to help track down which user is using an assigned role from a DT, allow the DT binding to provide some kind of DT/correlation ID. The binding can then build that up when the token is issued, and then serve it up later
If this is picked up and added to the UA header, then S3 logs can let you go backwards from requests to the specific DT issues/used, and then even the principal.
For the standard bindings, we'd return: principal + UUID