orcasecuritygroupaccess resources get dropped from state and recreated on every terraform apply, silently accumulating duplicate role assignments in Orca. One org grew to 120 assignment rows for 32 distinct grants. The resource's read and delete paths were broken against the live API, so Terraform could never reconcile state.