How access fits together
A principal can hold several roles, and their grants combine. Only Allow permissions are supported: a role with fewer permissions does not cancel access granted by another role. Creating a permission grants no access until it belongs to an assigned role.
For an IAM-controlled action, the required grant must match the action and resource scope. Without it, access is denied.