Update 4/9/2025: The cross-account bucket policy in the blog has been updated. It was missing a required principal: “arn:aws:iam::accountID:role/AWS-Signed-In-Console-Role.” This omission causes an access denied error. As enterprises evolve their cloud governance practices, multiple teams working in separate accounts may need to share data.