The IAM Roles created as part of AFT Bootstrap process of the workshop - AWSAFTService and AWSAFTExecution have trust policies which allow the role to be assumed by principals outside of aws organization.
This may result in security incidents in most organizations