Resource policies create a second authorisation surface

In cloud platforms, permission can be granted from the identity's side or from the resource's side, and both have to be considered.

A bucket can allow access to an account the account's own policies never mentioned. Reviewing only identity permissions therefore gives an incomplete answer, and resource policies are where accidental public or cross-account access usually originates.

More on Cloud IAM