Well, we do have service providers and identity providers separated for some reason in all the pretty architecture pictures… 😛
Though in fairness to Amazon this looks like you have to audit account use, have proper procedures and watch for the little credential squirrels wheresoever they may be.