There is a specific property that the KMS Keyring can ensure regarding the EDKs it produces and the EC used to wrap/unwrap data keys. The property is something along the lines of "If KMS is set up correctly, users who have the ability to only unwrap data keys are unable to modify the EC"
We need to determine the correct wording for this property, and define this new flag in the spec.