"AWS": "arn:aws:iam::123456789012:root" // Entire AWS account
"AWS": "arn:aws:iam::123456789012:user/username // IAM user
"AWS": "arn:aws:iam::123456789012:role/roleName" // IAM role
"Service": "ec2.amazonaws.com" // Service
"Federated": "arn:aws:iam::123456789012:saml-provider/MyProvider"
"CanonicalUser": "79a59df900b949e55d96a1e698fba1bc14EXAMPLE" //
canonicalUser - oac vs oai