This blog is in Japanese — sorry about that — but it might still be helpful if you use your browser’s translation feature to read it in English:
https://qiita.com/YoHey/items/649278b86b961af27472
Basically, it explains how to automatically create the IAM role needed for Turbonomic operations in member accounts under a management account by using AWS CloudFormation StackSets.