Closing the AWS account or changing certain account settings is treated as root-level territory. What should the city do for ordinary daily cloud work?
Select an answer to reveal the explanation.
Short Explanation
Root is the emergency wrench in the glass case — break it out to close the account or handle certain account settings, then lock it away again. Everyday builds, stops, and tickets should run under IAM identities.
Full Explanation
Some account-level operations require the root user, but AWS best practice is to avoid using root for daily administration. IAM users, groups, roles, and Identity Center permission sets should handle routine work under least privilege, with root protected by MFA and carefully controlled access.