We’re building a threat model for a cloud-based messaging service but are unsure how to structure it for clarity and completeness. Are there specific templates, tools, or best practices for documenting threat models in this context? What should we focus on to address cloud-specific threats effectively?