Why are good AWS security policies so difficult?

Creating good AWS security policies is difficult for two reasons. First, the powerful AWS security model is complex and difficult to understand.  Second, application deployments are changing and growing rapidly. Why is AWS IAM so @!#^$ hard? One of our favorite...