException =
+  Core._MatchServiceError
+    defaultService
+    "ConflictException"
+    Prelude.. Core.hasStatus 409
+
+-- | Unexpected error during processing of request.
+_InternalServerException :: (Core.AsError a) => Lens.Fold a Core.ServiceError
+_InternalServerException =
+  Core._MatchServiceError
+    defaultService
+    "InternalServerException"
+    Prelude.. Core.hasStatus 500
+
+-- | Request references a resource which does not exist.
+_ResourceNotFoundException :: (Core.AsError a) => Lens.Fold a Core.ServiceError
+_ResourceNotFoundException =
+  Core._MatchServiceError
+    defaultService
+    "ResourceNotFoundException"
+    Prelude.. Core.hasStatus 404
+
+-- | Request would cause a service quota to be exceeded. The limit is 10
+-- concurrent operations.
+_ServiceQuotaExceededException :: (Core.AsError a) => Lens.Fold a Core.ServiceError
+_ServiceQuotaExceededException =
+  Core._MatchServiceError
+    defaultService
+    "ServiceQuotaExceededException"
+    Prelude.. Core.hasStatus 402
+
+-- | Request was denied due to request throttling.
+_ThrottlingException :: (Core.AsError a) => Lens.Fold a Core.ServiceError
+_ThrottlingException =
+  Core._MatchServiceError
+    defaultService
+    "ThrottlingException"
+    Prelude.. Core.hasStatus 429
+
+-- | The input fails to satisfy the constraints specified by an AWS service.
+_ValidationException :: (Core.AsError a) => Lens.Fold a Core.ServiceError
+_ValidationException =
+  Core._MatchServiceError
+    defaultService
+    "ValidationException"
+    Prelude.. Core.hasStatus 400
diff --git a/gen/Amazonka/ControlTower/Types/ControlOperation.hs b/gen/Amazonka/ControlTower/Types/ControlOperation.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/Types/ControlOperation.hs
@@ -0,0 +1,125 @@
+{-# LANGUAGE DeriveGeneric #-}
+{-# LANGUAGE DuplicateRecordFields #-}
+{-# LANGUAGE NamedFieldPuns #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE RecordWildCards #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.Types.ControlOperation
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Amazonka.ControlTower.Types.ControlOperation where
+
+import Amazonka.ControlTower.Types.ControlOperationStatus
+import Amazonka.ControlTower.Types.ControlOperationType
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Core.Lens.Internal as Lens
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
+
+-- | An operation performed by the control.
+--
+-- /See:/ 'newControlOperation' smart constructor.
+data ControlOperation = ControlOperation'
+  { -- | The time that the operation finished.
+    endTime :: Prelude.Maybe Data.ISO8601,
+    -- | One of @ENABLE_CONTROL@ or @DISABLE_CONTROL@.
+    operationType :: Prelude.Maybe ControlOperationType,
+    -- | The time that the operation began.
+    startTime :: Prelude.Maybe Data.ISO8601,
+    -- | One of @IN_PROGRESS@, @SUCEEDED@, or @FAILED@.
+    status :: Prelude.Maybe ControlOperationStatus,
+    -- | If the operation result is @FAILED@, this string contains a message
+    -- explaining why the operation failed.
+    statusMessage :: Prelude.Maybe Prelude.Text
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'ControlOperation' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'endTime', 'controlOperation_endTime' - The time that the operation finished.
+--
+-- 'operationType', 'controlOperation_operationType' - One of @ENABLE_CONTROL@ or @DISABLE_CONTROL@.
+--
+-- 'startTime', 'controlOperation_startTime' - The time that the operation began.
+--
+-- 'status', 'controlOperation_status' - One of @IN_PROGRESS@, @SUCEEDED@, or @FAILED@.
+--
+-- 'statusMessage', 'controlOperation_statusMessage' - If the operation result is @FAILED@, this string contains a message
+-- explaining why the operation failed.
+newControlOperation ::
+  ControlOperation
+newControlOperation =
+  ControlOperation'
+    { endTime = Prelude.Nothing,
+      operationType = Prelude.Nothing,
+      startTime = Prelude.Nothing,
+      status = Prelude.Nothing,
+      statusMessage = Prelude.Nothing
+    }
+
+-- | The time that the operation finished.
+controlOperation_endTime :: Lens.Lens' ControlOperation (Prelude.Maybe Prelude.UTCTime)
+controlOperation_endTime = Lens.lens (\ControlOperation' {endTime} -> endTime) (\s@ControlOperation' {} a -> s {endTime = a} :: ControlOperation) Prelude.. Lens.mapping Data._Time
+
+-- | One of @ENABLE_CONTROL@ or @DISABLE_CONTROL@.
+controlOperation_operationType :: Lens.Lens' ControlOperation (Prelude.Maybe ControlOperationType)
+controlOperation_operationType = Lens.lens (\ControlOperation' {operationType} -> operationType) (\s@ControlOperation' {} a -> s {operationType = a} :: ControlOperation)
+
+-- | The time that the operation began.
+controlOperation_startTime :: Lens.Lens' ControlOperation (Prelude.Maybe Prelude.UTCTime)
+controlOperation_startTime = Lens.lens (\ControlOperation' {startTime} -> startTime) (\s@ControlOperation' {} a -> s {startTime = a} :: ControlOperation) Prelude.. Lens.mapping Data._Time
+
+-- | One of @IN_PROGRESS@, @SUCEEDED@, or @FAILED@.
+controlOperation_status :: Lens.Lens' ControlOperation (Prelude.Maybe ControlOperationStatus)
+controlOperation_status = Lens.lens (\ControlOperation' {status} -> status) (\s@ControlOperation' {} a -> s {status = a} :: ControlOperation)
+
+-- | If the operation result is @FAILED@, this string contains a message
+-- explaining why the operation failed.
+controlOperation_statusMessage :: Lens.Lens' ControlOperation (Prelude.Maybe Prelude.Text)
+controlOperation_statusMessage = Lens.lens (\ControlOperation' {statusMessage} -> statusMessage) (\s@ControlOperation' {} a -> s {statusMessage = a} :: ControlOperation)
+
+instance Data.FromJSON ControlOperation where
+  parseJSON =
+    Data.withObject
+      "ControlOperation"
+      ( \x ->
+          ControlOperation'
+            Prelude.<$> (x Data..:? "endTime")
+            Prelude.<*> (x Data..:? "operationType")
+            Prelude.<*> (x Data..:? "startTime")
+            Prelude.<*> (x Data..:? "status")
+            Prelude.<*> (x Data..:? "statusMessage")
+      )
+
+instance Prelude.Hashable ControlOperation where
+  hashWithSalt _salt ControlOperation' {..} =
+    _salt
+      `Prelude.hashWithSalt` endTime
+      `Prelude.hashWithSalt` operationType
+      `Prelude.hashWithSalt` startTime
+      `Prelude.hashWithSalt` status
+      `Prelude.hashWithSalt` statusMessage
+
+instance Prelude.NFData ControlOperation where
+  rnf ControlOperation' {..} =
+    Prelude.rnf endTime
+      `Prelude.seq` Prelude.rnf operationType
+      `Prelude.seq` Prelude.rnf startTime
+      `Prelude.seq` Prelude.rnf status
+      `Prelude.seq` Prelude.rnf statusMessage
diff --git a/gen/Amazonka/ControlTower/Types/ControlOperationStatus.hs b/gen/Amazonka/ControlTower/Types/ControlOperationStatus.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/Types/ControlOperationStatus.hs
@@ -0,0 +1,76 @@
+{-# LANGUAGE DeriveGeneric #-}
+{-# LANGUAGE DerivingStrategies #-}
+{-# LANGUAGE GeneralizedNewtypeDeriving #-}
+{-# LANGUAGE LambdaCase #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE PatternSynonyms #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.Types.ControlOperationStatus
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Amazonka.ControlTower.Types.ControlOperationStatus
+  ( ControlOperationStatus
+      ( ..,
+        ControlOperationStatus_FAILED,
+        ControlOperationStatus_IN_PROGRESS,
+        ControlOperationStatus_SUCCEEDED
+      ),
+  )
+where
+
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
+
+newtype ControlOperationStatus = ControlOperationStatus'
+  { fromControlOperationStatus ::
+      Data.Text
+  }
+  deriving stock
+    ( Prelude.Show,
+      Prelude.Read,
+      Prelude.Eq,
+      Prelude.Ord,
+      Prelude.Generic
+    )
+  deriving newtype
+    ( Prelude.Hashable,
+      Prelude.NFData,
+      Data.FromText,
+      Data.ToText,
+      Data.ToByteString,
+      Data.ToLog,
+      Data.ToHeader,
+      Data.ToQuery,
+      Data.FromJSON,
+      Data.FromJSONKey,
+      Data.ToJSON,
+      Data.ToJSONKey,
+      Data.FromXML,
+      Data.ToXML
+    )
+
+pattern ControlOperationStatus_FAILED :: ControlOperationStatus
+pattern ControlOperationStatus_FAILED = ControlOperationStatus' "FAILED"
+
+pattern ControlOperationStatus_IN_PROGRESS :: ControlOperationStatus
+pattern ControlOperationStatus_IN_PROGRESS = ControlOperationStatus' "IN_PROGRESS"
+
+pattern ControlOperationStatus_SUCCEEDED :: ControlOperationStatus
+pattern ControlOperationStatus_SUCCEEDED = ControlOperationStatus' "SUCCEEDED"
+
+{-# COMPLETE
+  ControlOperationStatus_FAILED,
+  ControlOperationStatus_IN_PROGRESS,
+  ControlOperationStatus_SUCCEEDED,
+  ControlOperationStatus'
+  #-}
diff --git a/gen/Amazonka/ControlTower/Types/ControlOperationType.hs b/gen/Amazonka/ControlTower/Types/ControlOperationType.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/Types/ControlOperationType.hs
@@ -0,0 +1,71 @@
+{-# LANGUAGE DeriveGeneric #-}
+{-# LANGUAGE DerivingStrategies #-}
+{-# LANGUAGE GeneralizedNewtypeDeriving #-}
+{-# LANGUAGE LambdaCase #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE PatternSynonyms #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.Types.ControlOperationType
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Amazonka.ControlTower.Types.ControlOperationType
+  ( ControlOperationType
+      ( ..,
+        ControlOperationType_DISABLE_CONTROL,
+        ControlOperationType_ENABLE_CONTROL
+      ),
+  )
+where
+
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
+
+newtype ControlOperationType = ControlOperationType'
+  { fromControlOperationType ::
+      Data.Text
+  }
+  deriving stock
+    ( Prelude.Show,
+      Prelude.Read,
+      Prelude.Eq,
+      Prelude.Ord,
+      Prelude.Generic
+    )
+  deriving newtype
+    ( Prelude.Hashable,
+      Prelude.NFData,
+      Data.FromText,
+      Data.ToText,
+      Data.ToByteString,
+      Data.ToLog,
+      Data.ToHeader,
+      Data.ToQuery,
+      Data.FromJSON,
+      Data.FromJSONKey,
+      Data.ToJSON,
+      Data.ToJSONKey,
+      Data.FromXML,
+      Data.ToXML
+    )
+
+pattern ControlOperationType_DISABLE_CONTROL :: ControlOperationType
+pattern ControlOperationType_DISABLE_CONTROL = ControlOperationType' "DISABLE_CONTROL"
+
+pattern ControlOperationType_ENABLE_CONTROL :: ControlOperationType
+pattern ControlOperationType_ENABLE_CONTROL = ControlOperationType' "ENABLE_CONTROL"
+
+{-# COMPLETE
+  ControlOperationType_DISABLE_CONTROL,
+  ControlOperationType_ENABLE_CONTROL,
+  ControlOperationType'
+  #-}
diff --git a/gen/Amazonka/ControlTower/Types/EnabledControlSummary.hs b/gen/Amazonka/ControlTower/Types/EnabledControlSummary.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/Types/EnabledControlSummary.hs
@@ -0,0 +1,78 @@
+{-# LANGUAGE DeriveGeneric #-}
+{-# LANGUAGE DuplicateRecordFields #-}
+{-# LANGUAGE NamedFieldPuns #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE RecordWildCards #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+{-# OPTIONS_GHC -fno-warn-unused-matches #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.Types.EnabledControlSummary
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Amazonka.ControlTower.Types.EnabledControlSummary where
+
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Core.Lens.Internal as Lens
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
+
+-- | A summary of enabled controls.
+--
+-- /See:/ 'newEnabledControlSummary' smart constructor.
+data EnabledControlSummary = EnabledControlSummary'
+  { -- | The ARN of the control. Only __Strongly recommended__ and __Elective__
+    -- controls are permitted, with the exception of the __Region deny__
+    -- guardrail.
+    controlIdentifier :: Prelude.Maybe Prelude.Text
+  }
+  deriving (Prelude.Eq, Prelude.Read, Prelude.Show, Prelude.Generic)
+
+-- |
+-- Create a value of 'EnabledControlSummary' with all optional fields omitted.
+--
+-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
+--
+-- The following record fields are available, with the corresponding lenses provided
+-- for backwards compatibility:
+--
+-- 'controlIdentifier', 'enabledControlSummary_controlIdentifier' - The ARN of the control. Only __Strongly recommended__ and __Elective__
+-- controls are permitted, with the exception of the __Region deny__
+-- guardrail.
+newEnabledControlSummary ::
+  EnabledControlSummary
+newEnabledControlSummary =
+  EnabledControlSummary'
+    { controlIdentifier =
+        Prelude.Nothing
+    }
+
+-- | The ARN of the control. Only __Strongly recommended__ and __Elective__
+-- controls are permitted, with the exception of the __Region deny__
+-- guardrail.
+enabledControlSummary_controlIdentifier :: Lens.Lens' EnabledControlSummary (Prelude.Maybe Prelude.Text)
+enabledControlSummary_controlIdentifier = Lens.lens (\EnabledControlSummary' {controlIdentifier} -> controlIdentifier) (\s@EnabledControlSummary' {} a -> s {controlIdentifier = a} :: EnabledControlSummary)
+
+instance Data.FromJSON EnabledControlSummary where
+  parseJSON =
+    Data.withObject
+      "EnabledControlSummary"
+      ( \x ->
+          EnabledControlSummary'
+            Prelude.<$> (x Data..:? "controlIdentifier")
+      )
+
+instance Prelude.Hashable EnabledControlSummary where
+  hashWithSalt _salt EnabledControlSummary' {..} =
+    _salt `Prelude.hashWithSalt` controlIdentifier
+
+instance Prelude.NFData EnabledControlSummary where
+  rnf EnabledControlSummary' {..} =
+    Prelude.rnf controlIdentifier
diff --git a/gen/Amazonka/ControlTower/Waiters.hs b/gen/Amazonka/ControlTower/Waiters.hs
new file mode 100644
--- /dev/null
+++ b/gen/Amazonka/ControlTower/Waiters.hs
@@ -0,0 +1,24 @@
+{-# LANGUAGE DisambiguateRecordFields #-}
+{-# LANGUAGE OverloadedStrings #-}
+{-# LANGUAGE StrictData #-}
+{-# LANGUAGE TypeFamilies #-}
+{-# LANGUAGE NoImplicitPrelude #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Amazonka.ControlTower.Waiters
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Amazonka.ControlTower.Waiters where
+
+import Amazonka.ControlTower.Lens
+import Amazonka.ControlTower.Types
+import qualified Amazonka.Core as Core
+import qualified Amazonka.Core.Lens.Internal as Lens
+import qualified Amazonka.Data as Data
+import qualified Amazonka.Prelude as Prelude
diff --git a/src/.gitkeep b/src/.gitkeep
new file mode 100644
--- /dev/null
+++ b/src/.gitkeep
diff --git a/test/Main.hs b/test/Main.hs
new file mode 100644
--- /dev/null
+++ b/test/Main.hs
@@ -0,0 +1,23 @@
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+
+-- |
+-- Module      : Main
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Main (main) where
+
+import Test.Amazonka.ControlTower
+import Test.Amazonka.ControlTower.Internal
+import Test.Tasty
+
+main :: IO ()
+main =
+  defaultMain $
+    testGroup
+      "ControlTower"
+      [ testGroup "tests" tests,
+        testGroup "fixtures" fixtures
+      ]
diff --git a/test/Test/Amazonka/ControlTower.hs b/test/Test/Amazonka/ControlTower.hs
new file mode 100644
--- /dev/null
+++ b/test/Test/Amazonka/ControlTower.hs
@@ -0,0 +1,20 @@
+-- |
+-- Module      : Test.Amazonka.ControlTower
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Test.Amazonka.ControlTower
+  ( tests,
+    fixtures,
+  )
+where
+
+import Test.Tasty (TestTree)
+
+tests :: [TestTree]
+tests = []
+
+fixtures :: [TestTree]
+fixtures = []
diff --git a/test/Test/Amazonka/ControlTower/Internal.hs b/test/Test/Amazonka/ControlTower/Internal.hs
new file mode 100644
--- /dev/null
+++ b/test/Test/Amazonka/ControlTower/Internal.hs
@@ -0,0 +1,8 @@
+-- |
+-- Module      : Test.Amazonka.ControlTower.Internal
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Test.Amazonka.ControlTower.Internal where
diff --git a/test/Test/Amazonka/Gen/ControlTower.hs b/test/Test/Amazonka/Gen/ControlTower.hs
new file mode 100644
--- /dev/null
+++ b/test/Test/Amazonka/Gen/ControlTower.hs
@@ -0,0 +1,118 @@
+{-# OPTIONS_GHC -fno-warn-orphans #-}
+{-# OPTIONS_GHC -fno-warn-unused-imports #-}
+
+-- Derived from AWS service descriptions, licensed under Apache 2.0.
+
+-- |
+-- Module      : Test.Amazonka.Gen.ControlTower
+-- Copyright   : (c) 2013-2023 Brendan Hay
+-- License     : Mozilla Public License, v. 2.0.
+-- Maintainer  : Brendan Hay
+-- Stability   : auto-generated
+-- Portability : non-portable (GHC extensions)
+module Test.Amazonka.Gen.ControlTower where
+
+import Amazonka.ControlTower
+import qualified Data.Proxy as Proxy
+import Test.Amazonka.ControlTower.Internal
+import Test.Amazonka.Fixture
+import Test.Amazonka.Prelude
+import Test.Tasty
+
+-- Auto-generated: the actual test selection needs to be manually placed into
+-- the top-level so that real test data can be incrementally added.
+--
+-- This commented snippet is what the entire set should look like:
+
+-- fixtures :: TestTree
+-- fixtures =
+--     [ testGroup "request"
+--         [ requestDisableControl $
+--             newDisableControl
+--
+--         , requestEnableControl $
+--             newEnableControl
+--
+--         , requestGetControlOperation $
+--             newGetControlOperation
+--
+--         , requestListEnabledControls $
+--             newListEnabledControls
+--
+--           ]
+
+--     , testGroup "response"
+--         [ responseDisableControl $
+--             newDisableControlResponse
+--
+--         , responseEnableControl $
+--             newEnableControlResponse
+--
+--         , responseGetControlOperation $
+--             newGetControlOperationResponse
+--
+--         , responseListEnabledControls $
+--             newListEnabledControlsResponse
+--
+--           ]
+--     ]
+
+-- Requests
+
+requestDisableControl :: DisableControl -> TestTree
+requestDisableControl =
+  req
+    "DisableControl"
+    "fixture/DisableControl.yaml"
+
+requestEnableControl :: EnableControl -> TestTree
+requestEnableControl =
+  req
+    "EnableControl"
+    "fixture/EnableControl.yaml"
+
+requestGetControlOperation :: GetControlOperation -> TestTree
+requestGetControlOperation =
+  req
+    "GetControlOperation"
+    "fixture/GetControlOperation.yaml"
+
+requestListEnabledControls :: ListEnabledControls -> TestTree
+requestListEnabledControls =
+  req
+    "ListEnabledControls"
+    "fixture/ListEnabledControls.yaml"
+
+-- Responses
+
+responseDisableControl :: DisableControlResponse -> TestTree
+responseDisableControl =
+  res
+    "DisableControlResponse"
+    "fixture/DisableControlResponse.proto"
+    defaultService
+    (Proxy.Proxy :: Proxy.Proxy DisableControl)
+
+responseEnableControl :: EnableControlResponse -> TestTree
+responseEnableControl =
+  res
+    "EnableControlResponse"
+    "fixture/EnableControlResponse.proto"
+    defaultService
+    (Proxy.Proxy :: Proxy.Proxy EnableControl)
+
+responseGetControlOperation :: GetControlOperationResponse -> TestTree
+responseGetControlOperation =
+  res
+    "GetControlOperationResponse"
+    "fixture/GetControlOperationResponse.proto"
+    defaultService
+    (Proxy.Proxy :: Proxy.Proxy GetControlOperation)
+
+responseListEnabledControls :: ListEnabledControlsResponse -> TestTree
+responseListEnabledControls =
+  res
+    "ListEnabledControlsResponse"
+    "fixture/ListEnabledControlsResponse.proto"
+    defaultService
+    (Proxy.Proxy :: Proxy.Proxy ListEnabledControls)
