This page lists the IAM roles and permissions for Backup and Disaster Recovery. To search through all roles and permissions, see the role and permission index .
Backup and Disaster Recovery roles
Backup and DR Admin
( roles/  
)
Provides full access to all Backup and DR resources.
  backupdr.  
 
-  backupdr.backupPlanAssociations. createForAlloydbCluster 
-  backupdr.backupPlanAssociations. createForCloudSqlInstance 
-  backupdr.backupPlanAssociations. createForComputeDisk 
-  backupdr.backupPlanAssociations. createForComputeInstance 
-  backupdr.backupPlanAssociations. deleteForAlloydbCluster 
-  backupdr.backupPlanAssociations. deleteForCloudSqlInstance 
-  backupdr.backupPlanAssociations. deleteForComputeDisk 
-  backupdr.backupPlanAssociations. deleteForComputeInstance 
-  backupdr.backupPlanAssociations. fetchForAlloydbCluster 
-  backupdr.backupPlanAssociations. fetchForCloudSqlInstance 
-  backupdr.backupPlanAssociations. fetchForComputeDisk 
-  backupdr.backupPlanAssociations. fetchForComputeInstance 
-  backupdr.backupPlanAssociations. getForAlloydbCluster 
-  backupdr.backupPlanAssociations. getForCloudSqlInstance 
-  backupdr.backupPlanAssociations. getForComputeDisk 
-  backupdr.backupPlanAssociations. getForComputeInstance 
-  backupdr.backupPlanAssociations. list 
-  backupdr.backupPlanAssociations. triggerBackupForAlloydbCluster 
-  backupdr.backupPlanAssociations. triggerBackupForCloudSqlInstance 
-  backupdr.backupPlanAssociations. triggerBackupForComputeDisk 
-  backupdr.backupPlanAssociations. triggerBackupForComputeInstance 
-  backupdr.backupPlanAssociations. updateForAlloydbCluster 
-  backupdr.backupPlanAssociations. updateForComputeDisk 
-  backupdr.backupPlanAssociations. updateForComputeInstance 
  backupdr.backupPlanRevisions.* 
 
-  backupdr.backupPlanRevisions. get 
-  backupdr.backupPlanRevisions. list 
  backupdr.backupPlans.* 
 
-  backupdr.backupPlans.create
-  backupdr.backupPlans.delete
-  backupdr.backupPlans.get
-  backupdr.backupPlans.list
-  backupdr.backupPlans.update
-  backupdr.backupPlans. useForAlloydbCluster 
-  backupdr.backupPlans. useForCloudSqlInstance 
-  backupdr.backupPlans. useForComputeDisk 
-  backupdr.backupPlans. useForComputeInstance 
  backupdr.backupVaults.* 
 
-  backupdr.backupVaults. associate 
-  backupdr.backupVaults.create
-  backupdr.backupVaults.delete
-  backupdr.backupVaults.get
-  backupdr.backupVaults.list
-  backupdr.backupVaults.update
  backupdr.bvbackups.* 
 
-  backupdr.bvbackups.delete
-  backupdr.bvbackups. fetchForCloudSqlInstance 
-  backupdr.bvbackups. fetchForComputeDisk 
-  backupdr.bvbackups. fetchForComputeInstance 
-  backupdr.bvbackups.get
-  backupdr.bvbackups.list
-  backupdr.bvbackups.restore
-  backupdr.bvbackups.update
-  backupdr.bvbackups. useReadOnlyForAlloydbCluster 
-  backupdr.bvbackups. useReadOnlyForCloudSqlInstance 
  backupdr.bvdataSources.* 
 
-  backupdr.bvdataSources. abandonBackup 
-  backupdr.bvdataSources. fetchAccessToken 
-  backupdr.bvdataSources. finalizeBackup 
-  backupdr.bvdataSources.get
-  backupdr.bvdataSources. initiateBackup 
-  backupdr.bvdataSources.list
-  backupdr.bvdataSources.remove
-  backupdr.bvdataSources. setInternalStatus 
-  backupdr.bvdataSources.update
-  backupdr.bvdataSources. useReadOnlyForAlloydbCluster 
-  backupdr.bvdataSources. useReadOnlyForCloudSqlInstance 
 backupdr.  
  backupdr.  
 
-  backupdr.dataSourceReferences. fetchForAlloydbCluster 
-  backupdr.dataSourceReferences. fetchForCloudSqlInstance 
-  backupdr.dataSourceReferences. getForAlloydbCluster 
-  backupdr.dataSourceReferences. getForCloudSqlInstance 
-  backupdr.dataSourceReferences. list 
  backupdr.locations.* 
 
-  backupdr.locations.get
-  backupdr.locations.list
  backupdr.managementServers.* 
 
-  backupdr.managementServers. access 
-  backupdr.managementServers. accessSensitiveData 
-  backupdr.managementServers. assignBackupPlans 
-  backupdr.managementServers. backupAccess 
-  backupdr.managementServers. create 
-  backupdr.managementServers. createConnection 
-  backupdr.managementServers. createDynamicProtection 
-  backupdr.managementServers. delete 
-  backupdr.managementServers. deleteDynamicProtection 
-  backupdr.managementServers.get
-  backupdr.managementServers. getDynamicProtection 
-  backupdr.managementServers. getIamPolicy 
-  backupdr.managementServers. list 
-  backupdr.managementServers. listDynamicProtection 
-  backupdr.managementServers. manageApplications 
-  backupdr.managementServers. manageBackupPlans 
-  backupdr.managementServers. manageBackupServers 
-  backupdr.managementServers. manageBackups 
-  backupdr.managementServers. manageClones 
-  backupdr.managementServers. manageExpiration 
-  backupdr.managementServers. manageHosts 
-  backupdr.managementServers. manageInternalACL 
-  backupdr.managementServers. manageJobs 
-  backupdr.managementServers. manageLiveClones 
-  backupdr.managementServers. manageMigrations 
-  backupdr.managementServers. manageMirroring 
-  backupdr.managementServers. manageMounts 
-  backupdr.managementServers. manageRestores 
-  backupdr.managementServers. manageSensitiveData 
-  backupdr.managementServers. manageStorage 
-  backupdr.managementServers. manageSystem 
-  backupdr.managementServers. manageWorkflows 
-  backupdr.managementServers. refreshWorkflows 
-  backupdr.managementServers. runWorkflows 
-  backupdr.managementServers. setIamPolicy 
-  backupdr.managementServers. testFailOvers 
-  backupdr.managementServers. viewBackupPlans 
-  backupdr.managementServers. viewBackupServers 
-  backupdr.managementServers. viewReports 
-  backupdr.managementServers. viewStorage 
-  backupdr.managementServers. viewSystem 
-  backupdr.managementServers. viewWorkflows 
  backupdr.operations.* 
 
-  backupdr.operations.cancel
-  backupdr.operations.delete
-  backupdr.operations.get
-  backupdr.operations.list
 backupdr.  
  backupdr.trial.* 
 
-  backupdr.trial.get
-  backupdr.trial.subscribe
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and DR Backup Config Viewer Beta
( roles/  
)
Provides read access to resource backup config. Resource backup config has the metadata of a Google Cloud resource that can be backed up, along with its backup configurations.
 backupdr.locations.list 
  backupdr.  
 
-  backupdr.resourceBackupConfigs. get 
-  backupdr.resourceBackupConfigs. list 
Backup and DR Backup User
( roles/  
)
Allows the user to apply existing backup plans. This role cannot create backup plans or restore from a backup.
  backupdr.  
 
-  backupdr.backupPlanAssociations. createForAlloydbCluster 
-  backupdr.backupPlanAssociations. createForCloudSqlInstance 
-  backupdr.backupPlanAssociations. createForComputeDisk 
-  backupdr.backupPlanAssociations. createForComputeInstance 
-  backupdr.backupPlanAssociations. deleteForAlloydbCluster 
-  backupdr.backupPlanAssociations. deleteForCloudSqlInstance 
-  backupdr.backupPlanAssociations. deleteForComputeDisk 
-  backupdr.backupPlanAssociations. deleteForComputeInstance 
-  backupdr.backupPlanAssociations. fetchForAlloydbCluster 
-  backupdr.backupPlanAssociations. fetchForCloudSqlInstance 
-  backupdr.backupPlanAssociations. fetchForComputeDisk 
-  backupdr.backupPlanAssociations. fetchForComputeInstance 
-  backupdr.backupPlanAssociations. getForAlloydbCluster 
-  backupdr.backupPlanAssociations. getForCloudSqlInstance 
-  backupdr.backupPlanAssociations. getForComputeDisk 
-  backupdr.backupPlanAssociations. getForComputeInstance 
-  backupdr.backupPlanAssociations. list 
-  backupdr.backupPlanAssociations. triggerBackupForAlloydbCluster 
-  backupdr.backupPlanAssociations. triggerBackupForCloudSqlInstance 
-  backupdr.backupPlanAssociations. triggerBackupForComputeDisk 
-  backupdr.backupPlanAssociations. triggerBackupForComputeInstance 
-  backupdr.backupPlanAssociations. updateForAlloydbCluster 
-  backupdr.backupPlanAssociations. updateForComputeDisk 
-  backupdr.backupPlanAssociations. updateForComputeInstance 
  backupdr.backupPlanRevisions.* 
 
-  backupdr.backupPlanRevisions. get 
-  backupdr.backupPlanRevisions. list 
 backupdr.backupPlans.get 
 backupdr.backupPlans.list 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.backupVaults.get 
 backupdr.backupVaults.list 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.bvbackups.get 
 backupdr.bvbackups.list 
 backupdr.bvdataSources.get 
 backupdr.bvdataSources.list 
  backupdr.  
 
-  backupdr.dataSourceReferences. fetchForAlloydbCluster 
-  backupdr.dataSourceReferences. fetchForCloudSqlInstance 
-  backupdr.dataSourceReferences. getForAlloydbCluster 
-  backupdr.dataSourceReferences. getForCloudSqlInstance 
-  backupdr.dataSourceReferences. list 
  backupdr.locations.* 
 
-  backupdr.locations.get
-  backupdr.locations.list
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.managementServers.get 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.operations.get 
 backupdr.operations.list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and DR Backup Vault Accessor
( roles/  
)
Allows the Backup Appliance permissions to create and manage backups in a backup vault.
 backupdr.backupVaults.get 
 backupdr.backupVaults.list 
 backupdr.bvbackups.delete 
 backupdr.bvbackups.get 
 backupdr.bvbackups.list 
 backupdr.bvbackups.update 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.bvdataSources.get 
 backupdr.  
 backupdr.bvdataSources.list 
 backupdr.bvdataSources.remove 
 backupdr.  
 backupdr.bvdataSources.update 
  backupdr.operations.* 
 
-  backupdr.operations.cancel
-  backupdr.operations.delete
-  backupdr.operations.get
-  backupdr.operations.list
Backup and DR Backup Vault Admin
( roles/  
)
Allows the Backup Appliance full administrative control of backup vault resources.
  backupdr.backupVaults.* 
 
-  backupdr.backupVaults. associate 
-  backupdr.backupVaults.create
-  backupdr.backupVaults.delete
-  backupdr.backupVaults.get
-  backupdr.backupVaults.list
-  backupdr.backupVaults.update
 backupdr.bvbackups.delete 
 backupdr.bvbackups.get 
 backupdr.bvbackups.list 
 backupdr.bvbackups.restore 
 backupdr.bvbackups.update 
 backupdr.bvdataSources.get 
 backupdr.bvdataSources.list 
 backupdr.bvdataSources.update 
 backupdr.  
  backupdr.locations.* 
 
-  backupdr.locations.get
-  backupdr.locations.list
  backupdr.operations.* 
 
-  backupdr.operations.cancel
-  backupdr.operations.delete
-  backupdr.operations.get
-  backupdr.operations.list
Backup and DR Backup Vault Lister
( roles/  
)
Allows the Backup Appliance permission to list backup vaults in a given project.
 backupdr.backupVaults.list 
Backup and DR Backup Vault Viewer
( roles/  
)
Allows read-only permissions to access backup vault resources and backups.
 backupdr.backupVaults.get 
 backupdr.backupVaults.list 
 backupdr.bvbackups.get 
 backupdr.bvbackups.list 
 backupdr.bvdataSources.get 
 backupdr.bvdataSources.list 
 backupdr.operations.get 
 backupdr.operations.list 
Backup and DR Cloud SQL Operator Beta
( roles/  
)
Allows a Backup and DR service account to discover and backup Cloud SQL instances.
 cloudsql.  
 cloudsql.instances.get 
Backup and DR Cloud Storage Operator
( roles/  
)
Allows a Backup and DR service account to store and manage data (backups or metadata) in Cloud Storage.
 storage.buckets.create 
 storage.buckets.get 
 storage.objects.create 
 storage.objects.delete 
 storage.objects.get 
 storage.objects.list 
Backup and DR Compute Engine Operator
( roles/  
)
Allows a Backup and DR service account to discover, back up, and restore Compute Engine VM instances.
 backupdr.  
 compute.addresses.list 
 compute.addresses.use 
 compute.addresses.useInternal 
  compute.diskTypes.* 
 
-  compute.diskTypes.get
-  compute.diskTypes.list
 compute.disks.create 
 compute.disks.createSnapshot 
 compute.disks.delete 
 compute.disks.get 
 compute.disks.setLabels 
 compute.disks.use 
 compute.disks.useReadOnly 
 compute.firewalls.list 
 compute.globalOperations.get 
 compute.images.create 
 compute.images.delete 
 compute.images.get 
 compute.images.useReadOnly 
 compute.instances.attachDisk 
 compute.instances.create 
 compute.  
 compute.instances.delete 
 compute.instances.detachDisk 
 compute.instances.get 
 compute.instances.list 
 compute.  
 compute.  
 compute.  
 compute.instances.setLabels 
 compute.instances.setMetadata 
 compute.  
 compute.instances.setTags 
 compute.instances.start 
 compute.instances.stop 
 compute.  
 compute.instances.useReadOnly 
  compute.machineTypes.* 
 
-  compute.machineTypes.get
-  compute.machineTypes.list
 compute.networks.list 
 compute.nodeGroups.get 
 compute.nodeGroups.list 
 compute.nodeTemplates.get 
 compute.projects.get 
 compute.regionOperations.get 
  compute.regions.* 
 
-  compute.regions.get
-  compute.regions.list
 compute.resourcePolicies.use 
 compute.snapshots.create 
 compute.snapshots.delete 
 compute.snapshots.get 
 compute.snapshots.setLabels 
 compute.snapshots.useReadOnly 
 compute.subnetworks.list 
 compute.subnetworks.use 
 compute.  
 compute.zoneOperations.get 
 compute.zones.list 
 iam.serviceAccounts.actAs 
 iam.serviceAccounts.get 
 iam.serviceAccounts.list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and DR Disk Operator Beta
( roles/  
)
Allows a Backup and DR service account to store and manage data (backups or metadata) in Disk.
 compute.disks.create 
 compute.disks.createSnapshot 
 compute.disks.createTagBinding 
 compute.disks.get 
 compute.disks.list 
 compute.disks.setLabels 
 compute.disks.useReadOnly 
 compute.regionOperations.get 
 compute.resourcePolicies.use 
 compute.snapshots.setLabels 
 compute.snapshots.useReadOnly 
 compute.storagePools.use 
 compute.zoneOperations.get 
Backup and DR Management Server Accessor
( roles/  
)
Grants the Backup and DR management server access role to Backup Appliances.
 backupdr.  
Backup and DR Mount User
( roles/  
)
Allows the user to mount from a backup. This role cannot create a backup plan or restore from a backup.
  backupdr.locations.* 
 
-  backupdr.locations.get
-  backupdr.locations.list
 backupdr.  
 backupdr.managementServers.get 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.operations.get 
 backupdr.operations.list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and DR Restore User
( roles/  
)
Allows the user to restore or mount from a backup. This role cannot create a backup plan.
 backupdr.backupVaults.get 
 backupdr.backupVaults.list 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.bvbackups.get 
 backupdr.bvbackups.list 
 backupdr.bvbackups.restore 
 backupdr.  
 backupdr.  
 backupdr.bvdataSources.get 
 backupdr.bvdataSources.list 
 backupdr.  
 backupdr.  
 backupdr.  
  backupdr.  
 
-  backupdr.dataSourceReferences. fetchForAlloydbCluster 
-  backupdr.dataSourceReferences. fetchForCloudSqlInstance 
-  backupdr.dataSourceReferences. getForAlloydbCluster 
-  backupdr.dataSourceReferences. getForCloudSqlInstance 
-  backupdr.dataSourceReferences. list 
  backupdr.locations.* 
 
-  backupdr.locations.get
-  backupdr.locations.list
 backupdr.  
 backupdr.managementServers.get 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.operations.get 
 backupdr.operations.list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and DR Service Agent
( roles/  
)
Grants the Backup and DR Service access to protect Compute Engine instances.
 alloydb.operations.get 
 cloudsql.  
 cloudsql.instances.get 
 compute.addresses.list 
 compute.addresses.use 
 compute.addresses.useInternal 
  compute.diskTypes.* 
 
-  compute.diskTypes.get
-  compute.diskTypes.list
 compute.disks.create 
 compute.disks.createSnapshot 
 compute.disks.delete 
 compute.disks.get 
 compute.disks.list 
 compute.disks.setLabels 
 compute.disks.use 
 compute.disks.useReadOnly 
 compute.firewalls.list 
 compute.globalOperations.get 
 compute.images.create 
 compute.images.delete 
 compute.images.get 
 compute.images.useReadOnly 
 compute.instances.attachDisk 
 compute.instances.create 
 compute.instances.delete 
 compute.instances.detachDisk 
 compute.instances.get 
 compute.instances.list 
 compute.instances.setLabels 
 compute.instances.setMetadata 
 compute.  
 compute.instances.setTags 
 compute.instances.start 
 compute.instances.stop 
 compute.instances.useReadOnly 
  compute.machineTypes.* 
 
-  compute.machineTypes.get
-  compute.machineTypes.list
 compute.networks.list 
 compute.nodeGroups.get 
 compute.nodeGroups.list 
 compute.nodeTemplates.get 
 compute.projects.get 
 compute.regionOperations.get 
  compute.regions.* 
 
-  compute.regions.get
-  compute.regions.list
 compute.snapshots.create 
 compute.snapshots.delete 
 compute.snapshots.get 
 compute.snapshots.setLabels 
 compute.snapshots.useReadOnly 
 compute.subnetworks.list 
 compute.subnetworks.use 
 compute.  
 compute.zoneOperations.get 
 compute.zones.list 
 file.backups.create 
 file.instances.get 
 iam.serviceAccounts.actAs 
 iam.serviceAccounts.get 
 iam.serviceAccounts.list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and DR User
( roles/  
)
Provides access to management console. Granular Backup and DR permissions depend on ACL configuration provided by Backup and DR admin within the management console.
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.managementServers.get 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.operations.get 
 backupdr.operations.list 
 backupdr.trial.get 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and DR User V2
( roles/  
)
Provides full access to Backup and DR resources except deploying and managing backup infrastructure, expiring backups, changing data sensitivity and configuring on-premises billing.
  backupdr.  
 
-  backupdr.backupPlanAssociations. createForAlloydbCluster 
-  backupdr.backupPlanAssociations. createForCloudSqlInstance 
-  backupdr.backupPlanAssociations. createForComputeDisk 
-  backupdr.backupPlanAssociations. createForComputeInstance 
-  backupdr.backupPlanAssociations. deleteForAlloydbCluster 
-  backupdr.backupPlanAssociations. deleteForCloudSqlInstance 
-  backupdr.backupPlanAssociations. deleteForComputeDisk 
-  backupdr.backupPlanAssociations. deleteForComputeInstance 
-  backupdr.backupPlanAssociations. fetchForAlloydbCluster 
-  backupdr.backupPlanAssociations. fetchForCloudSqlInstance 
-  backupdr.backupPlanAssociations. fetchForComputeDisk 
-  backupdr.backupPlanAssociations. fetchForComputeInstance 
-  backupdr.backupPlanAssociations. getForAlloydbCluster 
-  backupdr.backupPlanAssociations. getForCloudSqlInstance 
-  backupdr.backupPlanAssociations. getForComputeDisk 
-  backupdr.backupPlanAssociations. getForComputeInstance 
-  backupdr.backupPlanAssociations. list 
-  backupdr.backupPlanAssociations. triggerBackupForAlloydbCluster 
-  backupdr.backupPlanAssociations. triggerBackupForCloudSqlInstance 
-  backupdr.backupPlanAssociations. triggerBackupForComputeDisk 
-  backupdr.backupPlanAssociations. triggerBackupForComputeInstance 
-  backupdr.backupPlanAssociations. updateForAlloydbCluster 
-  backupdr.backupPlanAssociations. updateForComputeDisk 
-  backupdr.backupPlanAssociations. updateForComputeInstance 
  backupdr.backupPlanRevisions.* 
 
-  backupdr.backupPlanRevisions. get 
-  backupdr.backupPlanRevisions. list 
  backupdr.backupPlans.* 
 
-  backupdr.backupPlans.create
-  backupdr.backupPlans.delete
-  backupdr.backupPlans.get
-  backupdr.backupPlans.list
-  backupdr.backupPlans.update
-  backupdr.backupPlans. useForAlloydbCluster 
-  backupdr.backupPlans. useForCloudSqlInstance 
-  backupdr.backupPlans. useForComputeDisk 
-  backupdr.backupPlans. useForComputeInstance 
 backupdr.  
 backupdr.backupVaults.get 
 backupdr.backupVaults.list 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.bvbackups.get 
 backupdr.bvbackups.list 
 backupdr.bvbackups.restore 
 backupdr.  
 backupdr.  
 backupdr.bvdataSources.get 
 backupdr.bvdataSources.list 
 backupdr.  
 backupdr.  
 backupdr.  
  backupdr.  
 
-  backupdr.dataSourceReferences. fetchForAlloydbCluster 
-  backupdr.dataSourceReferences. fetchForCloudSqlInstance 
-  backupdr.dataSourceReferences. getForAlloydbCluster 
-  backupdr.dataSourceReferences. getForCloudSqlInstance 
-  backupdr.dataSourceReferences. list 
  backupdr.locations.* 
 
-  backupdr.locations.get
-  backupdr.locations.list
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.managementServers.get 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.operations.get 
 backupdr.operations.list 
 backupdr.trial.get 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and DR Viewer
( roles/  
)
Provides read-only access to all Backup and DR resources.
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
  backupdr.backupPlanRevisions.* 
 
-  backupdr.backupPlanRevisions. get 
-  backupdr.backupPlanRevisions. list 
 backupdr.backupPlans.get 
 backupdr.backupPlans.list 
 backupdr.backupVaults.get 
 backupdr.backupVaults.list 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.bvbackups.get 
 backupdr.bvbackups.list 
 backupdr.bvdataSources.get 
 backupdr.bvdataSources.list 
  backupdr.  
 
-  backupdr.dataSourceReferences. fetchForAlloydbCluster 
-  backupdr.dataSourceReferences. fetchForCloudSqlInstance 
-  backupdr.dataSourceReferences. getForAlloydbCluster 
-  backupdr.dataSourceReferences. getForCloudSqlInstance 
-  backupdr.dataSourceReferences. list 
  backupdr.locations.* 
 
-  backupdr.locations.get
-  backupdr.locations.list
 backupdr.  
 backupdr.  
 backupdr.managementServers.get 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.operations.get 
 backupdr.operations.list 
 backupdr.trial.get 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Backup and Disaster Recovery permissions
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Databases Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Compute Storage Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Databases Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Compute Storage Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Compute Storage Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Compute Storage Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Databases Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Compute Storage Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Databases Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Compute Storage Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.backupPlans.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.backupPlans.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.backupPlans.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Databases Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.backupPlans.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Databases Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.backupPlans.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Databases Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Compute Storage Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.backupVaults.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 backupdr.backupVaults.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 backupdr.backupVaults.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Backup Vault Viewer 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Databases Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.backupVaults.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Backup Vault Lister 
( roles/  
)
 Backup and DR Backup Vault Viewer 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Databases Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.backupVaults.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 backupdr.bvbackups.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.bvbackups.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Backup Vault Viewer 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.bvbackups.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Backup Vault Viewer 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.bvbackups.restore 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.bvbackups.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Databases Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 backupdr.bvdataSources.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Backup Vault Viewer 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 backupdr.bvdataSources.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Backup Vault Viewer 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.bvdataSources.remove 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 backupdr.bvdataSources.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Databases Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.locations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.locations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Config Viewer 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Databases Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Compute Engine Operator 
( roles/  
)
 Backup and DR Management Server Accessor 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.managementServers.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 backupdr.  
 
 backupdr.  
 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.operations.cancel 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 backupdr.operations.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 backupdr.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Backup Vault Viewer 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Databases Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR Backup User 
( roles/  
)
 Backup and DR Backup Vault Accessor 
( roles/  
)
 Backup and DR Backup Vault Admin 
( roles/  
)
 Backup and DR Backup Vault Viewer 
( roles/  
)
 Backup and DR Mount User 
( roles/  
)
 Backup and DR Restore User 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Backup Config Viewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Backup Config Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 backupdr.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 AlloyDB Admin 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Compute Admin 
( roles/  
)
 Compute Instance Admin (beta) 
( roles/  
)
 Compute Instance Admin (v1) 
( roles/  
)
 Databases Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Notebooks Legacy Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  AI Platform Notebooks Service Agent 
( roles/)notebooks.serviceAgent 
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
 backupdr.trial.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Admin 
( roles/  
)
 Backup and DR User 
( roles/  
)
 Backup and DR User V2 
( roles/  
)
 Backup and DR Viewer 
( roles/  
)
 Support User 
( roles/  
)

