You can grant users permissions to access different resources.
When personnel changes occur, you only need to change the user groups to which the users belong.
You (account A) can grant permissions to another account (account B) by creating an agency. Account B can then grant the Agent Operator permissions to a user so that the user can manage resources in your account (account A).
You can federate external users to IAM and grant permissions to the users to access cloud resources by creating an identity provider and identity conversion rules.