Bicep does that, but it's Azure only, and you can't really 'destroy', just apply.
https://learn.microsoft.com/en-us/azure/azure-resource-manag...
Not sure how I could "misunderstand" this quote to mean anything else.
By that logic, CloudFormation is also the same; end users don't have access to the state so therefore the state file is the state of the environment itself? We, as users, have no idea what intermediate step exists between the configuration yaml and actual representation of an account's resources.