We need only limited set of permissions for select AWS services at the time signup and these are available for review. This can be revoked from your end at any time.  We cannot access your environment/resources once the access is revoked. Specifically, our permissions does not allow us to log into your compute / database resources. Our permission set is restricted to provisioning of infrastructure and collecting cost and usage metrics of your AWS account. We use cross account delegate access of AWS with a limited permission set. This is the prescribed mechanism by AWS for third party access to the AWS environment.