Security
Scope IAM permissions to the specific destination bucket used by each Channel.
Use the
aws:SourceArncondition in the trust policy to prevent other clusters or services from assuming the Channel role.Enable CloudTrail logging to audit all Channel API calls.