Often Cloud teams are left in the dark with no way of confidently knowing who can administer IAM, what permissions are actually granted to principals and data resources, whether that access has changed recently. If you are dealing with this, I feel your pain. I know...