The article discusses the complexity and challenges of Identity and Access Management (IAM) in cloud providers, particularly in AWS and GCP. The author argues that the current system is broken and proposes a solution where permissions are automatically scoped based on actual usage. The author also criticizes the current system for being overly complicated and prone to security risks. The article highlights the need for a more streamlined and automated approach to IAM.