This page lists the IAM roles and permissions for Access Context Manager. To search through all roles and permissions, see the role and permission index .
Access Context Manager roles
Cloud Access Binding Admin
( roles/
)
Create, edit, and change Cloud access bindings.
accesscontextmanager.
-
accesscontextmanager.gcpUserAccessBindings. create -
accesscontextmanager.gcpUserAccessBindings. delete -
accesscontextmanager.gcpUserAccessBindings. get -
accesscontextmanager.gcpUserAccessBindings. list -
accesscontextmanager.gcpUserAccessBindings. update
Cloud Access Binding Reader
( roles/
)
Read access to Cloud access bindings.
accesscontextmanager.
accesscontextmanager.
Access Context Manager Admin
( roles/
)
Full access to policies, access levels, access zones and authorized orgs descs.
accesscontextmanager.
-
accesscontextmanager.accessLevels. create -
accesscontextmanager.accessLevels. delete -
accesscontextmanager.accessLevels. get -
accesscontextmanager.accessLevels. list -
accesscontextmanager.accessLevels. replaceAll -
accesscontextmanager.accessLevels. update
accesscontextmanager.
-
accesscontextmanager.authorizedOrgsDescs. create -
accesscontextmanager.authorizedOrgsDescs. delete -
accesscontextmanager.authorizedOrgsDescs. get -
accesscontextmanager.authorizedOrgsDescs. list -
accesscontextmanager.authorizedOrgsDescs. update
accesscontextmanager.
-
accesscontextmanager.policies. create -
accesscontextmanager.policies. delete -
accesscontextmanager.policies. get -
accesscontextmanager.policies. getIamPolicy -
accesscontextmanager.policies. list -
accesscontextmanager.policies. setIamPolicy -
accesscontextmanager.policies. update
accesscontextmanager.
-
accesscontextmanager.servicePerimeters. commit -
accesscontextmanager.servicePerimeters. create -
accesscontextmanager.servicePerimeters. delete -
accesscontextmanager.servicePerimeters. get -
accesscontextmanager.servicePerimeters. list -
accesscontextmanager.servicePerimeters. replaceAll -
accesscontextmanager.servicePerimeters. update
cloudasset.
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Access Context Manager Editor
( roles/
)
Edit access to policies. Create, edit, and change access levels, access zones and authorized orgs descs.
accesscontextmanager.
-
accesscontextmanager.accessLevels. create -
accesscontextmanager.accessLevels. delete -
accesscontextmanager.accessLevels. get -
accesscontextmanager.accessLevels. list -
accesscontextmanager.accessLevels. replaceAll -
accesscontextmanager.accessLevels. update
accesscontextmanager.
-
accesscontextmanager.authorizedOrgsDescs. create -
accesscontextmanager.authorizedOrgsDescs. delete -
accesscontextmanager.authorizedOrgsDescs. get -
accesscontextmanager.authorizedOrgsDescs. list -
accesscontextmanager.authorizedOrgsDescs. update
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
-
accesscontextmanager.servicePerimeters. commit -
accesscontextmanager.servicePerimeters. create -
accesscontextmanager.servicePerimeters. delete -
accesscontextmanager.servicePerimeters. get -
accesscontextmanager.servicePerimeters. list -
accesscontextmanager.servicePerimeters. replaceAll -
accesscontextmanager.servicePerimeters. update
cloudasset.
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Access Context Manager Reader
( roles/
)
Read access to policies, access levels, access zones and authorized orgs descs.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
VPC Service Controls Troubleshooter Viewer
( roles/
)
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
accesscontextmanager.
logging.exclusions.get
logging.exclusions.list
logging.logEntries.list
logging.logMetrics.get
logging.logMetrics.list
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.list
logging.sinks.get
logging.sinks.list
logging.usage.get
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Access Context Manager permissions
accesscontextmanager.
accessLevels.
create
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
accesscontextmanager.
accessLevels.
delete
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
accesscontextmanager.
accessLevels.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
accesscontextmanager.
accessLevels.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
accesscontextmanager.
accessLevels.
replaceAll
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
accessLevels.
update
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
accesscontextmanager.
authorizedOrgsDescs.
create
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
authorizedOrgsDescs.
delete
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
authorizedOrgsDescs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
accesscontextmanager.
authorizedOrgsDescs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
accesscontextmanager.
authorizedOrgsDescs.
update
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
gcpUserAccessBindings.
create
Owner
( roles/
)
Editor
( roles/
)
Cloud Access Binding Admin
( roles/
)
accesscontextmanager.
gcpUserAccessBindings.
delete
Owner
( roles/
)
Editor
( roles/
)
Cloud Access Binding Admin
( roles/
)
accesscontextmanager.
gcpUserAccessBindings.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Access Binding Admin
( roles/
)
Cloud Access Binding Reader
( roles/
)
Support User
( roles/
)
Service agent roles
- Security Center Service Agent
(
roles/)securitycenter.serviceAgent - Security Center Control Service Agent
(
roles/)securitycenter.controlServiceAgent
accesscontextmanager.
gcpUserAccessBindings.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Access Binding Admin
( roles/
)
Cloud Access Binding Reader
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Security Center Service Agent
(
roles/)securitycenter.serviceAgent - Security Center Control Service Agent
(
roles/)securitycenter.controlServiceAgent
accesscontextmanager.
gcpUserAccessBindings.
update
Owner
( roles/
)
Editor
( roles/
)
Cloud Access Binding Admin
( roles/
)
accesscontextmanager.
policies.
create
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
policies.
delete
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
policies.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
accesscontextmanager.
policies.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
accesscontextmanager.
policies.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
accesscontextmanager.
policies.
setIamPolicy
Owner
( roles/
)
Access Context Manager Admin
( roles/
)
Security Admin
( roles/
)
accesscontextmanager.
policies.
update
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
servicePerimeters.
commit
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
servicePerimeters.
create
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
accesscontextmanager.
servicePerimeters.
delete
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
accesscontextmanager.
servicePerimeters.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
SLZ BQDW Blueprint Organization Level Remediator
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
accesscontextmanager.
servicePerimeters.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
Access Context Manager Reader
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
SLZ BQDW Blueprint Organization Level Remediator
( roles/
)
accesscontextmanager.
servicePerimeters.
replaceAll
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
accesscontextmanager.
servicePerimeters.
update
Owner
( roles/
)
Editor
( roles/
)
Access Context Manager Admin
( roles/
)
Access Context Manager Editor
( roles/
)
SLZ BQDW Blueprint Organization Level Remediator
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent

