...granted based on an AWS Account ID. Once authenticated, a subscriber has full access to all user operations in the system. Access to each individual domain is controlled by an independent Access Control List (ACL) that maps authenticated users...
http://s3.amazonaws.com/aws_blog/AWS_Security_Whitepaper_2008_09.pdf