Domain 1 of the SAA-C03 covers secure architectures — and it starts with identity. Here’s everything I’ve learned about IAM, STS, Cognito, Organizations, and how AWS decides who gets to do what.