The idea is that instead of having a "main" accless code that we run on start-up, we fetch attributes lazily, whenever we fetch an element from S3 that is encrypted and comes with an embedded policy.
In an ideal world, we would have a registry of authenticated APS which we can query based on the ID, but we may not need that just now.