This page lists the IAM roles and permissions for Access Context Manager. To search through all roles and permissions, see the role and permission index .
Access Context Manager roles
Cloud Access Binding Admin
( roles/
)
Create, edit, and change Cloud access bindings.
accesscontextmanager.
-
accesscontextmanager.
gcpUserAccessBindings. create -
accesscontextmanager.
gcpUserAccessBindings. delete -
accesscontextmanager.
gcpUserAccessBindings. get -
accesscontextmanager.
gcpUserAccessBindings. list -
accesscontextmanager.
gcpUserAccessBindings. update
Cloud Access Binding Reader
( roles/
)
Read access to Cloud access bindings.
accesscontextmanager.
accesscontextmanager.
Access Context Manager Admin
( roles/
)
Full access to policies, access levels, access zones and authorized orgs descs.
accesscontextmanager.
-
accesscontextmanager.
accessLevels. create -
accesscontextmanager.
accessLevels. delete -
accesscontextmanager.
accessLevels. get -
accesscontextmanager.
accessLevels. list -
accesscontextmanager.
accessLevels. replaceAll -
accesscontextmanager.
accessLevels. update
accesscontextmanager.
-
accesscontextmanager.
authorizedOrgsDescs. create -
accesscontextmanager.
authorizedOrgsDescs. delete -
accesscontextmanager.
authorizedOrgsDescs. get -
accesscontextmanager.
authorizedOrgsDescs. list -
accesscontextmanager.
authorizedOrgsDescs. update
accesscontextmanager.
-
accesscontextmanager.
policies. create -
accesscontextmanager.
policies. delete -
accesscontextmanager.
policies. get -
accesscontextmanager.
policies. getIamPolicy -
accesscontextmanager.
policies. list -
accesscontextmanager.
policies. setIamPolicy -
accesscontextmanager.
policies. update
accesscontextmanager.
-
accesscontextmanager.
servicePerimeters. commit -
accesscontextmanager.
servicePerimeters. create -
accesscontextmanager.
servicePerimeters. delete -
accesscontextmanager.
servicePerimeters. get -
accesscontextmanager.
servicePerimeters. list -
accesscontextmanager.
servicePerimeters. replaceAll -
accesscontextmanager.
servicePerimeters. update
cloudasset.
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Access Context Manager Editor
( roles/
)
Edit access to policies. Create, edit, and change access levels, access zones and authorized orgs descs.
accesscontextmanager.
-
accesscontextmanager.
accessLevels. create -
accesscontextmanager.
accessLevels. delete -
accesscontextmanager.
accessLevels. get -
accesscontextmanager.
accessLevels. list -
accesscontextmanager.
accessLevels. replaceAll -
accesscontextmanager.
accessLevels. update
accesscontextmanager.
-
accesscontextmanager.
authorizedOrgsDescs. create -
accesscontextmanager.
authorizedOrgsDescs. delete -
accesscontextmanager.
authorizedOrgsDescs. get -
accesscontextmanager.
authorizedOrgsDescs. list -
accesscontextmanager.
authorizedOrgsDescs. update
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
-
accesscontextmanager.
servicePerimeters. commit -
accesscontextmanager.
servicePerimeters. create -
accesscontextmanager.
servicePerimeters. delete -
accesscontextmanager.
servicePerimeters. get -
accesscontextmanager.
servicePerimeters. list -
accesscontextmanager.
servicePerimeters. replaceAll -
accesscontextmanager.
servicePerimeters. update
cloudasset.
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Access Context Manager Reader
( roles/
)
Read access to policies, access levels, access zones and authorized orgs descs.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
VPC Service Controls Troubleshooter Viewer
( roles/
)
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
logging.exclusions.get
logging.exclusions.list
logging.logEntries.list
logging.logMetrics.get
logging.logMetrics.list
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.list
logging.sinks.get
logging.sinks.list
logging.usage.get
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Access Context Manager permissions
accesscontextmanager.
accessLevels.
create
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
accesscontextmanager.
accessLevels.
delete
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
accesscontextmanager.
accessLevels.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
accesscontextmanager.
accessLevels.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
accesscontextmanager.
accessLevels.
replaceAll
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
accessLevels.
update
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
accesscontextmanager.
authorizedOrgsDescs.
create
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
authorizedOrgsDescs.
delete
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
authorizedOrgsDescs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
accesscontextmanager.
authorizedOrgsDescs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
accesscontextmanager.
authorizedOrgsDescs.
update
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
gcpUserAccessBindings.
create
Owner
( roles/
)
Editor
( roles/
)
Cloud Access Binding Admin
( roles/
)
accesscontextmanager.
gcpUserAccessBindings.
delete
Owner
( roles/
)
Editor
( roles/
)
Cloud Access Binding Admin
( roles/
)
accesscontextmanager.
gcpUserAccessBindings.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Access Binding Admin
( roles/
)
Cloud Access Binding Reader
( roles/
)
Support User
( roles/
)
Service agent roles
- Security Center Service Agent
(
roles/
)securitycenter.serviceAgent - Security Center Control Service Agent
(
roles/
)securitycenter.controlServiceAgent
accesscontextmanager.
gcpUserAccessBindings.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Access Binding Admin
( roles/
)
Cloud Access Binding Reader
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Security Center Service Agent
(
roles/
)securitycenter.serviceAgent - Security Center Control Service Agent
(
roles/
)securitycenter.controlServiceAgent
accesscontextmanager.
gcpUserAccessBindings.
update
Owner
( roles/
)
Editor
( roles/
)
Cloud Access Binding Admin
( roles/
)
accesscontextmanager.
policies.
create
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
policies.
delete
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
policies.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
accesscontextmanager.
policies.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
accesscontextmanager.
policies.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
accesscontextmanager.
policies.
setIamPolicy
Owner
( roles/
)
Access Context Manager Admin
( roles/
)
Security Admin
( roles/
)
accesscontextmanager.
policies.
update
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
servicePerimeters.
commit
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
servicePerimeters.
create
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
accesscontextmanager.
servicePerimeters.
delete
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
accesscontextmanager.
servicePerimeters.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
SLZ BQDW Blueprint Organization Level Remediator
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
accesscontextmanager.
servicePerimeters.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
SLZ BQDW Blueprint Organization Level Remediator
( roles/
)
accesscontextmanager.
servicePerimeters.
replaceAll
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
servicePerimeters.
update
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
SLZ BQDW Blueprint Organization Level Remediator
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent