This page lists the IAM roles and permissions for Cloud Trace. To search through all roles and permissions, see the role and permission index .
Cloud Trace roles
Cloud Trace Admin
( roles/
)
Provides full access to the Trace console and read-write access to traces.
Lowest-level resources where you can grant this role:
- Project
cloudtrace.*
-
cloudtrace.insights.get
-
cloudtrace.insights.list
-
cloudtrace.stats.get
-
cloudtrace.tasks.create
-
cloudtrace.tasks.delete
-
cloudtrace.tasks.get
-
cloudtrace.tasks.list
-
cloudtrace.traceScopes.create
-
cloudtrace.traceScopes.delete
-
cloudtrace.traceScopes.get
-
cloudtrace.traceScopes.list
-
cloudtrace.traceScopes.update
-
cloudtrace.traces.get
-
cloudtrace.traces.list
-
cloudtrace.traces.patch
observability.scopes.get
observability.traceScopes.*
-
observability.
traceScopes. create -
observability.
traceScopes. delete -
observability.traceScopes.get
-
observability.traceScopes.list
-
observability.
traceScopes. update
resourcemanager.projects.get
resourcemanager.projects.list
telemetry.traces.write
Cloud Trace Agent
( roles/
)
For service accounts. Provides ability to write traces by sending the data to Stackdriver Trace.
Lowest-level resources where you can grant this role:
- Project
cloudtrace.traces.patch
telemetry.traces.write
Cloud Trace User
( roles/
)
Provides full access to the Trace console and read access to traces.
Lowest-level resources where you can grant this role:
- Project
cloudtrace.insights.*
-
cloudtrace.insights.get
-
cloudtrace.insights.list
cloudtrace.stats.get
cloudtrace.tasks.*
-
cloudtrace.tasks.create
-
cloudtrace.tasks.delete
-
cloudtrace.tasks.get
-
cloudtrace.tasks.list
cloudtrace.traceScopes.*
-
cloudtrace.traceScopes.create
-
cloudtrace.traceScopes.delete
-
cloudtrace.traceScopes.get
-
cloudtrace.traceScopes.list
-
cloudtrace.traceScopes.update
cloudtrace.traces.get
cloudtrace.traces.list
observability.scopes.get
observability.traceScopes.*
-
observability.
traceScopes. create -
observability.
traceScopes. delete -
observability.traceScopes.get
-
observability.traceScopes.list
-
observability.
traceScopes. update
resourcemanager.projects.get
resourcemanager.projects.list
Cloud Trace permissions
cloudtrace.insights.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.insights.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.stats.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.tasks.create
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.tasks.delete
Owner
( roles/
)
Editor
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
cloudtrace.tasks.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.tasks.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.traceScopes.create
Owner
( roles/
)
Editor
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
cloudtrace.traceScopes.delete
Owner
( roles/
)
Editor
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
cloudtrace.traceScopes.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.traceScopes.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.traceScopes.update
Owner
( roles/
)
Editor
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
cloudtrace.traces.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.traces.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace User
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
cloudtrace.traces.patch
Owner
( roles/
)
Editor
( roles/
)
Cloud Trace Admin
( roles/
)
Cloud Trace Agent
( roles/
)
Service agent roles
- Apigee Service Agent
(
roles/
)apigee.serviceAgent - KubeRun Events Data Plane Service Agent
(
roles/
)kuberun.eventsDataPlaneServiceAgent - Mesh Data Plane Service Agent
(
roles/
)meshdataplane.serviceAgent - Monitoring Service Agent
(
roles/
)monitoring.notificationServiceAgent - Vertex AI Reasoning Engine Service Agent
(
roles/
)aiplatform.reasoningEngineServiceAgent