We do at AWS. Not all commands though, but most commands that we audit and find are dangerous.
See a similar outage in S3 from 2 years ago - https://aws.amazon.com/message/41926/
See a similar outage in S3 from 2 years ago - https://aws.amazon.com/message/41926/
That above seems pretty clunky, so it's very likely not what happens.
In this particular case, commands that were run on a Production machine were by-design limited to what they can do and affect (mostly just the physical host they’re run on or a few hosts in the logical group of hosts they belong to).