> It would also be nice if integrations could be blocked or de-authorized from the AWS side
I have no idea how DataDog integration works but if I had to guess I'd expect to setup an IAM account for them to use? If so, you could delete the IAM account they're using.