I'd like to have an IAM user which would be able to create whatever resources they like, BUUTTTT able to see and manage only those resources created by itself, like a "subcloud" which has no idea about others, or like having completely separate root accounts basically (while keeping the overview from the one root account). I can't find anything of sorts... Permission boundaries and generally all policies seem to only be based on restricting on actions, while I want to restrict on ownership.