This page lists the IAM roles and permissions for Network Management API. To search through all roles and permissions, see the role and permission index .
Network Management API roles
Network Management Admin
( roles/
)
Full access to Network Management resources.
Lowest-level resources where you can grant this role:
- Project
networkmanagement.*
-
networkmanagement.connectivitytests. create -
networkmanagement.connectivitytests. createTagBinding -
networkmanagement.connectivitytests. delete -
networkmanagement.connectivitytests. deleteTagBinding -
networkmanagement.connectivitytests. get -
networkmanagement.connectivitytests. getIamPolicy -
networkmanagement.connectivitytests. list -
networkmanagement.connectivitytests. listEffectiveTags -
networkmanagement.connectivitytests. listTagBindings -
networkmanagement.connectivitytests. rerun -
networkmanagement.connectivitytests. setIamPolicy -
networkmanagement.connectivitytests. update -
networkmanagement.locations. get -
networkmanagement.locations. list -
networkmanagement.monitoringpoints. downloadConfig -
networkmanagement.monitoringpoints. get -
networkmanagement.monitoringpoints. list -
networkmanagement.networkpaths. get -
networkmanagement.networkpaths. list -
networkmanagement.operations. cancel -
networkmanagement.operations. delete -
networkmanagement.operations. get -
networkmanagement.operations. list -
networkmanagement.providers. create -
networkmanagement.providers. delete -
networkmanagement.providers. generateProviderAccessToken -
networkmanagement.providers. get -
networkmanagement.providers. list -
networkmanagement.topologygraphs. read -
networkmanagement.vpcflowlogsconfigs. create -
networkmanagement.vpcflowlogsconfigs. delete -
networkmanagement.vpcflowlogsconfigs. get -
networkmanagement.vpcflowlogsconfigs. list -
networkmanagement.vpcflowlogsconfigs. update -
networkmanagement.webpaths.get -
networkmanagement.webpaths. list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Networkmanagement Editor
( roles/
)
Editor role for networkmanagement
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.locations.*
-
networkmanagement.locations. get -
networkmanagement.locations. list
networkmanagement.
networkmanagement.
networkmanagement.
-
networkmanagement.networkpaths. get -
networkmanagement.networkpaths. list
networkmanagement.operations.*
-
networkmanagement.operations. cancel -
networkmanagement.operations. delete -
networkmanagement.operations. get -
networkmanagement.operations. list
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
-
networkmanagement.vpcflowlogsconfigs. create -
networkmanagement.vpcflowlogsconfigs. delete -
networkmanagement.vpcflowlogsconfigs. get -
networkmanagement.vpcflowlogsconfigs. list -
networkmanagement.vpcflowlogsconfigs. update
networkmanagement.webpaths.*
-
networkmanagement.webpaths.get -
networkmanagement.webpaths. list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Network Management Viewer
( roles/
)
Read-only access to Network Management resources.
Lowest-level resources where you can grant this role:
- Project
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.locations.*
-
networkmanagement.locations. get -
networkmanagement.locations. list
networkmanagement.
networkmanagement.
networkmanagement.
-
networkmanagement.networkpaths. get -
networkmanagement.networkpaths. list
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.webpaths.*
-
networkmanagement.webpaths.get -
networkmanagement.webpaths. list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Cloud Network Insights Admin Beta
( roles/
)
Full access to Cloud Network Insights resources.
networkmanagement.locations.*
-
networkmanagement.locations. get -
networkmanagement.locations. list
networkmanagement.
-
networkmanagement.monitoringpoints. downloadConfig -
networkmanagement.monitoringpoints. get -
networkmanagement.monitoringpoints. list
networkmanagement.
-
networkmanagement.networkpaths. get -
networkmanagement.networkpaths. list
networkmanagement.
networkmanagement.
networkmanagement.providers.*
-
networkmanagement.providers. create -
networkmanagement.providers. delete -
networkmanagement.providers. generateProviderAccessToken -
networkmanagement.providers. get -
networkmanagement.providers. list
networkmanagement.webpaths.*
-
networkmanagement.webpaths.get -
networkmanagement.webpaths. list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Cloud Network Insights Editor Beta
( roles/
)
Editor access to Cloud Network Insights resources.
networkmanagement.locations.*
-
networkmanagement.locations. get -
networkmanagement.locations. list
networkmanagement.
-
networkmanagement.monitoringpoints. downloadConfig -
networkmanagement.monitoringpoints. get -
networkmanagement.monitoringpoints. list
networkmanagement.
-
networkmanagement.networkpaths. get -
networkmanagement.networkpaths. list
networkmanagement.
networkmanagement.
networkmanagement.providers.*
-
networkmanagement.providers. create -
networkmanagement.providers. delete -
networkmanagement.providers. generateProviderAccessToken -
networkmanagement.providers. get -
networkmanagement.providers. list
networkmanagement.webpaths.*
-
networkmanagement.webpaths.get -
networkmanagement.webpaths. list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Cloud Network Insights Viewer Beta
( roles/
)
Read-only access to Cloud Network Insights resources.
networkmanagement.
networkmanagement.
networkmanagement.
-
networkmanagement.networkpaths. get -
networkmanagement.networkpaths. list
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.webpaths.*
-
networkmanagement.webpaths.get -
networkmanagement.webpaths. list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Service agent roles
Service agent roles should only be granted to service agents .
| Role | Permissions |
|---|---|
GCP Network Management Service Agent( Grants the GCP Network Management API the authority to complete analysis based on network configurations from Compute Engine and Container Engine. |
|
Network Management API permissions
networkmanagement.
connectivitytests.
create
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
connectivitytests.
createTagBinding
Owner
( roles/
)
Network Management Admin
( roles/
)
Tag User
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
connectivitytests.
delete
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
connectivitytests.
deleteTagBinding
Owner
( roles/
)
Network Management Admin
( roles/
)
Tag User
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
connectivitytests.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent
networkmanagement.
connectivitytests.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
networkmanagement.
connectivitytests.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - Database Migration Service Agent
(
roles/)datamigration.serviceAgent - External Exposure Service Agent
(
roles/)externalexposure.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent
networkmanagement.
connectivitytests.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
networkmanagement.
connectivitytests.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
networkmanagement.
connectivitytests.
rerun
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
connectivitytests.
setIamPolicy
Owner
( roles/
)
Security Admin
( roles/
)
Network Management Admin
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
connectivitytests.
update
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
locations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
networkmanagement.
locations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
networkmanagement.
monitoringpoints.
downloadConfig
Owner
( roles/
)
Network Management Admin
( roles/
)
Network Administrator
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
networkmanagement.
monitoringpoints.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)
networkmanagement.
monitoringpoints.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)
networkmanagement.
networkpaths.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)
networkmanagement.
networkpaths.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)
networkmanagement.
operations.
cancel
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
operations.
delete
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
operations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
networkmanagement.
operations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
networkmanagement.
providers.
create
Owner
( roles/
)
Network Management Admin
( roles/
)
Network Administrator
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
networkmanagement.
providers.
delete
Owner
( roles/
)
Network Management Admin
( roles/
)
Network Administrator
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
networkmanagement.
providers.
generateProviderAccessToken
Owner
( roles/
)
Network Management Admin
( roles/
)
Network Administrator
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)
networkmanagement.
providers.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)
networkmanagement.
providers.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)
networkmanagement.
topologygraphs.
read
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
create
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
delete
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
update
Owner
( roles/
)
Editor
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Administrator
( roles/
)
networkmanagement.webpaths.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)
networkmanagement.
webpaths.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Network Management Admin
( roles/
)
Networkmanagement Editor
( roles/
)
Network Management Viewer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Cloud Network Insights Admin
( roles/
)
Cloud Network Insights Editor
( roles/
)
Cloud Network Insights Viewer
( roles/
)

