I'm being dumb. I can see that it is preferable to embed credentials for a restricted IAM acct, not your root/master AWS account.
But how does using a TVM improve the situation? Surely you still need to embed creds which allow the app to use the TVM? In that case, an attacker can extract those creds, and ask the TVM for a time-limited token any time they like.
How does using a TVM improve security over embedding the creds of a restricted account?