This page lists the IAM roles and permissions for Service Catalog. To search through all roles and permissions, see the role and permission index .
Service Catalog roles
Catalog Consumer Beta
( roles/
)
Can browse catalogs in the target resource context.
cloudprivatecatalog.
resourcemanager.projects.get
resourcemanager.projects.list
Catalog Admin Beta
( roles/
)
Can manage catalog and view its associations.
cloudprivatecatalog.
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
associations. create -
cloudprivatecatalogproducer.
associations. delete -
cloudprivatecatalogproducer.
associations. get -
cloudprivatecatalogproducer.
associations. list
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
catalogAssociations. create -
cloudprivatecatalogproducer.
catalogAssociations. delete -
cloudprivatecatalogproducer.
catalogAssociations. get -
cloudprivatecatalogproducer.
catalogAssociations. list
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
catalogs. create -
cloudprivatecatalogproducer.
catalogs. delete -
cloudprivatecatalogproducer.
catalogs. get -
cloudprivatecatalogproducer.
catalogs. getIamPolicy -
cloudprivatecatalogproducer.
catalogs. list -
cloudprivatecatalogproducer.
catalogs. setIamPolicy -
cloudprivatecatalogproducer.
catalogs. undelete -
cloudprivatecatalogproducer.
catalogs. update
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
producerCatalogs. attachProduct -
cloudprivatecatalogproducer.
producerCatalogs. create -
cloudprivatecatalogproducer.
producerCatalogs. delete -
cloudprivatecatalogproducer.
producerCatalogs. detachProduct -
cloudprivatecatalogproducer.
producerCatalogs. get -
cloudprivatecatalogproducer.
producerCatalogs. getIamPolicy -
cloudprivatecatalogproducer.
producerCatalogs. list -
cloudprivatecatalogproducer.
producerCatalogs. setIamPolicy -
cloudprivatecatalogproducer.
producerCatalogs. update
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
products. create -
cloudprivatecatalogproducer.
products. delete -
cloudprivatecatalogproducer.
products. get -
cloudprivatecatalogproducer.
products. getIamPolicy -
cloudprivatecatalogproducer.
products. list -
cloudprivatecatalogproducer.
products. setIamPolicy -
cloudprivatecatalogproducer.
products. update
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
targets. associate -
cloudprivatecatalogproducer.
targets. unassociate
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Catalog Manager Beta
( roles/
)
Can manage associations between a catalog and a target resource.
cloudprivatecatalog.
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
associations. create -
cloudprivatecatalogproducer.
associations. delete -
cloudprivatecatalogproducer.
associations. get -
cloudprivatecatalogproducer.
associations. list
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
catalogAssociations. create -
cloudprivatecatalogproducer.
catalogAssociations. delete -
cloudprivatecatalogproducer.
catalogAssociations. get -
cloudprivatecatalogproducer.
catalogAssociations. list
cloudprivatecatalogproducer.
cloudprivatecatalogproducer.
cloudprivatecatalogproducer.
cloudprivatecatalogproducer.
cloudprivatecatalogproducer.
-
cloudprivatecatalogproducer.
targets. associate -
cloudprivatecatalogproducer.
targets. unassociate
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Catalog Org Admin Beta
( roles/
)
Can manage catalog org settings.
cloudprivatecatalog.
cloudprivatecatalogproducer.*
-
cloudprivatecatalogproducer.
associations. create -
cloudprivatecatalogproducer.
associations. delete -
cloudprivatecatalogproducer.
associations. get -
cloudprivatecatalogproducer.
associations. list -
cloudprivatecatalogproducer.
catalogAssociations. create -
cloudprivatecatalogproducer.
catalogAssociations. delete -
cloudprivatecatalogproducer.
catalogAssociations. get -
cloudprivatecatalogproducer.
catalogAssociations. list -
cloudprivatecatalogproducer.
catalogs. create -
cloudprivatecatalogproducer.
catalogs. delete -
cloudprivatecatalogproducer.
catalogs. get -
cloudprivatecatalogproducer.
catalogs. getIamPolicy -
cloudprivatecatalogproducer.
catalogs. list -
cloudprivatecatalogproducer.
catalogs. setIamPolicy -
cloudprivatecatalogproducer.
catalogs. undelete -
cloudprivatecatalogproducer.
catalogs. update -
cloudprivatecatalogproducer.
producerCatalogs. attachProduct -
cloudprivatecatalogproducer.
producerCatalogs. create -
cloudprivatecatalogproducer.
producerCatalogs. delete -
cloudprivatecatalogproducer.
producerCatalogs. detachProduct -
cloudprivatecatalogproducer.
producerCatalogs. get -
cloudprivatecatalogproducer.
producerCatalogs. getIamPolicy -
cloudprivatecatalogproducer.
producerCatalogs. list -
cloudprivatecatalogproducer.
producerCatalogs. setIamPolicy -
cloudprivatecatalogproducer.
producerCatalogs. update -
cloudprivatecatalogproducer.
products. create -
cloudprivatecatalogproducer.
products. delete -
cloudprivatecatalogproducer.
products. get -
cloudprivatecatalogproducer.
products. getIamPolicy -
cloudprivatecatalogproducer.
products. list -
cloudprivatecatalogproducer.
products. setIamPolicy -
cloudprivatecatalogproducer.
products. update -
cloudprivatecatalogproducer.
settings. get -
cloudprivatecatalogproducer.
settings. update -
cloudprivatecatalogproducer.
targets. associate -
cloudprivatecatalogproducer.
targets. unassociate
commerceorggovernance.
-
commerceorggovernance.
organizationSettings. get -
commerceorggovernance.
organizationSettings. update
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Service Catalog permissions
cloudprivatecatalog.
targets.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Consumer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
cloudprivatecatalogproducer.
associations.
create
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
associations.
delete
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
associations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
associations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
catalogAssociations.
create
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
catalogAssociations.
delete
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
catalogAssociations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
catalogAssociations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
catalogs.
create
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
catalogs.
delete
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
catalogs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
catalogs.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
catalogs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
catalogs.
setIamPolicy
Owner
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
cloudprivatecatalogproducer.
catalogs.
undelete
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
catalogs.
update
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
attachProduct
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
create
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
delete
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
detachProduct
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
setIamPolicy
Owner
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
cloudprivatecatalogproducer.
producerCatalogs.
update
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
products.
create
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
products.
delete
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
products.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
products.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
products.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
products.
setIamPolicy
Owner
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
Security Admin
( roles/
)
cloudprivatecatalogproducer.
products.
update
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
settings.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Catalog Org Admin
( roles/
)
Support User
( roles/
)
cloudprivatecatalogproducer.
settings.
update
Owner
( roles/
)
Editor
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
targets.
associate
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)
cloudprivatecatalogproducer.
targets.
unassociate
Owner
( roles/
)
Editor
( roles/
)
Catalog Admin
( roles/
)
Catalog Manager
( roles/
)
Catalog Org Admin
( roles/
)