- Introduce DEBUG permission for federated permissions to view unredacted secure logs
- Allow owners to grant specific IAM users, roles, or groups access without disabling secure logging
- Enable unredacted log export to S3 while maintaining fine‑grained audit control