This page lists the IAM roles and permissions for Network Connectivity Center. To search through all roles and permissions, see the role and permission index .
Network Connectivity Center roles
Networkconnectivity Editor
( roles/
)
Editor role for networkconnectivity
networkconnectivity.
-
networkconnectivity.gatewayAdvertisedRoutes. create -
networkconnectivity.gatewayAdvertisedRoutes. delete -
networkconnectivity.gatewayAdvertisedRoutes. get -
networkconnectivity.gatewayAdvertisedRoutes. list -
networkconnectivity.gatewayAdvertisedRoutes. update
networkconnectivity.
networkconnectivity.
networkconnectivity.groups.get
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.groups.use
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.hubs.get
networkconnectivity.
networkconnectivity.hubs.list
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
-
networkconnectivity.locations. get -
networkconnectivity.locations. list
networkconnectivity.
-
networkconnectivity.multicloudDataTransferConfigs. create -
networkconnectivity.multicloudDataTransferConfigs. delete -
networkconnectivity.multicloudDataTransferConfigs. get -
networkconnectivity.multicloudDataTransferConfigs. list -
networkconnectivity.multicloudDataTransferConfigs. update
networkconnectivity.
-
networkconnectivity.multicloudDataTransferDestinations. create -
networkconnectivity.multicloudDataTransferDestinations. delete -
networkconnectivity.multicloudDataTransferDestinations. get -
networkconnectivity.multicloudDataTransferDestinations. list -
networkconnectivity.multicloudDataTransferDestinations. update
networkconnectivity.
-
networkconnectivity.multicloudDataTransferSupportedServices. get -
networkconnectivity.multicloudDataTransferSupportedServices. list
networkconnectivity.
-
networkconnectivity.operations. cancel -
networkconnectivity.operations. delete -
networkconnectivity.operations. get -
networkconnectivity.operations. list
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
-
networkconnectivity.regionalEndpoints. create -
networkconnectivity.regionalEndpoints. delete -
networkconnectivity.regionalEndpoints. get -
networkconnectivity.regionalEndpoints. list
networkconnectivity.
-
networkconnectivity.remoteTransportProfiles. get -
networkconnectivity.remoteTransportProfiles. list
networkconnectivity.
-
networkconnectivity.serviceClasses. create -
networkconnectivity.serviceClasses. delete -
networkconnectivity.serviceClasses. get -
networkconnectivity.serviceClasses. list -
networkconnectivity.serviceClasses. update -
networkconnectivity.serviceClasses. use
networkconnectivity.
-
networkconnectivity.serviceConnectionMaps. create -
networkconnectivity.serviceConnectionMaps. delete -
networkconnectivity.serviceConnectionMaps. get -
networkconnectivity.serviceConnectionMaps. list -
networkconnectivity.serviceConnectionMaps. update
networkconnectivity.
-
networkconnectivity.serviceConnectionPolicies. create -
networkconnectivity.serviceConnectionPolicies. delete -
networkconnectivity.serviceConnectionPolicies. get -
networkconnectivity.serviceConnectionPolicies. list -
networkconnectivity.serviceConnectionPolicies. update
networkconnectivity.
networkconnectivity.
networkconnectivity.spokes.get
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
-
networkconnectivity.transports. create -
networkconnectivity.transports. delete -
networkconnectivity.transports. get -
networkconnectivity.transports. list -
networkconnectivity.transports. update
resourcemanager.projects.get
resourcemanager.projects.list
Service Automation Consumer Network Admin
( roles/
)
Service Automation Consumer Network Admin is responsible for setting up ServiceConnectionPolicies.
networkconnectivity.
-
networkconnectivity.serviceConnectionPolicies. create -
networkconnectivity.serviceConnectionPolicies. delete -
networkconnectivity.serviceConnectionPolicies. get -
networkconnectivity.serviceConnectionPolicies. list -
networkconnectivity.serviceConnectionPolicies. update
resourcemanager.projects.get
resourcemanager.projects.list
Group Admin
( roles/
)
Enables full access to group resources and read-only access to hub and spoke resources
networkconnectivity.
networkconnectivity.
networkconnectivity.groups.*
-
networkconnectivity.groups. acceptSpoke -
networkconnectivity.groups. acceptSpokeUpdate -
networkconnectivity.groups.get -
networkconnectivity.groups. getIamPolicy -
networkconnectivity.groups. list -
networkconnectivity.groups. rejectSpoke -
networkconnectivity.groups. rejectSpokeUpdate -
networkconnectivity.groups. setIamPolicy -
networkconnectivity.groups.use
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.hubs.get
networkconnectivity.
networkconnectivity.hubs.list
networkconnectivity.
-
networkconnectivity.locations. get -
networkconnectivity.locations. list
networkconnectivity.
networkconnectivity.
networkconnectivity.spokes.get
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Group User
( roles/
)
Enables use access on group resources
networkconnectivity.groups.use
Hub & Spoke Admin
( roles/
)
Enables full access to hub and spoke resources.
Lowest-level resources where you can grant this role:
- Project
networkconnectivity.
-
networkconnectivity.gatewayAdvertisedRoutes. create -
networkconnectivity.gatewayAdvertisedRoutes. delete -
networkconnectivity.gatewayAdvertisedRoutes. get -
networkconnectivity.gatewayAdvertisedRoutes. list -
networkconnectivity.gatewayAdvertisedRoutes. update
networkconnectivity.groups.*
-
networkconnectivity.groups. acceptSpoke -
networkconnectivity.groups. acceptSpokeUpdate -
networkconnectivity.groups.get -
networkconnectivity.groups. getIamPolicy -
networkconnectivity.groups. list -
networkconnectivity.groups. rejectSpoke -
networkconnectivity.groups. rejectSpokeUpdate -
networkconnectivity.groups. setIamPolicy -
networkconnectivity.groups.use
networkconnectivity.
-
networkconnectivity.hubRouteTables. get -
networkconnectivity.hubRouteTables. getIamPolicy -
networkconnectivity.hubRouteTables. list -
networkconnectivity.hubRouteTables. setIamPolicy
networkconnectivity.
-
networkconnectivity.hubRoutes. get -
networkconnectivity.hubRoutes. getIamPolicy -
networkconnectivity.hubRoutes. list -
networkconnectivity.hubRoutes. setIamPolicy
networkconnectivity.hubs.*
-
networkconnectivity.hubs. create -
networkconnectivity.hubs. delete -
networkconnectivity.hubs.get -
networkconnectivity.hubs. getIamPolicy -
networkconnectivity.hubs.list -
networkconnectivity.hubs. listSpokes -
networkconnectivity.hubs. queryStatus -
networkconnectivity.hubs. setIamPolicy -
networkconnectivity.hubs. update
networkconnectivity.
-
networkconnectivity.locations. get -
networkconnectivity.locations. list
networkconnectivity.
-
networkconnectivity.operations. cancel -
networkconnectivity.operations. delete -
networkconnectivity.operations. get -
networkconnectivity.operations. list
networkconnectivity.spokes.*
-
networkconnectivity.spokes. create -
networkconnectivity.spokes. delete -
networkconnectivity.spokes.get -
networkconnectivity.spokes. getIamPolicy -
networkconnectivity.spokes. list -
networkconnectivity.spokes. setIamPolicy -
networkconnectivity.spokes. update
resourcemanager.projects.get
resourcemanager.projects.list
Hub & Spoke Viewer
( roles/
)
Enables read-only access to hub and spoke resources.
Lowest-level resources where you can grant this role:
- Project
networkconnectivity.
networkconnectivity.
networkconnectivity.groups.get
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.hubs.get
networkconnectivity.
networkconnectivity.hubs.list
networkconnectivity.
networkconnectivity.
networkconnectivity.
-
networkconnectivity.locations. get -
networkconnectivity.locations. list
networkconnectivity.spokes.get
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Multicloud Data Transfer Config Admin
( roles/
)
Full access to all Multicloud Data Transfer Config resources.
networkconnectivity.
-
networkconnectivity.multicloudDataTransferConfigs. create -
networkconnectivity.multicloudDataTransferConfigs. delete -
networkconnectivity.multicloudDataTransferConfigs. get -
networkconnectivity.multicloudDataTransferConfigs. list -
networkconnectivity.multicloudDataTransferConfigs. update
networkconnectivity.
-
networkconnectivity.multicloudDataTransferDestinations. create -
networkconnectivity.multicloudDataTransferDestinations. delete -
networkconnectivity.multicloudDataTransferDestinations. get -
networkconnectivity.multicloudDataTransferDestinations. list -
networkconnectivity.multicloudDataTransferDestinations. update
networkconnectivity.
-
networkconnectivity.multicloudDataTransferSupportedServices. get -
networkconnectivity.multicloudDataTransferSupportedServices. list
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Multicloud Data Transfer Config Viewer
( roles/
)
Read-only access to all Multicloud Data Transfer Config resources.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
-
networkconnectivity.multicloudDataTransferSupportedServices. get -
networkconnectivity.multicloudDataTransferSupportedServices. list
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Destination Admin
( roles/
)
Access to all Destination resources.
networkconnectivity.
-
networkconnectivity.multicloudDataTransferDestinations. create -
networkconnectivity.multicloudDataTransferDestinations. delete -
networkconnectivity.multicloudDataTransferDestinations. get -
networkconnectivity.multicloudDataTransferDestinations. list -
networkconnectivity.multicloudDataTransferDestinations. update
networkconnectivity.
-
networkconnectivity.multicloudDataTransferSupportedServices. get -
networkconnectivity.multicloudDataTransferSupportedServices. list
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Destination Viewer
( roles/
)
Read-only access to all Destination resources.
networkconnectivity.
networkconnectivity.
networkconnectivity.
-
networkconnectivity.multicloudDataTransferSupportedServices. get -
networkconnectivity.multicloudDataTransferSupportedServices. list
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Regional Endpoint Admin
( roles/
)
Full access to all Regional Endpoint resources.
networkconnectivity.
-
networkconnectivity.regionalEndpoints. create -
networkconnectivity.regionalEndpoints. delete -
networkconnectivity.regionalEndpoints. get -
networkconnectivity.regionalEndpoints. list
resourcemanager.projects.get
resourcemanager.projects.list
Regional Endpoint Viewer
( roles/
)
Read-only access to all Regional Endpoint resources.
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Service Class User
( roles/
)
Service Class User uses a ServiceClass
networkconnectivity.
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Service Automation Service Producer Admin
( roles/
)
Service Automation Producer Admin uses information from a consumer request to manage ServiceClasses and ServiceConnectionMaps
networkconnectivity.
networkconnectivity.
networkconnectivity.
-
networkconnectivity.serviceClasses. create -
networkconnectivity.serviceClasses. delete -
networkconnectivity.serviceClasses. get -
networkconnectivity.serviceClasses. list -
networkconnectivity.serviceClasses. update -
networkconnectivity.serviceClasses. use
networkconnectivity.
-
networkconnectivity.serviceConnectionMaps. create -
networkconnectivity.serviceConnectionMaps. delete -
networkconnectivity.serviceConnectionMaps. get -
networkconnectivity.serviceConnectionMaps. list -
networkconnectivity.serviceConnectionMaps. update
resourcemanager.projects.get
resourcemanager.projects.list
Spoke Admin
( roles/
)
Enables full access to spoke resources and read-only access to hub resources.
Lowest-level resources where you can grant this role:
- Project
networkconnectivity.
-
networkconnectivity.gatewayAdvertisedRoutes. create -
networkconnectivity.gatewayAdvertisedRoutes. delete -
networkconnectivity.gatewayAdvertisedRoutes. get -
networkconnectivity.gatewayAdvertisedRoutes. list -
networkconnectivity.gatewayAdvertisedRoutes. update
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.hubs.get
networkconnectivity.
networkconnectivity.hubs.list
networkconnectivity.
-
networkconnectivity.locations. get -
networkconnectivity.locations. list
networkconnectivity.
networkconnectivity.
networkconnectivity.spokes.*
-
networkconnectivity.spokes. create -
networkconnectivity.spokes. delete -
networkconnectivity.spokes.get -
networkconnectivity.spokes. getIamPolicy -
networkconnectivity.spokes. list -
networkconnectivity.spokes. setIamPolicy -
networkconnectivity.spokes. update
resourcemanager.projects.get
resourcemanager.projects.list
Transport Admin
( roles/
)
Enables full access to Transport resources
networkconnectivity.
-
networkconnectivity.locations. get -
networkconnectivity.locations. list
networkconnectivity.
-
networkconnectivity.operations. cancel -
networkconnectivity.operations. delete -
networkconnectivity.operations. get -
networkconnectivity.operations. list
networkconnectivity.
-
networkconnectivity.remoteTransportProfiles. get -
networkconnectivity.remoteTransportProfiles. list
networkconnectivity.
-
networkconnectivity.transports. create -
networkconnectivity.transports. delete -
networkconnectivity.transports. get -
networkconnectivity.transports. list -
networkconnectivity.transports. update
resourcemanager.projects.get
resourcemanager.projects.list
Transport Viewer
( roles/
)
Enables view access to Transport resources
networkconnectivity.
-
networkconnectivity.locations. get -
networkconnectivity.locations. list
networkconnectivity.
networkconnectivity.
networkconnectivity.
-
networkconnectivity.remoteTransportProfiles. get -
networkconnectivity.remoteTransportProfiles. list
networkconnectivity.
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Service agent roles
Service agent roles should only be granted to service agents .
Network Connectivity Service Agent
( roles/
)
Grants the Network Connectivity API authority to read some networking resources. It does not mutate these resources.
compute.addresses.create
compute.
compute.addresses.delete
compute.
compute.addresses.get
compute.addresses.setLabels
compute.addresses.use
compute.forwardingRules.create
compute.forwardingRules.delete
compute.forwardingRules.get
compute.
compute.
compute.
compute.
compute.
compute.instances.get
compute.
compute.networks.get
compute.networks.updatePolicy
compute.networks.use
compute.projects.get
compute.regionOperations.get
compute.routers.get
compute.subnetworks.create
compute.subnetworks.delete
compute.subnetworks.get
compute.
compute.subnetworks.list
compute.
compute.subnetworks.use
compute.vpnTunnels.get
dns.changes.create
dns.managedZoneOperations.*
-
dns.managedZoneOperations.get -
dns.managedZoneOperations.list
dns.managedZones.create
dns.managedZones.delete
dns.managedZones.get
dns.managedZones.list
dns.managedZones.update
dns.
dns.resourceRecordSets.*
-
dns.resourceRecordSets.create -
dns.resourceRecordSets.delete -
dns.resourceRecordSets.get -
dns.resourceRecordSets.list -
dns.resourceRecordSets.update
networkconnectivity.groups.use
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
networkconnectivity.
servicedirectory.
servicedirectory.
servicedirectory.
servicedirectory.
servicedirectory.
Network Connectivity Center permissions
networkconnectivity.
gatewayAdvertisedRoutes.
create
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
gatewayAdvertisedRoutes.
delete
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
gatewayAdvertisedRoutes.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
gatewayAdvertisedRoutes.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
gatewayAdvertisedRoutes.
update
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
groups.
acceptSpoke
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.
groups.
acceptSpokeUpdate
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.groups.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
networkconnectivity.
groups.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
networkconnectivity.
groups.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
networkconnectivity.
groups.
rejectSpoke
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.
groups.
rejectSpokeUpdate
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.
groups.
setIamPolicy
Owner
( roles/
)
Security Admin
( roles/
)
Network Administrator
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.groups.use
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Group Admin
( roles/
)
Group User
( roles/
)
Hub & Spoke Admin
( roles/
)
Service agent roles
- Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent
networkconnectivity.
hubRouteTables.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
Service agent roles
- Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent
networkconnectivity.
hubRouteTables.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
hubRouteTables.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
Service agent roles
- Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent
networkconnectivity.
hubRouteTables.
setIamPolicy
Owner
( roles/
)
Security Admin
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.
hubRoutes.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
Service agent roles
- Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent
networkconnectivity.
hubRoutes.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
hubRoutes.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
Service agent roles
- Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent
networkconnectivity.
hubRoutes.
setIamPolicy
Owner
( roles/
)
Security Admin
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.
hubs.
create
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.
hubs.
delete
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.hubs.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
hubs.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.hubs.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
hubs.
listSpokes
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
networkconnectivity.
hubs.
queryStatus
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
networkconnectivity.
hubs.
setIamPolicy
Owner
( roles/
)
Security Admin
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.
hubs.
update
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
networkconnectivity.
internalRanges.
create
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent - Oracle Database@Google Cloud Service Agent
(
roles/)oci.serviceAgent
networkconnectivity.
internalRanges.
delete
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent - Oracle Database@Google Cloud Service Agent
(
roles/)oci.serviceAgent
networkconnectivity.
internalRanges.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent - Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent - Oracle Database@Google Cloud Service Agent
(
roles/)oci.serviceAgent
networkconnectivity.
internalRanges.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
internalRanges.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent - Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent - Oracle Database@Google Cloud Service Agent
(
roles/)oci.serviceAgent - Service Networking Service Agent
(
roles/)servicenetworking.serviceAgent
networkconnectivity.
internalRanges.
setIamPolicy
Owner
( roles/
)
Compute Network Admin
( roles/
)
Security Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
internalRanges.
update
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Oracle Database@Google Cloud Service Agent
(
roles/)oci.serviceAgent
networkconnectivity.
locations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
Transport Admin
( roles/
)
Transport Viewer
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent
networkconnectivity.
locations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
Transport Admin
( roles/
)
Transport Viewer
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent
networkconnectivity.
multicloudDataTransferConfigs.
create
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
networkconnectivity.
multicloudDataTransferConfigs.
delete
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
networkconnectivity.
multicloudDataTransferConfigs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Support User
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Multicloud Data Transfer Config Viewer
( roles/
)
networkconnectivity.
multicloudDataTransferConfigs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Multicloud Data Transfer Config Viewer
( roles/
)
networkconnectivity.
multicloudDataTransferConfigs.
update
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
networkconnectivity.
multicloudDataTransferDestinations.
create
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Destination Admin
( roles/
)
networkconnectivity.
multicloudDataTransferDestinations.
delete
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Destination Admin
( roles/
)
networkconnectivity.
multicloudDataTransferDestinations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Support User
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Multicloud Data Transfer Config Viewer
( roles/
)
Destination Admin
( roles/
)
Destination Viewer
( roles/
)
networkconnectivity.
multicloudDataTransferDestinations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Multicloud Data Transfer Config Viewer
( roles/
)
Destination Admin
( roles/
)
Destination Viewer
( roles/
)
networkconnectivity.
multicloudDataTransferDestinations.
update
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Destination Admin
( roles/
)
networkconnectivity.
multicloudDataTransferSupportedServices.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Support User
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Multicloud Data Transfer Config Viewer
( roles/
)
Destination Admin
( roles/
)
Destination Viewer
( roles/
)
networkconnectivity.
multicloudDataTransferSupportedServices.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Multicloud Data Transfer Config Viewer
( roles/
)
Destination Admin
( roles/
)
Destination Viewer
( roles/
)
networkconnectivity.
operations.
cancel
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Transport Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
operations.
delete
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Transport Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
operations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Multicloud Data Transfer Config Viewer
( roles/
)
Destination Admin
( roles/
)
Destination Viewer
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Spoke Admin
( roles/
)
Transport Admin
( roles/
)
Transport Viewer
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent - Network Connectivity Service Agent
(
roles/)networkconnectivity.serviceAgent - Oracle Database@Google Cloud Service Agent
(
roles/)oci.serviceAgent
networkconnectivity.
operations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Multicloud Data Transfer Config Admin
( roles/
)
Multicloud Data Transfer Config Viewer
( roles/
)
Destination Admin
( roles/
)
Destination Viewer
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Spoke Admin
( roles/
)
Transport Admin
( roles/
)
Transport Viewer
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent - Oracle Database@Google Cloud Service Agent
(
roles/)oci.serviceAgent
networkconnectivity.
policyBasedRoutes.
create
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
policyBasedRoutes.
delete
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
policyBasedRoutes.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent
networkconnectivity.
policyBasedRoutes.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
policyBasedRoutes.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent
networkconnectivity.
policyBasedRoutes.
setIamPolicy
Owner
( roles/
)
Compute Network Admin
( roles/
)
Security Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
regionalEndpoints.
create
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Regional Endpoint Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
regionalEndpoints.
delete
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Regional Endpoint Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
regionalEndpoints.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Regional Endpoint Admin
( roles/
)
Regional Endpoint Viewer
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
regionalEndpoints.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Regional Endpoint Admin
( roles/
)
Regional Endpoint Viewer
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
remoteTransportProfiles.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Support User
( roles/
)
Transport Admin
( roles/
)
Transport Viewer
( roles/
)
networkconnectivity.
remoteTransportProfiles.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Transport Admin
( roles/
)
Transport Viewer
( roles/
)
networkconnectivity.
serviceClasses.
create
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceClasses.
delete
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceClasses.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Service Class User
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceClasses.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service Class User
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceClasses.
update
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceClasses.
use
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Class User
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Instance Group Manager Service Agent
(
roles/)compute.instanceGroupManagerServiceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionMaps.
create
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionMaps.
delete
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionMaps.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionMaps.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionMaps.
update
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Service Producer Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionPolicies.
create
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Consumer Network Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionPolicies.
delete
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Consumer Network Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionPolicies.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Service Automation Consumer Network Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionPolicies.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Cloud Memorystore Redis Admin
( roles/
)
Databases Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service Automation Consumer Network Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
serviceConnectionPolicies.
update
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Networkconnectivity Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Automation Consumer Network Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
networkconnectivity.
spokes.
create
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
spokes.
delete
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.spokes.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
spokes.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
spokes.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Group Admin
( roles/
)
Hub & Spoke Admin
( roles/
)
Hub & Spoke Viewer
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
spokes.
setIamPolicy
Owner
( roles/
)
Security Admin
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
spokes.
update
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Network Administrator
( roles/
)
Hub & Spoke Admin
( roles/
)
Spoke Admin
( roles/
)
networkconnectivity.
transports.
create
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Transport Admin
( roles/
)
networkconnectivity.
transports.
delete
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Transport Admin
( roles/
)
networkconnectivity.
transports.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Support User
( roles/
)
Transport Admin
( roles/
)
Transport Viewer
( roles/
)
networkconnectivity.
transports.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Networkconnectivity Editor
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Transport Admin
( roles/
)
Transport Viewer
( roles/
)
networkconnectivity.
transports.
update
Owner
( roles/
)
Editor
( roles/
)
Networkconnectivity Editor
( roles/
)
Transport Admin
( roles/
)

