AWS monitoring - role based access?

We are interested in using AWS integrations.

Is a service account in each account the only way to connect?

Service account creation is restricted. We would also need to create an additional step when creating new accounts.

Are there no role-based access options?