You create a cross‑account role in your AWS account that trusts the app’s AWS account. The role name is unique per user. When a task needs AWS access, the app uses that role to access your account to perform read‑oriented operations requested by you.