Here’s a moment that comes up in nearly every compliance review: a security engineer pulls a list of IAM roles in the AWS environment. The list is long. Some roles were created for a migration project that closed two quarters ago, a few belong to contractors who haven’t worked there in over a year, and others are attached to agentic identities without any way to see which human they were acting on behalf of.