An enterprise has contracted a third-party service provider to carry out tasks within the companys AWS environment. The vendor operates an automated system hosted in their own AWS account, and they do not have direct IAM user access to the enterprises AWS account. The company wants to securely grant this tool permission to access resources in their AWS account without creating IAM users for the vendor.What is the most secure and appropriate way for the company to provide access to the vendor's automated tool?