I'm not talking legal blame for the past mistake, just that at some point in the near future their IAM interface should be fixed. For one thing it should be easy to give permissions to view the permissions without giving keys to the kingdom. For another thing, there's a mental overhead to working with multiple AWS accounts [1]. I get the impression that Google Cloud Platform is ahead right now (while lots of other Google properties are not, heh).
Edit: the spyware company is absolutely to blame, but the complexity of AWS permissions including permission to view the permissions seems like a footgun to me. However, leaving open the admin site is something I wouldn't expect AWS to help with.
https://engineering.coinbase.com/you-need-more-than-one-aws-...