You've more or less got it. You authorize to the vault and store the secrets in memory. So no passwords on-disk/in-source 'floating around'.
Note that with AWS IAM auth, AWS is a trusted third party, and accounts with high-powered IAM access (think AWS admins) end up having a great deal of authority in Vault, too. But for us, at least, these assumptions are reasonable.