This page lists the IAM roles and permissions for Cloud Logging. To search through all roles and permissions, see the role and permission index .
Cloud Logging roles
Logging Admin
( roles/
)
Provides all permissions necessary to use all features of Cloud Logging.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.copyLogEntries
logging.buckets.create
logging.
logging.buckets.delete
logging.
logging.buckets.get
logging.buckets.list
logging.
logging.
logging.buckets.undelete
logging.buckets.update
logging.exclusions.*
-
logging.exclusions.create -
logging.exclusions.delete -
logging.exclusions.get -
logging.exclusions.list -
logging.exclusions.update
logging.fields.access
logging.links.*
-
logging.links.create -
logging.links.delete -
logging.links.get -
logging.links.list
logging.locations.*
-
logging.locations.get -
logging.locations.list
logging.logEntries.*
-
logging.logEntries.create -
logging.logEntries.download -
logging.logEntries.list -
logging.logEntries.route
logging.logMetrics.*
-
logging.logMetrics.create -
logging.logMetrics.delete -
logging.logMetrics.get -
logging.logMetrics.list -
logging.logMetrics.update
logging.logScopes.*
-
logging.logScopes.create -
logging.logScopes.delete -
logging.logScopes.get -
logging.logScopes.list -
logging.logScopes.update
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.*
-
logging.logs.delete -
logging.logs.list
logging.notificationRules.*
-
logging.notificationRules. create -
logging.notificationRules. delete -
logging.notificationRules.get -
logging.notificationRules.list -
logging.notificationRules. update
logging.operations.*
-
logging.operations.cancel -
logging.operations.get -
logging.operations.list
logging.privateLogEntries.list
logging.queries.*
-
logging.queries.deleteShared -
logging.queries.getShared -
logging.queries.listShared -
logging.queries.share -
logging.queries.updateShared -
logging.queries.usePrivate
logging.settings.*
-
logging.settings.get -
logging.settings.update
logging.sinks.*
-
logging.sinks.create -
logging.sinks.delete -
logging.sinks.get -
logging.sinks.list -
logging.sinks.update
logging.sqlAlerts.*
-
logging.sqlAlerts.create -
logging.sqlAlerts.update
logging.usage.get
logging.views.*
-
logging.views.access -
logging.views.create -
logging.views.delete -
logging.views.get -
logging.views.getIamPolicy -
logging.views.list -
logging.views.listLogs -
logging.views.listResourceKeys -
logging.views. listResourceValues -
logging.views.setIamPolicy -
logging.views.update
observability.scopes.get
resourcemanager.projects.get
resourcemanager.projects.list
Logs Bucket Writer
( roles/
)
Ability to write logs to a log bucket.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.write
Logs Configuration Writer
( roles/
)
Provides permissions to read and write the configurations of logs-based metrics and sinks for exporting logs.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.create
logging.
logging.buckets.delete
logging.
logging.buckets.get
logging.buckets.list
logging.
logging.
logging.buckets.undelete
logging.buckets.update
logging.exclusions.*
-
logging.exclusions.create -
logging.exclusions.delete -
logging.exclusions.get -
logging.exclusions.list -
logging.exclusions.update
logging.links.*
-
logging.links.create -
logging.links.delete -
logging.links.get -
logging.links.list
logging.locations.*
-
logging.locations.get -
logging.locations.list
logging.logMetrics.*
-
logging.logMetrics.create -
logging.logMetrics.delete -
logging.logMetrics.get -
logging.logMetrics.list -
logging.logMetrics.update
logging.logScopes.*
-
logging.logScopes.create -
logging.logScopes.delete -
logging.logScopes.get -
logging.logScopes.list -
logging.logScopes.update
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.list
logging.notificationRules.*
-
logging.notificationRules. create -
logging.notificationRules. delete -
logging.notificationRules.get -
logging.notificationRules.list -
logging.notificationRules. update
logging.operations.*
-
logging.operations.cancel -
logging.operations.get -
logging.operations.list
logging.settings.*
-
logging.settings.get -
logging.settings.update
logging.sinks.*
-
logging.sinks.create -
logging.sinks.delete -
logging.sinks.get -
logging.sinks.list -
logging.sinks.update
logging.sqlAlerts.*
-
logging.sqlAlerts.create -
logging.sqlAlerts.update
logging.views.create
logging.views.delete
logging.views.get
logging.views.getIamPolicy
logging.views.list
logging.views.update
observability.scopes.get
resourcemanager.projects.get
resourcemanager.projects.list
Log Field Accessor
( roles/
)
Ability to read restricted fields in a log bucket.
Lowest-level resources where you can grant this role:
- Project
logging.fields.access
Log Link Accessor
( roles/
)
Ability to see links for a bucket.
logging.links.get
logging.links.list
Logs Writer
( roles/
)
Provides the permissions to write log entries.
Lowest-level resources where you can grant this role:
- Project
logging.logEntries.create
logging.logEntries.route
Private Logs Viewer
( roles/
)
Provides permissions of the Logs Viewer role and in addition, provides read-only access to log entries in private logs.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.get
logging.buckets.list
logging.exclusions.get
logging.exclusions.list
logging.links.get
logging.links.list
logging.locations.*
-
logging.locations.get -
logging.locations.list
logging.logEntries.list
logging.logMetrics.get
logging.logMetrics.list
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.list
logging.operations.get
logging.operations.list
logging.privateLogEntries.list
logging.queries.getShared
logging.queries.listShared
logging.queries.usePrivate
logging.sinks.get
logging.sinks.list
logging.usage.get
logging.views.access
logging.views.get
logging.views.list
observability.scopes.get
resourcemanager.projects.get
Cloud Logging Service Agent
( roles/
)
Grants a Cloud Logging Service Account the ability to create and link datasets.
bigquery.datasets.create
bigquery.datasets.get
bigquery.datasets.link
SQL Alert Writer Beta
( roles/
)
Ability to write SQL Alerts.
logging.sqlAlerts.*
-
logging.sqlAlerts.create -
logging.sqlAlerts.update
Logs View Accessor
( roles/
)
Ability to read logs in a view.
Lowest-level resources where you can grant this role:
- Project
logging.logEntries.download
logging.views.access
logging.views.listLogs
logging.views.listResourceKeys
logging.
Logs Viewer
( roles/
)
Provides access to view logs.
Lowest-level resources where you can grant this role:
- Project
logging.buckets.get
logging.buckets.list
logging.exclusions.get
logging.exclusions.list
logging.links.get
logging.links.list
logging.locations.*
-
logging.locations.get -
logging.locations.list
logging.logEntries.list
logging.logMetrics.get
logging.logMetrics.list
logging.logScopes.get
logging.logScopes.list
logging.logServiceIndexes.list
logging.logServices.list
logging.logs.list
logging.operations.get
logging.operations.list
logging.queries.getShared
logging.queries.listShared
logging.queries.usePrivate
logging.sinks.get
logging.sinks.list
logging.usage.get
logging.views.get
logging.views.list
observability.scopes.get
resourcemanager.projects.get
Cloud Logging permissions
logging.buckets.copyLogEntries
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
logging.buckets.create
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Apigee Service Agent
(
roles/)apigee.serviceAgent
logging.
buckets.
createTagBinding
Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Tag User
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.buckets.delete
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.
buckets.
deleteTagBinding
Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Tag User
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.buckets.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Apigee Service Agent
(
roles/)apigee.serviceAgent
logging.buckets.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Audit Manager Auditing Service Agent
(
roles/)auditmanager.serviceAgent - Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent - Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Apigee Service Agent
(
roles/)apigee.serviceAgent
logging.
buckets.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.
buckets.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.buckets.undelete
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.buckets.update
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.buckets.write
Logs Bucket Writer
( roles/
)
Service agent roles
- Cloud Build Logging Service Agent
(
roles/)cloudbuild.loggingServiceAgent
logging.exclusions.create
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.exclusions.delete
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.exclusions.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.exclusions.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.exclusions.update
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.fields.access
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Log Field Accessor
( roles/
)
logging.links.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.links.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.links.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Log Link Accessor
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.links.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Log Link Accessor
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Monitoring Service Agent
(
roles/)monitoring.notificationServiceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.locations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.locations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logEntries.create
Owner
( roles/
)
Editor
( roles/
)
Cloud Build Service Account
( roles/
)
Cloud Deploy Runner
( roles/
)
Composer Worker
( roles/
)
Confidential Space Workload User
( roles/
)
Cloud Infrastructure Manager Agent
( roles/
)
Kubernetes Engine Default Node Service Account
( roles/
)
Dataflow Worker
( roles/
)
Dataproc Hub Agent
( roles/
)
Dataproc Worker
( roles/
)
Developer Connect Insights Config Agent
( roles/
)
Firebase App Hosting Compute Runner
( roles/
)
Anthos Multi-cloud Telemetry Writer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Writer
( roles/
)
Cloud Run Builder
( roles/
)
Storage Transfer Agent
( roles/
)
Service agent roles
- Vertex AI Extension Custom Code Service Agent
(
roles/)aiplatform.extensionCustomCodeServiceAgent - Vertex AI Extension Service Agent
(
roles/)aiplatform.extensionServiceAgent - Vertex AI Notebook Service Agent
(
roles/)aiplatform.notebookServiceAgent - Vertex AI RAG Data Service Agent
(
roles/)aiplatform.ragServiceAgent - Vertex AI Reasoning Engine Service Agent
(
roles/)aiplatform.reasoningEngineServiceAgent - Vertex AI Service Agent
(
roles/)aiplatform.serviceAgent - Vertex AI Telemetry Service Agent
(
roles/)aiplatform.telemetryServiceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - App Engine flexible environment Service Agent
(
roles/)appengineflex.serviceAgent - Recommendations AI Service Agent
(
roles/)automlrecommendations.serviceAgent - BigQuery Connection Service Agent
(
roles/)bigqueryconnection.serviceAgent - BigQuery Data Transfer Service Agent
(
roles/)bigquerydatatransfer.serviceAgent - Customer Engagement Suite Service Agent
(
roles/)ces.serviceAgent - Gemini for Google Cloud Service Agent
(
roles/)cloudaicompanion.serviceAgent - Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent - Infrastructure Manager Service Agent
(
roles/)cloudconfig.serviceAgent - Cloud Deploy Service Agent
(
roles/)clouddeploy.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent - Cloud IoT Core Service Agent
(
roles/)cloudiot.serviceAgent - Cloud Scheduler Service Agent
(
roles/)cloudscheduler.serviceAgent - Cloud Tasks Service Agent
(
roles/)cloudtasks.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Compute Engine Service Agent
(
roles/)compute.serviceAgent - Kubernetes Engine Default Node Service Agent
(
roles/)container.defaultNodeServiceAgent - [Deprecated] Kubernetes Engine Node Service Agent
(
roles/)container.nodeServiceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - Cloud Dataplex Service Agent
(
roles/)dataplex.serviceAgent - Dataproc Resource Manager Node Service Agent
(
roles/)dataprocrm.nodeServiceAgent - Dialogflow Service Agent
(
roles/)dialogflow.serviceAgent - Discovery Engine Service Agent
(
roles/)discoveryengine.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Firebase Machine Learning Service Agent
(
roles/)firebaseml.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Mesh Data Plane Service Agent
(
roles/)meshdataplane.serviceAgent - AI Platform Service Agent
(
roles/)ml.serviceAgent - RMA Service Agent
(
roles/)rapidmigrationassessment.serviceAgent - Retail Service Agent
(
roles/)retail.serviceAgent - Cloud Spanner API Service Agent
(
roles/)spanner.serviceAgent - Cloud Vision AI Service Agent
(
roles/)visionai.serviceAgent - Serverless VPC Access Service Agent
(
roles/)vpcaccess.serviceAgent - Vertex AI Custom Code Service Agent
(
roles/)aiplatform.customCodeServiceAgent
logging.logEntries.download
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs View Accessor
( roles/
)
logging.logEntries.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Billing Account Administrator
( roles/
)
Cloud Build Service Account
( roles/
)
Cloud Hub Operator
( roles/
)
Composer Worker
( roles/
)
Dataproc Hub Agent
( roles/
)
Firebase Admin
( roles/
)
Firebase Develop Admin
( roles/
)
Firebase Develop Viewer
( roles/
)
Firebase Viewer
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent - Secured Landing Zone Service Agent
(
roles/)securedlandingzone.serviceAgent - Security Center Control Service Agent
(
roles/)securitycenter.controlServiceAgent - Security Center Service Agent
(
roles/)securitycenter.serviceAgent - Vertex AI Telemetry Service Agent
(
roles/)aiplatform.telemetryServiceAgent
logging.logEntries.route
Owner
( roles/
)
Editor
( roles/
)
Composer Worker
( roles/
)
Dataflow Worker
( roles/
)
Dataproc Hub Agent
( roles/
)
Dataproc Worker
( roles/
)
Firebase App Hosting Compute Runner
( roles/
)
Anthos Multi-cloud Telemetry Writer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Writer
( roles/
)
Service agent roles
- Vertex AI Extension Custom Code Service Agent
(
roles/)aiplatform.extensionCustomCodeServiceAgent - Vertex AI Extension Service Agent
(
roles/)aiplatform.extensionServiceAgent - Vertex AI Notebook Service Agent
(
roles/)aiplatform.notebookServiceAgent - Vertex AI RAG Data Service Agent
(
roles/)aiplatform.ragServiceAgent - Vertex AI Reasoning Engine Service Agent
(
roles/)aiplatform.reasoningEngineServiceAgent - Vertex AI Service Agent
(
roles/)aiplatform.serviceAgent - Vertex AI Telemetry Service Agent
(
roles/)aiplatform.telemetryServiceAgent - Recommendations AI Service Agent
(
roles/)automlrecommendations.serviceAgent - BigQuery Connection Service Agent
(
roles/)bigqueryconnection.serviceAgent - BigQuery Data Transfer Service Agent
(
roles/)bigquerydatatransfer.serviceAgent - Customer Engagement Suite Service Agent
(
roles/)ces.serviceAgent - Gemini for Google Cloud Service Agent
(
roles/)cloudaicompanion.serviceAgent - Infrastructure Manager Service Agent
(
roles/)cloudconfig.serviceAgent - Cloud IoT Core Service Agent
(
roles/)cloudiot.serviceAgent - Cloud Scheduler Service Agent
(
roles/)cloudscheduler.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Dataplex Service Agent
(
roles/)dataplex.serviceAgent - Dataproc Resource Manager Node Service Agent
(
roles/)dataprocrm.nodeServiceAgent - Dialogflow Service Agent
(
roles/)dialogflow.serviceAgent - Firebase Machine Learning Service Agent
(
roles/)firebaseml.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Mesh Data Plane Service Agent
(
roles/)meshdataplane.serviceAgent - AI Platform Service Agent
(
roles/)ml.serviceAgent - Retail Service Agent
(
roles/)retail.serviceAgent - Vertex AI Custom Code Service Agent
(
roles/)aiplatform.customCodeServiceAgent
logging.logMetrics.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Serverless VPC Access Service Agent
(
roles/)vpcaccess.serviceAgent - App Engine flexible environment Service Agent
(
roles/)appengineflex.serviceAgent
logging.logMetrics.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Serverless VPC Access Service Agent
(
roles/)vpcaccess.serviceAgent - App Engine flexible environment Service Agent
(
roles/)appengineflex.serviceAgent
logging.logMetrics.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Serverless VPC Access Service Agent
(
roles/)vpcaccess.serviceAgent - App Engine flexible environment Service Agent
(
roles/)appengineflex.serviceAgent
logging.logMetrics.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logMetrics.update
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Serverless VPC Access Service Agent
(
roles/)vpcaccess.serviceAgent - App Engine flexible environment Service Agent
(
roles/)appengineflex.serviceAgent
logging.logScopes.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Observability Scopes Editor
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logScopes.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Observability Scopes Editor
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logScopes.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Logs Viewer
( roles/
)
Observability Scopes Editor
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logScopes.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Logs Viewer
( roles/
)
Observability Scopes Editor
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logScopes.update
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Observability Scopes Editor
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logServiceIndexes.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Billing Account Administrator
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logServices.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Billing Account Administrator
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.logs.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
logging.logs.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Billing Account Administrator
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.
notificationRules.
create
Owner
( roles/
)
Editor
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.
notificationRules.
delete
Owner
( roles/
)
Editor
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.notificationRules.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Error Reporting Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.notificationRules.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Error Reporting Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.
notificationRules.
update
Owner
( roles/
)
Editor
( roles/
)
Error Reporting Admin
( roles/
)
Error Reporting User
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.operations.cancel
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.operations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.operations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.privateLogEntries.list
Owner
( roles/
)
Billing Account Administrator
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
logging.queries.deleteShared
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
logging.queries.getShared
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Observability Analytics User
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
logging.queries.listShared
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Observability Analytics User
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
logging.queries.share
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
logging.queries.updateShared
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
logging.queries.usePrivate
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Observability Analytics User
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
logging.settings.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.settings.update
Owner
( roles/
)
Editor
( roles/
)
Assured Workloads Administrator
( roles/
)
Assured Workloads Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent
logging.sinks.create
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KubeRun Events Control Plane Service Agent
(
roles/)kuberun.eventsControlPlaneServiceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.sinks.delete
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KubeRun Events Control Plane Service Agent
(
roles/)kuberun.eventsControlPlaneServiceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.sinks.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KubeRun Events Control Plane Service Agent
(
roles/)kuberun.eventsControlPlaneServiceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.sinks.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.sinks.update
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
logging.sqlAlerts.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
SQL Alert Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.sqlAlerts.update
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
SQL Alert Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.usage.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
VPC Service Controls Troubleshooter Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
logging.views.access
Owner
( roles/
)
Cloud Build Service Account
( roles/
)
Composer Worker
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Private Logs Viewer
( roles/
)
Logs View Accessor
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
logging.views.create
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Apigee Service Agent
(
roles/)apigee.serviceAgent
logging.views.delete
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.views.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Apigee Service Agent
(
roles/)apigee.serviceAgent
logging.views.getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent
logging.views.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Cloud Hub Operator
( roles/
)
Dataproc Hub Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Site Reliability Engineer
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Private Logs Viewer
( roles/
)
Logs Viewer
( roles/
)
Telco Automation Admin
( roles/
)
Telco Automation Tier 1 Operations Admin
( roles/
)
Telco Automation Tier 4 Operations Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Apigee Service Agent
(
roles/)apigee.serviceAgent
logging.views.listLogs
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs View Accessor
( roles/
)
logging.views.listResourceKeys
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs View Accessor
( roles/
)
logging.
views.
listResourceValues
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Logging Admin
( roles/
)
Logs View Accessor
( roles/
)
logging.views.setIamPolicy
Owner
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Logging Admin
( roles/
)
logging.views.update
Owner
( roles/
)
Editor
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Logging Admin
( roles/
)
Logs Configuration Writer
( roles/
)
Service agent roles
- Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent

