This page lists the IAM roles and permissions for Access Context Manager. To search through all roles and permissions, see the role and permission index .
Access Context Manager roles
Cloud Access Binding Admin
( roles/  
)
Create, edit, and change Cloud access bindings.
  accesscontextmanager.  
 
-  accesscontextmanager.gcpUserAccessBindings. create 
-  accesscontextmanager.gcpUserAccessBindings. delete 
-  accesscontextmanager.gcpUserAccessBindings. get 
-  accesscontextmanager.gcpUserAccessBindings. list 
-  accesscontextmanager.gcpUserAccessBindings. update 
Cloud Access Binding Reader
( roles/  
)
Read access to Cloud access bindings.
 accesscontextmanager.  
 accesscontextmanager.  
Access Context Manager Admin
( roles/  
)
Full access to policies, access levels, access zones and authorized orgs descs.
  accesscontextmanager.  
 
-  accesscontextmanager.accessLevels. create 
-  accesscontextmanager.accessLevels. delete 
-  accesscontextmanager.accessLevels. get 
-  accesscontextmanager.accessLevels. list 
-  accesscontextmanager.accessLevels. replaceAll 
-  accesscontextmanager.accessLevels. update 
  accesscontextmanager.  
 
-  accesscontextmanager.authorizedOrgsDescs. create 
-  accesscontextmanager.authorizedOrgsDescs. delete 
-  accesscontextmanager.authorizedOrgsDescs. get 
-  accesscontextmanager.authorizedOrgsDescs. list 
-  accesscontextmanager.authorizedOrgsDescs. update 
  accesscontextmanager.  
 
-  accesscontextmanager.policies. create 
-  accesscontextmanager.policies. delete 
-  accesscontextmanager.policies. get 
-  accesscontextmanager.policies. getIamPolicy 
-  accesscontextmanager.policies. list 
-  accesscontextmanager.policies. setIamPolicy 
-  accesscontextmanager.policies. update 
  accesscontextmanager.  
 
-  accesscontextmanager.servicePerimeters. commit 
-  accesscontextmanager.servicePerimeters. create 
-  accesscontextmanager.servicePerimeters. delete 
-  accesscontextmanager.servicePerimeters. get 
-  accesscontextmanager.servicePerimeters. list 
-  accesscontextmanager.servicePerimeters. replaceAll 
-  accesscontextmanager.servicePerimeters. update 
 cloudasset.  
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Access Context Manager Editor
( roles/  
)
Edit access to policies. Create, edit, and change access levels, access zones and authorized orgs descs.
  accesscontextmanager.  
 
-  accesscontextmanager.accessLevels. create 
-  accesscontextmanager.accessLevels. delete 
-  accesscontextmanager.accessLevels. get 
-  accesscontextmanager.accessLevels. list 
-  accesscontextmanager.accessLevels. replaceAll 
-  accesscontextmanager.accessLevels. update 
  accesscontextmanager.  
 
-  accesscontextmanager.authorizedOrgsDescs. create 
-  accesscontextmanager.authorizedOrgsDescs. delete 
-  accesscontextmanager.authorizedOrgsDescs. get 
-  accesscontextmanager.authorizedOrgsDescs. list 
-  accesscontextmanager.authorizedOrgsDescs. update 
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
  accesscontextmanager.  
 
-  accesscontextmanager.servicePerimeters. commit 
-  accesscontextmanager.servicePerimeters. create 
-  accesscontextmanager.servicePerimeters. delete 
-  accesscontextmanager.servicePerimeters. get 
-  accesscontextmanager.servicePerimeters. list 
-  accesscontextmanager.servicePerimeters. replaceAll 
-  accesscontextmanager.servicePerimeters. update 
 cloudasset.  
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Access Context Manager Reader
( roles/  
)
Read access to policies, access levels, access zones and authorized orgs descs.
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
VPC Service Controls Troubleshooter Viewer
( roles/  
)
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 accesscontextmanager.  
 logging.exclusions.get 
 logging.exclusions.list 
 logging.logEntries.list 
 logging.logMetrics.get 
 logging.logMetrics.list 
 logging.logServiceIndexes.list 
 logging.logServices.list 
 logging.logs.list 
 logging.sinks.get 
 logging.sinks.list 
 logging.usage.get 
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Access Context Manager permissions
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Access Binding Admin 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Access Binding Admin 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Access Binding Admin 
( roles/  
)
 Cloud Access Binding Reader 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Access Binding Admin 
( roles/  
)
 Cloud Access Binding Reader 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Access Binding Admin 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 SLZ BQDW Blueprint Organization Level Remediator 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 Access Context Manager Reader 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 SLZ BQDW Blueprint Organization Level Remediator 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 accesscontextmanager.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Access Context Manager Admin 
( roles/  
)
 Access Context Manager Editor 
( roles/  
)
 SLZ BQDW Blueprint Organization Level Remediator 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 

