This page lists the IAM roles and permissions for Service Management. To search through all roles and permissions, see the role and permission index .
Service Management roles
Service Management Administrator
( roles/
)
Full control of Google Service Management resources.
monitoring.timeSeries.list
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
serviceconsumermanagement.*
-
serviceconsumermanagement.consumers. get -
serviceconsumermanagement.quota. get -
serviceconsumermanagement.quota. update -
serviceconsumermanagement.tenancyu. addResource -
serviceconsumermanagement.tenancyu. create -
serviceconsumermanagement.tenancyu. delete -
serviceconsumermanagement.tenancyu. list -
serviceconsumermanagement.tenancyu. removeResource
servicemanagement.*
-
servicemanagement.services. bind -
servicemanagement.services. check -
servicemanagement.services. create -
servicemanagement.services. delete -
servicemanagement.services.get -
servicemanagement.services. getIamPolicy -
servicemanagement.services. list -
servicemanagement.services. quota -
servicemanagement.services. report -
servicemanagement.services. setIamPolicy -
servicemanagement.services. update
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.quotas.get
serviceusage.services.get
serviceusage.values.test
Service Checker
( roles/
)
Can check admission of a service during runtime.
servicemanagement.
Service Config Editor
( roles/
)
Access to update the service config and create rollouts.
servicemanagement.services.get
servicemanagement.
Quota Administrator Beta
( roles/
)
Provides access to administer service quotas.
Lowest-level resources where you can grant this role:
- Project
cloudquotas.*
-
cloudquotas.quotas.get -
cloudquotas.quotas.update
monitoring.alertPolicies.*
-
monitoring.alertPolicies. create -
monitoring.alertPolicies. createTagBinding -
monitoring.alertPolicies. delete -
monitoring.alertPolicies. deleteTagBinding -
monitoring.alertPolicies.get -
monitoring.alertPolicies.list -
monitoring.alertPolicies. listEffectiveTags -
monitoring.alertPolicies. listTagBindings -
monitoring.alertPolicies. update
monitoring.timeSeries.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.consumerpolicy.*
-
serviceusage.consumerpolicy. analyze -
serviceusage.consumerpolicy. get -
serviceusage.consumerpolicy. update
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.quotas.*
-
serviceusage.quotas.get -
serviceusage.quotas.update
serviceusage.services.disable
serviceusage.services.enable
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
Quota Viewer Beta
( roles/
)
Provides access to view service quotas.
Lowest-level resources where you can grant this role:
- Project
cloudquotas.quotas.get
monitoring.timeSeries.list
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.quotas.get
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
Service Reporter
( roles/
)
Can report usage of a service during runtime.
servicemanagement.
Service Consumer
( roles/
)
Can enable the service.
servicemanagement.
Service Controller
( roles/
)
Can check preconditions and report usage of a service during runtime.
Lowest-level resources where you can grant this role:
- Project
servicemanagement.
servicemanagement.services.get
servicemanagement.
servicemanagement.
Service Management permissions
servicemanagement.
services.
bind
Owner
( roles/
)
Editor
( roles/
)
Firebase SDK Provisioning Service Agent
( roles/
)
Service Management Administrator
( roles/
)
Service Consumer
( roles/
)
Service agent roles
- Firebase Service Management Service Agent
(
roles/)firebase.managementServiceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
servicemanagement.
services.
check
Owner
( roles/
)
Editor
( roles/
)
Service Management Administrator
( roles/
)
Service Checker
( roles/
)
Service Controller
( roles/
)
Service agent roles
- Cloud Endpoints Service Agent
(
roles/)endpoints.serviceAgent - Cloud API Gateway Service Agent
(
roles/)apigateway.serviceAgent
servicemanagement.
services.
create
Owner
( roles/
)
Editor
( roles/
)
Service Management Administrator
( roles/
)
Service agent roles
- Cloud API Gateway Management Service Agent
(
roles/)apigateway_management.serviceAgent
servicemanagement.
services.
delete
Owner
( roles/
)
Editor
( roles/
)
Service Management Administrator
( roles/
)
Service agent roles
- Cloud API Gateway Management Service Agent
(
roles/)apigateway_management.serviceAgent
servicemanagement.services.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
ApiGateway Admin
( roles/
)
ApiGateway Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service Management Administrator
( roles/
)
Service Config Editor
( roles/
)
Service Controller
( roles/
)
Service agent roles
- Cloud Endpoints Service Agent
(
roles/)endpoints.serviceAgent - Endpoints Portal Service Agent
(
roles/)endpointsportal.serviceAgent - Cloud API Gateway Management Service Agent
(
roles/)apigateway_management.serviceAgent
servicemanagement.
services.
getIamPolicy
Owner
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Service Management Administrator
( roles/
)
servicemanagement.
services.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service Management Administrator
( roles/
)
Service agent roles
- Endpoints Portal Service Agent
(
roles/)endpointsportal.serviceAgent - Cloud API Gateway Management Service Agent
(
roles/)apigateway_management.serviceAgent
servicemanagement.
services.
quota
Owner
( roles/
)
Editor
( roles/
)
Service Management Administrator
( roles/
)
Service Controller
( roles/
)
Service agent roles
- Cloud Endpoints Service Agent
(
roles/)endpoints.serviceAgent - Cloud API Gateway Service Agent
(
roles/)apigateway.serviceAgent
servicemanagement.
services.
report
Owner
( roles/
)
Editor
( roles/
)
Service Management Administrator
( roles/
)
Service Reporter
( roles/
)
Service Controller
( roles/
)
Service agent roles
- Vertex AI Telemetry Service Agent
(
roles/)aiplatform.telemetryServiceAgent - Cloud API Gateway Service Agent
(
roles/)apigateway.serviceAgent - Cloud Deploy Service Agent
(
roles/)clouddeploy.serviceAgent - Cloud Dataplex Service Agent
(
roles/)dataplex.serviceAgent - Cloud Endpoints Service Agent
(
roles/)endpoints.serviceAgent - Vertex AI Service Agent
(
roles/)aiplatform.serviceAgent
servicemanagement.
services.
setIamPolicy
Owner
( roles/
)
Security Admin
( roles/
)
Service Management Administrator
( roles/
)
servicemanagement.
services.
update
Owner
( roles/
)
Editor
( roles/
)
Service Management Administrator
( roles/
)
Service Config Editor
( roles/
)
Service agent roles
- Cloud API Gateway Management Service Agent
(
roles/)apigateway_management.serviceAgent

