Edge BYOC validation failing with 403 during Zendesk migration

Stuck on the Edge BYOC configuration step while migrating our Zendesk support structure to Genesys Cloud. We are trying to replicate the local failover capabilities we had in Zendesk by setting up a private edge, but the deployment validator returns a 403 Forbidden error on POST /api/v2/edges/byoc. The payload includes the correct edge_profile_id and region settings derived from our Zendesk data center locations, yet the API rejects the request immediately.

Is there a specific IAM role or permission set required for BYOC that is often overlooked when moving from Zendesk’s simpler infrastructure model? We have verified the network connectivity and firewall rules, but the error persists. The documentation mentions a trust relationship requirement, but it is unclear if this needs to be configured before the initial POST request. We are using the latest Genesys Cloud API v2 endpoints. Any insights on what might be blocking this specific migration path would be appreciated. We are aiming to go live next week and this blocker is critical for our data residency compliance.