Securing AWS Lambda Execution Roles When to Use - When deploying new Lambda functions and defining their IAM execution roles - When remediating overly permissive Lambda roles discovered during security audits - When implementing least-privilege access patterns for serverless architectures - When building reusable IAM templates for Lambda functions across teams - When Security Hub or Prowler reports Lambda functions with excessive permissions Do not use for securing Lambda function invocation (use resource-based policies and API Gateway authorizers), for Lambda code security (use SAST tools),…