Unused cloud permissions are latent attack paths

Permissions that have never been used are still permissions.

Cloud providers record what each account actually does, which means you can compare granted against used, and the gap is usually enormous. Every unused permission does nothing for the business and everything for whoever takes the account. It is one of the few security clean-ups with a genuinely low risk of breaking anything, because by definition nobody has been using it.

More on Cloud IAM