Currently, session tagging when assuming an AWS IAM Role via Spacelift will only tag the first assumption. For situations where there are multiple links in an assumption chain, e.g using a Spacelift integration to automatically assume an access role, then using the OpenTofu AWS provider to assume a second role in a target account, this means only the access role assumption is tagged.
Ideally, transitive session tags would be used so the tag persists through the entire assumption chain.
AWS docs for session tagging for reference: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html
Our security team is keen for this feature so that AWS CloudTrail events can be captured in our SIEM to understand exactly which Spacelift stack run resulted in changes, which can then be linked back to specific commits/authors.