Summary
The team has learned about the IAM concepts (users, user groups, roles, and policies) but is now facing some practical work ahead. With all they know now, they have to decide which IAM entities to create.
After that, they will create the right permissions grouped inside policies, assign them as needed, and test them exhaustively. Only then will they begin to create more users for other departments.
Gloria also wants to help the team more practically. She’s planning to request an audit log after all those permissions are in place, to see whether everything is running as expected or not.