Your question is IAM at Scale and Secrets Policies. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
How would you fix overly generous access policies at scale for both user and service accounts, and how would you apply the same approach to Vault secrets policies? Also, explain how you implement SAML and OAuth flows and scale IAM across an enterprise.