This workflow runs a report to identify IAM users and roles with excessive permissions. If findings are present, it moves to an approval stage and then remediates the excessive permissions via a blueprint; if no findings, the workflow ends with no action.