This page lists the IAM roles and permissions for Cloud Config Manager API. To search through all roles and permissions, see the role and permission index .
Cloud Config Manager API roles
Cloud Infrastructure Manager Admin
( roles/
)
Full access to Cloud Infrastructure Manager resources.
config.*
-
config.artifacts.import -
config.deployments.create -
config.deployments.delete -
config.deployments.deleteState -
config.deployments.get -
config.deployments. getIamPolicy -
config.deployments.getLock -
config.deployments.getState -
config.deployments.list -
config.deployments.lock -
config.deployments. setIamPolicy -
config.deployments.unlock -
config.deployments.update -
config.deployments.updateState -
config.locations.get -
config.locations.list -
config.operations.cancel -
config.operations.delete -
config.operations.get -
config.operations.list -
config.previews.create -
config.previews.delete -
config.previews.export -
config.previews.get -
config.previews.list -
config.previews.upload -
config.resourcechanges.get -
config.resourcechanges.list -
config.resourcedrifts.get -
config.resourcedrifts.list -
config.resources.get -
config.resources.list -
config.revisions.get -
config.revisions.getState -
config.revisions.list -
config.terraformversions.get -
config.terraformversions.list
resourcemanager.projects.get
resourcemanager.projects.list
Cloud Infrastructure Manager Agent
( roles/
)
Required permissions to make Cloud Infrastructure Manager work with the user-specified service account.
cloudbuild.connections.list
cloudbuild.
cloudbuild.repositories.list
cloudquotas.quotas.get
config.artifacts.import
config.deployments.deleteState
config.deployments.getLock
config.deployments.getState
config.deployments.updateState
config.previews.upload
config.revisions.getState
logging.logEntries.create
monitoring.timeSeries.list
storage.buckets.create
storage.buckets.delete
storage.buckets.get
storage.buckets.list
storage.buckets.update
storage.objects.create
storage.objects.delete
storage.objects.get
storage.objects.list
storage.objects.update
Cloud Infrastructure Manager Viewer
( roles/
)
Read-only access to Cloud Infrastructure Manager resources.
config.deployments.get
config.
config.deployments.list
config.locations.*
-
config.locations.get -
config.locations.list
config.operations.get
config.operations.list
config.previews.get
config.previews.list
config.resources.*
-
config.resources.get -
config.resources.list
config.revisions.get
config.revisions.list
config.terraformversions.*
-
config.terraformversions.get -
config.terraformversions.list
resourcemanager.projects.get
resourcemanager.projects.list
Cloud Config Manager API permissions
config.artifacts.import
Owner
( roles/
)
Editor
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
config.deployments.create
Owner
( roles/
)
Editor
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- SaaS Service Management Service Agent
(
roles/)saasservicemgmt.serviceAgent - Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.deployments.delete
Owner
( roles/
)
Editor
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- SaaS Service Management Service Agent
(
roles/)saasservicemgmt.serviceAgent - Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.deployments.deleteState
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
config.deployments.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- SaaS Service Management Service Agent
(
roles/)saasservicemgmt.serviceAgent - Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.
deployments.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
config.deployments.getLock
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
config.deployments.getState
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.deployments.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.deployments.lock
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.
deployments.
setIamPolicy
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Security Admin
( roles/
)
config.deployments.unlock
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.deployments.update
Owner
( roles/
)
Editor
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- SaaS Service Management Service Agent
(
roles/)saasservicemgmt.serviceAgent - Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.deployments.updateState
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
config.locations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.locations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.operations.cancel
Owner
( roles/
)
Editor
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.operations.delete
Owner
( roles/
)
Editor
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.operations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- SaaS Service Management Service Agent
(
roles/)saasservicemgmt.serviceAgent - Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.operations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.previews.create
Owner
( roles/
)
Editor
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.previews.delete
Owner
( roles/
)
Editor
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.previews.export
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
config.previews.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.previews.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.previews.upload
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
config.resourcechanges.get
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
config.resourcechanges.list
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
config.resourcedrifts.get
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
config.resourcedrifts.list
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
config.resources.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.resources.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.revisions.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- SaaS Service Management Service Agent
(
roles/)saasservicemgmt.serviceAgent - Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.revisions.getState
Owner
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.revisions.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Workload Manager Service Agent
(
roles/)workloadmanager.serviceAgent - DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.terraformversions.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent
config.terraformversions.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
App Management Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Cloud Infrastructure Manager Admin
( roles/
)
Cloud Infrastructure Manager Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Admin
( roles/
)
Application Editor
( roles/
)
Application Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- DesignCenter Service Agent
(
roles/)designcenter.serviceAgent

