This page lists the IAM roles and permissions for Web Security Scanner. To search through all roles and permissions, see the role and permission index .
Web Security Scanner roles
Web Security Scanner Editor
( roles/
)
Full access to all Web Security Scanner resources
Lowest-level resources where you can grant this role:
- Project
appengine.applications.get
cloudsecurityscanner.*
-
cloudsecurityscanner.
crawledurls. list -
cloudsecurityscanner.
results. get -
cloudsecurityscanner.
results. list -
cloudsecurityscanner.
scanruns. get -
cloudsecurityscanner.
scanruns. getSummary -
cloudsecurityscanner.
scanruns. list -
cloudsecurityscanner.
scanruns. stop -
cloudsecurityscanner.
scans. create -
cloudsecurityscanner.
scans. delete -
cloudsecurityscanner.scans.get
-
cloudsecurityscanner.
scans. list -
cloudsecurityscanner.scans.run
-
cloudsecurityscanner.
scans. update
compute.addresses.list
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.quotas.get
serviceusage.services.get
serviceusage.services.list
Web Security Scanner Runner
( roles/
)
Read access to Scan and ScanRun, plus the ability to start scans
Lowest-level resources where you can grant this role:
- Project
cloudsecurityscanner.
cloudsecurityscanner.
cloudsecurityscanner.
cloudsecurityscanner.
cloudsecurityscanner.scans.get
cloudsecurityscanner.
cloudsecurityscanner.scans.run
Web Security Scanner Viewer
( roles/
)
Read access to all Web Security Scanner resources
Lowest-level resources where you can grant this role:
- Project
cloudsecurityscanner.
cloudsecurityscanner.results.*
-
cloudsecurityscanner.
results. get -
cloudsecurityscanner.
results. list
cloudsecurityscanner.
cloudsecurityscanner.
cloudsecurityscanner.
cloudsecurityscanner.scans.get
cloudsecurityscanner.
serviceusage.quotas.get
serviceusage.services.get
serviceusage.services.list
Cloud Web Security Scanner Service Agent
( roles/
)
Gives the Cloud Web Security Scanner service account access to compute engine details and app engine details.
appengine.applications.get
cloudasset.assets.listResource
compute.addresses.list
compute.backendServices.get
compute.forwardingRules.get
compute.
compute.sslCertificates.list
compute.targetHttpProxies.get
compute.targetHttpsProxies.get
compute.urlMaps.get
Web Security Scanner permissions
cloudsecurityscanner.
crawledurls.
list
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Runner
( roles/
)
Web Security Scanner Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecurityscanner.
results.
get
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Viewer
( roles/
)
Security Auditor
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecurityscanner.
results.
list
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecurityscanner.
scanruns.
get
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Runner
( roles/
)
Web Security Scanner Viewer
( roles/
)
Security Auditor
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecurityscanner.
scanruns.
getSummary
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Viewer
( roles/
)
Security Auditor
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecurityscanner.
scanruns.
list
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Runner
( roles/
)
Web Security Scanner Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecurityscanner.
scanruns.
stop
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Runner
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
cloudsecurityscanner.
scans.
create
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
cloudsecurityscanner.
scans.
delete
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
cloudsecurityscanner.scans.get
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Runner
( roles/
)
Web Security Scanner Viewer
( roles/
)
Security Auditor
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/
)cloudsecuritycompliance.serviceAgent - Audit Manager Auditing Service Agent
(
roles/
)auditmanager.serviceAgent
cloudsecurityscanner.
scans.
list
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Runner
( roles/
)
Web Security Scanner Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/
)cloudsecuritycompliance.serviceAgent - Audit Manager Auditing Service Agent
(
roles/
)auditmanager.serviceAgent
cloudsecurityscanner.scans.run
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Web Security Scanner Runner
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)
cloudsecurityscanner.
scans.
update
Owner
( roles/
)
Editor
( roles/
)
Web Security Scanner Editor
( roles/
)
Security Center Admin
( roles/
)
Security Center Admin Editor
( roles/
)