How does the provider handle scope creep on nice_cxone_iam_role when the UI grants extra permissions outside the state file? The 07:00 JST sync pipeline’s doing jack all right now since Terraform 1.9.11 with nice-cxone 1.21.3 won’t drop the perpetual drift on the permissions block.
Ran tf apply -refresh-only and the debug logs show the remote state hash matches the local state hash exactly. Console output still wants to update the block every single cycle.