As the linked tweet says: "If you check out the AWS docs on IAM policy parsing order there is a flowchart that shows you can get an Allow outcome before the boundary policy is evaluated."
IAM-Deescalate: is an open source tool to help users reduce the risk of privilege escalation.
Twilio's Insecure Text Message Issue | AWS Morning Brief podcast - Listen or read transcript on Metacast