Not promoting anything here, I simply had a similar access problem and this helped me. I wanted to test the idea before applying it to production roles, so I created a few examples with permissions I knew were unnecessary or rarely used. I tested cloud unused access detection while looking at unused access detection and unused permissions, and it made the review process much clearer for me. That small test gave me more confidence before I started changing real permissions. https://teriam.io/cloud-unused-access-detection/