No worries - very welcomed questions.
The thing I need the most, is an ability to know what organization the token belongs to. Then, all of what we discussed could be accomplished.
In the case of AWS, this is possible with an ARN because the org id is embedded, and the credentials can return the associated organization.