This page lists the IAM roles and permissions for Cloud Security Compliance. To search through all roles and permissions, see the role and permission index .
Cloud Security Compliance roles
Compliance Manager Admin
( roles/
)
Full access to Compliance Manager resources.
auditmanager.auditReports.*
-
auditmanager.auditReports. generate -
auditmanager.auditReports.get -
auditmanager.auditReports.list
auditmanager.
auditmanager.
auditmanager.controlReports.*
-
auditmanager.controlReports. get -
auditmanager.controlReports. list
auditmanager.controls.list
auditmanager.findings.list
auditmanager.locations.*
-
auditmanager.locations. enrollResource -
auditmanager.locations.get -
auditmanager.locations.list
auditmanager.operations.*
-
auditmanager.operations.get -
auditmanager.operations.list
auditmanager.
-
auditmanager.resourceEnrollmentStatuses. get -
auditmanager.resourceEnrollmentStatuses. list
cloudsecuritycompliance.*
-
cloudsecuritycompliance.auditReports. generate -
cloudsecuritycompliance.auditReports. get -
cloudsecuritycompliance.auditReports. list -
cloudsecuritycompliance.auditScopeReports. generate -
cloudsecuritycompliance.billingSettings. get -
cloudsecuritycompliance.cloudControlDeployments. create -
cloudsecuritycompliance.cloudControlDeployments. delete -
cloudsecuritycompliance.cloudControlDeployments. get -
cloudsecuritycompliance.cloudControlDeployments. list -
cloudsecuritycompliance.cloudControlDeployments. update -
cloudsecuritycompliance.cloudControlPredictions. create -
cloudsecuritycompliance.cloudControlPredictions. get -
cloudsecuritycompliance.cloudControlPredictions. list -
cloudsecuritycompliance.cloudControls. create -
cloudsecuritycompliance.cloudControls. delete -
cloudsecuritycompliance.cloudControls. get -
cloudsecuritycompliance.cloudControls. list -
cloudsecuritycompliance.cloudControls. update -
cloudsecuritycompliance.cmEnrollments. get -
cloudsecuritycompliance.cmEnrollments. update -
cloudsecuritycompliance.controlComplianceSummaries. list -
cloudsecuritycompliance.controlReports. get -
cloudsecuritycompliance.controls. get -
cloudsecuritycompliance.controls. list -
cloudsecuritycompliance.findingSummaries. list -
cloudsecuritycompliance.findings. list -
cloudsecuritycompliance.frameworkAudits. create -
cloudsecuritycompliance.frameworkAudits. get -
cloudsecuritycompliance.frameworkAudits. list -
cloudsecuritycompliance.frameworkComplianceReports. aggregate -
cloudsecuritycompliance.frameworkComplianceReports. get -
cloudsecuritycompliance.frameworkComplianceSummaries. list -
cloudsecuritycompliance.frameworkDeployments. create -
cloudsecuritycompliance.frameworkDeployments. delete -
cloudsecuritycompliance.frameworkDeployments. get -
cloudsecuritycompliance.frameworkDeployments. list -
cloudsecuritycompliance.frameworkDeployments. update -
cloudsecuritycompliance.frameworks. create -
cloudsecuritycompliance.frameworks. delete -
cloudsecuritycompliance.frameworks. get -
cloudsecuritycompliance.frameworks. list -
cloudsecuritycompliance.frameworks. update -
cloudsecuritycompliance.locations. enrollResource -
cloudsecuritycompliance.locations. get -
cloudsecuritycompliance.locations. list -
cloudsecuritycompliance.operations. cancel -
cloudsecuritycompliance.operations. delete -
cloudsecuritycompliance.operations. get -
cloudsecuritycompliance.operations. list -
cloudsecuritycompliance.resourceEnrollmentStatuses. get -
cloudsecuritycompliance.resourceEnrollmentStatuses. list
resourcemanager.projects.get
resourcemanager.projects.list
Compliance Manager Viewer
( roles/
)
Readonly access to Compliance Manager resources.
auditmanager.auditReports.get
auditmanager.auditReports.list
auditmanager.
auditmanager.controlReports.*
-
auditmanager.controlReports. get -
auditmanager.controlReports. list
auditmanager.controls.list
auditmanager.findings.list
auditmanager.locations.get
auditmanager.locations.list
auditmanager.operations.*
-
auditmanager.operations.get -
auditmanager.operations.list
auditmanager.
-
auditmanager.resourceEnrollmentStatuses. get -
auditmanager.resourceEnrollmentStatuses. list
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
-
cloudsecuritycompliance.controls. get -
cloudsecuritycompliance.controls. list
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
-
cloudsecuritycompliance.frameworkComplianceReports. aggregate -
cloudsecuritycompliance.frameworkComplianceReports. get
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
-
cloudsecuritycompliance.resourceEnrollmentStatuses. get -
cloudsecuritycompliance.resourceEnrollmentStatuses. list
resourcemanager.projects.get
resourcemanager.projects.list
Service agent roles
Service agent roles should only be granted to service agents .
Cloud Security Compliance Service Agent
( roles/
)
Gives CSC Service Account access to consumer resources.
accessapproval.settings.get
aiplatform.customJobs.get
aiplatform.customJobs.list
aiplatform.datasets.get
aiplatform.datasets.list
aiplatform.endpoints.get
aiplatform.endpoints.list
aiplatform.featurestores.get
aiplatform.featurestores.list
aiplatform.
aiplatform.
aiplatform.metadataStores.get
aiplatform.metadataStores.list
aiplatform.models.get
aiplatform.models.list
aiplatform.
aiplatform.
aiplatform.tensorboards.get
aiplatform.tensorboards.list
aiplatform.
aiplatform.
artifactregistry.
artifactregistry.
axt.labels.get
bigquery.datasets.get
binaryauthorization.policy.get
certificatemanager.certs.list
certificatemanager.
cloudasset.
cloudasset.assets.analyzeMove
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.exportIapWeb
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listIamRoles
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listIapWeb
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listResource
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listTpuNodes
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.feeds.create
cloudasset.feeds.delete
cloudasset.feeds.get
cloudasset.
cloudasset.
cloudasset.
cloudkms.cryptoKeys.get
cloudkms.cryptoKeys.list
cloudkms.keyRings.list
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecurityscanner.scans.get
cloudsecurityscanner.
cloudsql.instances.get
cloudsql.instances.list
cloudsql.users.list
compute.autoscalers.list
compute.backendServices.list
compute.disks.list
compute.firewallPolicies.list
compute.firewalls.list
compute.forwardingRules.list
compute.
compute.
compute.instanceGroups.list
compute.instances.get
compute.instances.list
compute.networks.list
compute.regionSslPolicies.list
compute.
compute.regionUrlMaps.list
compute.routers.list
compute.securityPolicies.list
compute.sslCertificates.list
compute.sslPolicies.list
compute.subnetworks.list
compute.targetHttpProxies.list
compute.targetSslProxies.list
compute.urlMaps.list
compute.vpnGateways.list
compute.zones.list
container.clusters.get
container.clusters.list
dlp.fileStoreProfiles.list
dlp.inspectTemplates.list
dlp.jobTriggers.list
dlp.jobs.list
dlp.tableDataProfiles.get
dns.managedZones.list
iam.serviceAccounts.get
iam.
logging.buckets.list
logging.settings.update
monitoring.alertPolicies.list
monitoring.timeSeries.list
notebooks.instances.get
notebooks.instances.list
orgpolicy.constraints.list
orgpolicy.policy.get
privateca.certificates.list
recommender.
recommender.
recommender.locations.*
-
recommender.locations.get -
recommender.locations.list
resourcemanager.folders.get
resourcemanager.
resourcemanager.folders.list
resourcemanager.
resourcemanager.
resourcemanager.
resourcemanager.
resourcemanager.projects.get
resourcemanager.
resourcemanager.projects.list
resourcemanager.tagHolds.list
resourcemanager.tagKeys.get
resourcemanager.tagKeys.list
resourcemanager.tagValues.get
resourcemanager.tagValues.list
securitycentermanagement.
securitycentermanagement.
serviceusage.consumerpolicy.*
-
serviceusage.consumerpolicy. analyze -
serviceusage.consumerpolicy. get -
serviceusage.consumerpolicy. update
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.mcppolicy.get
serviceusage.operations.get
serviceusage.quotas.get
serviceusage.services.enable
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
storage.buckets.get
storage.buckets.getIamPolicy
storage.buckets.list
Cloud Security Compliance permissions
cloudsecuritycompliance.
auditReports.
generate
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
auditReports.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
auditReports.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
auditScopeReports.
generate
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
billingSettings.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
cloudControlDeployments.
create
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
cloudControlDeployments.
delete
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
cloudControlDeployments.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
cloudControlDeployments.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
cloudControlDeployments.
update
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
cloudControlPredictions.
create
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
cloudControlPredictions.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
cloudControlPredictions.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
cloudControls.
create
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
cloudControls.
delete
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
cloudControls.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
cloudControls.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
cloudControls.
update
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
cmEnrollments.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
cmEnrollments.
update
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
controlComplianceSummaries.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
controlReports.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
controls.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
controls.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
findingSummaries.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
findings.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
frameworkAudits.
create
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
frameworkAudits.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
frameworkAudits.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
frameworkComplianceReports.
aggregate
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
frameworkComplianceReports.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
frameworkComplianceSummaries.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
frameworkDeployments.
create
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
frameworkDeployments.
delete
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
frameworkDeployments.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
frameworkDeployments.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
frameworkDeployments.
update
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
frameworks.
create
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent
cloudsecuritycompliance.
frameworks.
delete
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
frameworks.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - DSPM Service Agent
(
roles/)dspm.serviceAgent
cloudsecuritycompliance.
frameworks.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent
cloudsecuritycompliance.
frameworks.
update
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
locations.
enrollResource
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
locations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
locations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
operations.
cancel
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
operations.
delete
Owner
( roles/
)
Editor
( roles/
)
Compliance Manager Admin
( roles/
)
Security Center Admin
( roles/
)
cloudsecuritycompliance.
operations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent
cloudsecuritycompliance.
operations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
resourceEnrollmentStatuses.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)
cloudsecuritycompliance.
resourceEnrollmentStatuses.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compliance Manager Admin
( roles/
)
Compliance Manager Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Security Center Admin
( roles/
)
Cloud Hub Operator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Security Center Admin Editor
( roles/
)
Security Center Admin Viewer
( roles/
)

