Just permissions. The "IAM" can be safely dropped. It's exactly what you think it'd be: restrictions and privileges.
"IAM" is basically the name for a specific model of doing it.
Unless something really crazy happened, this user is unlikely to be correct. Accounts are supposed to be firewalled/sandboxed in a way that you can't contagion across to someone else's let alone systemwide.
It's possible (some sweeping script on a powerful connection that smashes just the right things or some exploit to break the sandboxing), just probably not likely - especially unintentionally.