Is that true though? IAM isn’t open, and things like service accounts and service chaining (a can only access b through c) are also not.