Status: IN
The `AWSCloudTrail_FullAccess` policy scopes S3 and SNS write permissions to resources matching `aws-cloudtrail-logs*` — not all buckets/topics.
Source: entries/2026/03/12/aws-managed-policy-latest-reference-AWSCloudTrail_FullAccesshtml.md