Permissions Policies are confusing because they can get very complex... because enterprises need that functionality. IDK, maybe I'm in the minority but I don't think IAM is something that can/should be watered down.
- IAM / Bucket Policies as mentioned
- S3 Block Public Access (yes this is the name of a distinct feature)
- S3 Access Points
The interactions between all four of the above need to be taken into account to determine the access a consumer has to a bucket or its objects.
I'm not taking a swing at IAM - it's a great system. My grudge is with AWS having disparate interacting security controls for different services (of which S3 is probably the worst offender).
To heave back onto the topic at hand, let's hope R2 can do better having the benefit of a clean slate to build off!