My customer AWS account was full of IAM accounts, they never rotated the IAM keys, and permissions were really too large. I help them to put in place best practices and trained the teams to not use AWS IAM accounts or IAM keys but use IAM roles in their application. I restricted and migrated everything (more than 200 users, used for applications and people) I also put in place IAM roles for the developers with the help of their SAML provider, so local users don't use IAM accounts but also IAM roles It was a 6 months full-time project and customer CTO was really happy after this project