"AWS": "arn:aws:iam::123456789012:root"       // Entire AWS account
  "AWS": "arn:aws:iam::123456789012:user/username // IAM user
  "AWS": "arn:aws:iam::123456789012:role/roleName" // IAM role
  "Service": "ec2.amazonaws.com" // Service
  "Federated": "arn:aws:iam::123456789012:saml-provider/MyProvider"
  "CanonicalUser": "79a59df900b949e55d96a1e698fba1bc14EXAMPLE" //

canonicalUser - oac vs oai