## Module functionality
Creates an IAM policy that allows RW access to a buckets that fall under the provided list of bucket_masks
