When I give 'iam:*' permissions to an IAM role and it inevitably gets exploited to create a role with wider permissions and fuck things up, is that when I tell my manager that the permissions went rogue?
After all, I an innocent little engineer with TC of $500k/year, didn't intend for the role to be used that way.