Since ALKS no longer produces federated access keys, it'd help reduce confusion to remove references to things like the -i flag on the ALKS CLI. Perhaps the message could more clearly indicate that the current credentials aren't eligible to manage IAM resources via the ALKS API?