A large organization\’s internal certificate needs rarely fit neatly into a single, simple CA structure. Different business units have different risk profiles, different geographic regions face different regulatory requirements, and different categories of identity, from employee laptops to AI agents, need meaningfully different issuance policies. This article covers the design patterns large organizations actually use to structure a private CA that can serve all of this coherently, building on the foundational internal CA concepts covered earlier in this series.