What IAM Permissions Does a Cost-Optimization Tool Actually Need? An Honest Read-Only Scope You Can Defend in Security Review
A platform team starts a security review for a cost-optimization vendor. The vendor's onboarding doc asks for a CloudFormation template that creates a role with "to ensure all features work." The…