Adjusting Role Documents in FlexOrgs would be the best method.
To demonstrate a method to achieve this using FlexOrgs:
Whereby creating a FlexOrg Organization for each unique AWS account and then assigning a user group to a System Defined role e.g. Standard, Power User or Admin role that is specific to the account: