-
…in reply to @JustinBeckwith
JustinBeckwith I usually use a service account with a large role for a bit, and then wait for the IAM recommender to kick in and suggest me a custom role with only the permissions needed based on historical API usage from that account