This page lists the IAM roles and permissions for Cloud Logging. To search through all roles and permissions, see the role and permission index .
Cloud Logging roles
Logging Admin
( roles/
)
Provides all permissions necessary to use all features of Cloud Logging.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.copyLogEntries
logging.buckets.create
logging.
logging.buckets.delete
logging.
logging.buckets.get
logging.buckets.list
logging.
logging.
logging.buckets.undelete
logging.buckets.update
logging.exclusions.*
-
logging.exclusions.create
-
logging.exclusions.delete
-
logging.exclusions.get
-
logging.exclusions.list
-
logging.exclusions.update
logging.fields.access
logging.links.*
-
logging.links.create
-
logging.links.delete
-
logging.links.get
-
logging.links.list
logging.locations.*
-
logging.locations.get
-
logging.locations.list
logging.logEntries.*
-
logging.logEntries.create
-
logging.logEntries.download
-
logging.logEntries.list
-
logging.logEntries.route
logging.logMetrics.*
-
logging.logMetrics.create
-
logging.logMetrics.delete
-
logging.logMetrics.get
-
logging.logMetrics.list
-
logging.logMetrics.update
logging.logScopes.*
-
logging.logScopes.create
-
logging.logScopes.delete
-
logging.logScopes.get
-
logging.logScopes.list
-
logging.logScopes.update
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.*
-
logging.logs.delete
-
logging.logs.list
logging.notificationRules.*
-
logging.
notificationRules. create -
logging.
notificationRules. delete -
logging.notificationRules.get
-
logging.notificationRules.list
-
logging.
notificationRules. update
logging.operations.*
-
logging.operations.cancel
-
logging.operations.get
-
logging.operations.list
logging.privateLogEntries.list
logging.queries.*
-
logging.queries.deleteShared
-
logging.queries.getShared
-
logging.queries.listShared
-
logging.queries.share
-
logging.queries.updateShared
-
logging.queries.usePrivate
logging.settings.*
-
logging.settings.get
-
logging.settings.update
logging.sinks.*
-
logging.sinks.create
-
logging.sinks.delete
-
logging.sinks.get
-
logging.sinks.list
-
logging.sinks.update
logging.sqlAlerts.*
-
logging.sqlAlerts.create
-
logging.sqlAlerts.update
logging.usage.get
logging.views.*
-
logging.views.access
-
logging.views.create
-
logging.views.delete
-
logging.views.get
-
logging.views.getIamPolicy
-
logging.views.list
-
logging.views.listLogs
-
logging.views.listResourceKeys
-
logging.
views. listResourceValues -
logging.views.setIamPolicy
-
logging.views.update
observability.scopes.get
resourcemanager.projects.get
resourcemanager.projects.list
Logs Bucket Writer
( roles/
)
Ability to write logs to a log bucket.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.write
Logs Configuration Writer
( roles/
)
Provides permissions to read and write the configurations of logs-based metrics and sinks for exporting logs.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.create
logging.
logging.buckets.delete
logging.
logging.buckets.get
logging.buckets.list
logging.
logging.
logging.buckets.undelete
logging.buckets.update
logging.exclusions.*
-
logging.exclusions.create
-
logging.exclusions.delete
-
logging.exclusions.get
-
logging.exclusions.list
-
logging.exclusions.update
logging.links.*
-
logging.links.create
-
logging.links.delete
-
logging.links.get
-
logging.links.list
logging.locations.*
-
logging.locations.get
-
logging.locations.list
logging.logMetrics.*
-
logging.logMetrics.create
-
logging.logMetrics.delete
-
logging.logMetrics.get
-
logging.logMetrics.list
-
logging.logMetrics.update
logging.logScopes.*
-
logging.logScopes.create
-
logging.logScopes.delete
-
logging.logScopes.get
-
logging.logScopes.list
-
logging.logScopes.update
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.list
logging.notificationRules.*
-
logging.
notificationRules. create -
logging.
notificationRules. delete -
logging.notificationRules.get
-
logging.notificationRules.list
-
logging.
notificationRules. update
logging.operations.*
-
logging.operations.cancel
-
logging.operations.get
-
logging.operations.list
logging.settings.*
-
logging.settings.get
-
logging.settings.update
logging.sinks.*
-
logging.sinks.create
-
logging.sinks.delete
-
logging.sinks.get
-
logging.sinks.list
-
logging.sinks.update
logging.sqlAlerts.*
-
logging.sqlAlerts.create
-
logging.sqlAlerts.update
logging.views.create
logging.views.delete
logging.views.get
logging.views.getIamPolicy
logging.views.list
logging.views.update
observability.scopes.get
resourcemanager.projects.get
resourcemanager.projects.list
Log Field Accessor
( roles/
)
Ability to read restricted fields in a log bucket.
Lowest-level resources where you can grant this role:
- Project
logging.fields.access
Log Link Accessor
( roles/
)
Ability to see links for a bucket.
logging.links.get
logging.links.list
Logs Writer
( roles/
)
Provides the permissions to write log entries.
Lowest-level resources where you can grant this role:
- Project
logging.logEntries.create
logging.logEntries.route
Private Logs Viewer
( roles/
)
Provides permissions of the Logs Viewer role and in addition, provides read-only access to log entries in private logs.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.get
logging.buckets.list
logging.exclusions.get
logging.exclusions.list
logging.links.get
logging.links.list
logging.locations.*
-
logging.locations.get
-
logging.locations.list
logging.logEntries.list
logging.logMetrics.get
logging.logMetrics.list
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.list
logging.operations.get
logging.operations.list
logging.privateLogEntries.list
logging.queries.getShared
logging.queries.listShared
logging.queries.usePrivate
logging.sinks.get
logging.sinks.list
logging.usage.get
logging.views.access
logging.views.get
logging.views.list
observability.scopes.get
resourcemanager.projects.get
Cloud Logging Service Agent
( roles/
)
Grants a Cloud Logging Service Account the ability to create and link datasets.
bigquery.datasets.create
bigquery.datasets.get
bigquery.datasets.link
SQL Alert Writer Beta
( roles/
)
Ability to write SQL Alerts.
logging.sqlAlerts.*
-
logging.sqlAlerts.create
-
logging.sqlAlerts.update
Logs View Accessor
( roles/
)
Ability to read logs in a view.
Lowest-level resources where you can grant this role:
- Project
logging.logEntries.download
logging.views.access
logging.views.listLogs
logging.views.listResourceKeys
logging.
Logs Viewer
( roles/
)
Provides access to view logs.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.get
logging.buckets.list
logging.exclusions.get
logging.exclusions.list
logging.links.get
logging.links.list
logging.locations.*
-
logging.locations.get
-
logging.locations.list
logging.logEntries.list
logging.logMetrics.get
logging.logMetrics.list
logging.logScopes.get
logging.logScopes.list
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.list
logging.operations.get
logging.operations.list
logging.queries.getShared
logging.queries.listShared
logging.queries.usePrivate
logging.sinks.get
logging.sinks.list
logging.usage.get
logging.views.get
logging.views.list
observability.scopes.get
resourcemanager.projects.get
Cloud Logging permissions
logging.buckets.copyLogEntries
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
logging.buckets.create
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/
)cloudbuild.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Apigee Service Agent
(
roles/
)apigee.serviceAgent
logging.
buckets.
createTagBinding
Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Tag User
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.buckets.delete
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.
buckets.
deleteTagBinding
Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Tag User
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.buckets.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/
)cloudbuild.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Apigee Service Agent
(
roles/
)apigee.serviceAgent
logging.buckets.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Audit Manager Auditing Service Agent
(
roles/
)auditmanager.serviceAgent - Cloud Build Service Agent
(
roles/
)cloudbuild.serviceAgent - Cloud Security Compliance Service Agent
(
roles/
)cloudsecuritycompliance.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Apigee Service Agent
(
roles/
)apigee.serviceAgent
logging.
buckets.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.
buckets.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.buckets.undelete
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.buckets.update
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.buckets.write
Logs Bucket Writer
( roles/
)
Service agent roles
- Cloud Build Logging Service Agent
(
roles/
)cloudbuild.loggingServiceAgent
logging.exclusions.create
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.exclusions.delete
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.exclusions.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.exclusions.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.exclusions.update
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.fields.access
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Log Field Accessor
( roles/
)
logging.links.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.links.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.links.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Log Link Accessor
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.links.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Log Link Accessor
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Monitoring Service Agent
(
roles/
)monitoring.notificationServiceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.locations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.locations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logEntries.create
Owner
( roles/
)
Editor
( roles/
)
Cloud Build Service Account
( roles/
)
Cloud Deploy Runner
( roles/
)
Composer Worker
( roles/
)
Confidential Space Workload User
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
Kubernetes Engine Default Node Service Account
( roles/
)
Dataflow Worker
( roles/
)
Dataproc Hub Agent
( roles/
)
Dataproc Worker
( roles/
)
Developer Connect Insights Config Agent
( roles/
)
Anthos Multi-cloud Telemetry Writer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Writer
( roles/
)
Cloud Run Builder
( roles/
)
Storage Transfer Agent
( roles/
)
Service agent roles
- Vertex AI Extension Custom Code Service Agent
(
roles/
)aiplatform.extensionCustomCodeServiceAgent - Vertex AI Extension Service Agent
(
roles/
)aiplatform.extensionServiceAgent - Vertex AI Notebook Service Agent
(
roles/
)aiplatform.notebookServiceAgent - Vertex AI RAG Data Service Agent
(
roles/
)aiplatform.ragServiceAgent - Vertex AI Reasoning Engine Service Agent
(
roles/
)aiplatform.reasoningEngineServiceAgent - Vertex AI Service Agent
(
roles/
)aiplatform.serviceAgent - Vertex AI Telemetry Service Agent
(
roles/
)aiplatform.telemetryServiceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - App Engine flexible environment Service Agent
(
roles/
)appengineflex.serviceAgent - Recommendations AI Service Agent
(
roles/
)automlrecommendations.serviceAgent - BigQuery Connection Service Agent
(
roles/
)bigqueryconnection.serviceAgent - BigQuery Data Transfer Service Agent
(
roles/
)bigquerydatatransfer.serviceAgent - Gemini for Google Cloud Service Agent
(
roles/
)cloudaicompanion.serviceAgent - Cloud Build Service Agent
(
roles/
)cloudbuild.serviceAgent - Infrastructure Manager Service Agent
(
roles/
)cloudconfig.serviceAgent - Cloud Deploy Service Agent
(
roles/
)clouddeploy.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent - Cloud IoT Core Service Agent
(
roles/
)cloudiot.serviceAgent - Cloud Scheduler Service Agent
(
roles/
)cloudscheduler.serviceAgent - Cloud Tasks Service Agent
(
roles/
)cloudtasks.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Compute Engine Service Agent
(
roles/
)compute.serviceAgent - Kubernetes Engine Default Node Service Agent
(
roles/
)container.defaultNodeServiceAgent - [Deprecated] Kubernetes Engine Node Service Agent
(
roles/
)container.nodeServiceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/
)datafusion.serviceAgent - Cloud Dataplex Service Agent
(
roles/
)dataplex.serviceAgent - Dataproc Resource Manager Node Service Agent
(
roles/
)dataprocrm.nodeServiceAgent - Dialogflow Service Agent
(
roles/
)dialogflow.serviceAgent - Discovery Engine Service Agent
(
roles/
)discoveryengine.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Firebase Machine Learning Service Agent
(
roles/
)firebaseml.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/
)gkemulticloud.containerServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Mesh Data Plane Service Agent
(
roles/
)meshdataplane.serviceAgent - AI Platform Service Agent
(
roles/
)ml.serviceAgent - RMA Service Agent
(
roles/
)rapidmigrationassessment.serviceAgent - Retail Service Agent
(
roles/
)retail.serviceAgent - Cloud Spanner API Service Agent
(
roles/
)spanner.serviceAgent - Cloud Vision AI Service Agent
(
roles/
)visionai.serviceAgent - Serverless VPC Access Service Agent
(
roles/
)vpcaccess.serviceAgent - Vertex AI Custom Code Service Agent
(
roles/
)aiplatform.customCodeServiceAgent
logging.logEntries.download
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs View Accessor
( roles/
)
logging.logEntries.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Billing Account Administrator
( roles/
)
Cloud Build Service Account
( roles/
)
Cloud Hub Operator
( roles/
)
Composer Worker
( roles/
)
Dataproc Hub Agent
( roles/
)
Firebase Admin
( roles/
)
Firebase Develop Admin
( roles/
)
Firebase Develop Viewer
( roles/
)
Firebase Viewer
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/
)cloudbuild.serviceAgent - Secured Landing Zone Service Agent
(
roles/
)securedlandingzone.serviceAgent - Security Center Control Service Agent
(
roles/
)securitycenter.controlServiceAgent - Security Center Service Agent
(
roles/
)securitycenter.serviceAgent - Vertex AI Telemetry Service Agent
(
roles/
)aiplatform.telemetryServiceAgent
logging.logEntries.route
Owner
( roles/
)
Editor
( roles/
)
Composer Worker
( roles/
)
Dataflow Worker
( roles/
)
Dataproc Hub Agent
( roles/
)
Dataproc Worker
( roles/
)
Anthos Multi-cloud Telemetry Writer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Writer
( roles/
)
Service agent roles
- Vertex AI Extension Custom Code Service Agent
(
roles/
)aiplatform.extensionCustomCodeServiceAgent - Vertex AI Extension Service Agent
(
roles/
)aiplatform.extensionServiceAgent - Vertex AI Notebook Service Agent
(
roles/
)aiplatform.notebookServiceAgent - Vertex AI RAG Data Service Agent
(
roles/
)aiplatform.ragServiceAgent - Vertex AI Reasoning Engine Service Agent
(
roles/
)aiplatform.reasoningEngineServiceAgent - Vertex AI Service Agent
(
roles/
)aiplatform.serviceAgent - Vertex AI Telemetry Service Agent
(
roles/
)aiplatform.telemetryServiceAgent - Recommendations AI Service Agent
(
roles/
)automlrecommendations.serviceAgent - BigQuery Connection Service Agent
(
roles/
)bigqueryconnection.serviceAgent - BigQuery Data Transfer Service Agent
(
roles/
)bigquerydatatransfer.serviceAgent - Gemini for Google Cloud Service Agent
(
roles/
)cloudaicompanion.serviceAgent - Infrastructure Manager Service Agent
(
roles/
)cloudconfig.serviceAgent - Cloud IoT Core Service Agent
(
roles/
)cloudiot.serviceAgent - Cloud Scheduler Service Agent
(
roles/
)cloudscheduler.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Dataplex Service Agent
(
roles/
)dataplex.serviceAgent - Dataproc Resource Manager Node Service Agent
(
roles/
)dataprocrm.nodeServiceAgent - Dialogflow Service Agent
(
roles/
)dialogflow.serviceAgent - Firebase Machine Learning Service Agent
(
roles/
)firebaseml.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/
)gkemulticloud.containerServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Mesh Data Plane Service Agent
(
roles/
)meshdataplane.serviceAgent - AI Platform Service Agent
(
roles/
)ml.serviceAgent - Retail Service Agent
(
roles/
)retail.serviceAgent - Vertex AI Custom Code Service Agent
(
roles/
)aiplatform.customCodeServiceAgent
logging.logMetrics.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Serverless VPC Access Service Agent
(
roles/
)vpcaccess.serviceAgent - App Engine flexible environment Service Agent
(
roles/
)appengineflex.serviceAgent
logging.logMetrics.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Serverless VPC Access Service Agent
(
roles/
)vpcaccess.serviceAgent - App Engine flexible environment Service Agent
(
roles/
)appengineflex.serviceAgent
logging.logMetrics.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Serverless VPC Access Service Agent
(
roles/
)vpcaccess.serviceAgent - App Engine flexible environment Service Agent
(
roles/
)appengineflex.serviceAgent
logging.logMetrics.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logMetrics.update
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Serverless VPC Access Service Agent
(
roles/
)vpcaccess.serviceAgent - App Engine flexible environment Service Agent
(
roles/
)appengineflex.serviceAgent
logging.logScopes.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Observability Scopes Editor
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logScopes.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Observability Scopes Editor
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logScopes.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Logs Viewer
( roles/
)
Observability Scopes Editor
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logScopes.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Logs Viewer
( roles/
)
Observability Scopes Editor
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logScopes.update
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Observability Scopes Editor
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logServiceIndexes.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Billing Account Administrator
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logServices.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Billing Account Administrator
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.logs.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
logging.logs.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Billing Account Administrator
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.
notificationRules.
create
Owner
( roles/
)
Editor
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.
notificationRules.
delete
Owner
( roles/
)
Editor
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.notificationRules.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Error Reporting Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.notificationRules.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Error Reporting Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.
notificationRules.
update
Owner
( roles/
)
Editor
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.operations.cancel
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.operations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.operations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.privateLogEntries.list
Owner
( roles/
)
Billing Account Administrator
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
logging.queries.deleteShared
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
logging.queries.getShared
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Observability Analytics User
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
logging.queries.listShared
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Observability Analytics User
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
logging.queries.share
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
logging.queries.updateShared
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
logging.queries.usePrivate
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Observability Analytics User
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
logging.settings.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.settings.update
Owner
( roles/
)
Editor
( roles/
)
Assured Workloads Administrator
( roles/
)
Assured Workloads Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Security Compliance Service Agent
(
roles/
)cloudsecuritycompliance.serviceAgent
logging.sinks.create
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KubeRun Events Control Plane Service Agent
(
roles/
)kuberun.eventsControlPlaneServiceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.sinks.delete
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KubeRun Events Control Plane Service Agent
(
roles/
)kuberun.eventsControlPlaneServiceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.sinks.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KubeRun Events Control Plane Service Agent
(
roles/
)kuberun.eventsControlPlaneServiceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.sinks.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.sinks.update
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
logging.sqlAlerts.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
SQL Alert Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.sqlAlerts.update
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
SQL Alert Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.usage.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
logging.views.access
Owner
( roles/
)
Cloud Build Service Account
( roles/
)
Composer Worker
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs View Accessor
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/
)cloudbuild.serviceAgent
logging.views.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Apigee Service Agent
(
roles/
)apigee.serviceAgent
logging.views.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.views.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Apigee Service Agent
(
roles/
)apigee.serviceAgent
logging.views.getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent
logging.views.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Apigee Service Agent
(
roles/
)apigee.serviceAgent
logging.views.listLogs
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs View Accessor
( roles/
)
logging.views.listResourceKeys
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs View Accessor
( roles/
)
logging.
views.
listResourceValues
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs View Accessor
( roles/
)
logging.views.setIamPolicy
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Logging Admin
( roles/
)
logging.views.update
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent