Well, I'd be curious if that means it has more permissions that necessary to run in production because of that - e.g. to create an arbitrary bucket, or queue, or IAM policy.
Deployed services don't currently have permissions to provision or modify infrastructure. This is done by our build system while your services are being compiled. It is an orthogonal control plane with its own permission system.