> poor IAM policy and role modeling
This is a bad take. Making good IAM Roles and Policies is incredibly complicated if you have a complicated account. You WILL get it wrong. This becomes much more tractable if you have reasonable account boundaries between workloads.
If you insist on a single massive account you're fighting against the way that AWS designs the system, and you're gonna have a bad time.