I understand that we can enforce tagging on resources on AWS by introducing IAM policies, for example for EC2,
{ "Version": "2012-10-17", &quo