I don't buy that audit trail clarity is a win for the role. It's a wash, maybe even worse. Sure, you get a session name you can format, but you're relying on a contractor-run wrapper script to do it right, as the later posts show. They'll mess it up, or forget, or their CI runner won't have `whoami` set. Now your "clear" trail has a hundred sessions named `default-session-123`. With a dedicated IAM user, at least every single call is tied to a unique, permanent ARN that maps directly to a human in your identity system. That's easier to automate alerts on.
And on revocation being "instant" by updating the trust policy, that assumes you catch it. If they've already assumed the role and have a 12-hour session, your policy update does nothing until that session expires. Deactivating an IAM user's single set of keys is a more concrete, immediate sever.