This page lists the IAM roles and permissions for Binary Authorization. To search through all roles and permissions, see the role and permission index .
Binary Authorization roles
Binaryauthorization Admin
( roles/
)
Admin role for binaryauthorization
binaryauthorization.*
-
binaryauthorization.attestors. create -
binaryauthorization.attestors. delete -
binaryauthorization.attestors. get -
binaryauthorization.attestors. getIamPolicy -
binaryauthorization.attestors. list -
binaryauthorization.attestors. setIamPolicy -
binaryauthorization.attestors. update -
binaryauthorization.attestors. verifyImageAttested -
binaryauthorization.continuousValidationConfig. get -
binaryauthorization.continuousValidationConfig. getIamPolicy -
binaryauthorization.continuousValidationConfig. setIamPolicy -
binaryauthorization.continuousValidationConfig. update -
binaryauthorization.platformPolicies. create -
binaryauthorization.platformPolicies. delete -
binaryauthorization.platformPolicies. evaluatePolicy -
binaryauthorization.platformPolicies. get -
binaryauthorization.platformPolicies. list -
binaryauthorization.platformPolicies. replace -
binaryauthorization.policy. evaluatePolicy -
binaryauthorization.policy.get -
binaryauthorization.policy. getIamPolicy -
binaryauthorization.policy. setIamPolicy -
binaryauthorization.policy. update
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Attestor Admin
( roles/
)
Administrator of Binary Authorization Attestors
binaryauthorization.
-
binaryauthorization.attestors. create -
binaryauthorization.attestors. delete -
binaryauthorization.attestors. get -
binaryauthorization.attestors. getIamPolicy -
binaryauthorization.attestors. list -
binaryauthorization.attestors. setIamPolicy -
binaryauthorization.attestors. update -
binaryauthorization.attestors. verifyImageAttested
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Attestor Editor
( roles/
)
Editor of Binary Authorization Attestors
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Attestor Image Verifier
( roles/
)
Caller of Binary Authorization Attestors VerifyImageAttested
binaryauthorization.
binaryauthorization.
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Attestor Viewer
( roles/
)
Viewer of Binary Authorization Attestors
binaryauthorization.
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binaryauthorization Editor
( roles/
)
Editor role for binaryauthorization
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
-
binaryauthorization.platformPolicies. create -
binaryauthorization.platformPolicies. delete -
binaryauthorization.platformPolicies. evaluatePolicy -
binaryauthorization.platformPolicies. get -
binaryauthorization.platformPolicies. list -
binaryauthorization.platformPolicies. replace
binaryauthorization.
binaryauthorization.policy.get
binaryauthorization.
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Policy Administrator
( roles/
)
Administrator of Binary Authorization Policy
binaryauthorization.
-
binaryauthorization.continuousValidationConfig. get -
binaryauthorization.continuousValidationConfig. getIamPolicy -
binaryauthorization.continuousValidationConfig. setIamPolicy -
binaryauthorization.continuousValidationConfig. update
binaryauthorization.
-
binaryauthorization.platformPolicies. create -
binaryauthorization.platformPolicies. delete -
binaryauthorization.platformPolicies. evaluatePolicy -
binaryauthorization.platformPolicies. get -
binaryauthorization.platformPolicies. list -
binaryauthorization.platformPolicies. replace
binaryauthorization.policy.*
-
binaryauthorization.policy. evaluatePolicy -
binaryauthorization.policy.get -
binaryauthorization.policy. getIamPolicy -
binaryauthorization.policy. setIamPolicy -
binaryauthorization.policy. update
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Policy Editor
( roles/
)
Editor of Binary Authorization Policy
binaryauthorization.
binaryauthorization.
binaryauthorization.
-
binaryauthorization.platformPolicies. create -
binaryauthorization.platformPolicies. delete -
binaryauthorization.platformPolicies. evaluatePolicy -
binaryauthorization.platformPolicies. get -
binaryauthorization.platformPolicies. list -
binaryauthorization.platformPolicies. replace
binaryauthorization.
binaryauthorization.policy.get
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Policy Evaluator
( roles/
)
Evaluator of Binary Authorization Policy
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.policy.get
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Policy Viewer
( roles/
)
Viewer of Binary Authorization Policy
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.policy.get
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Service Agent
( roles/
)
Can read Notes and Occurrences from the Container Analysis Service to find and verify signatures.
artifactregistry.
artifactregistry.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
cloudasset.
cloudasset.feeds.create
cloudasset.feeds.delete
cloudasset.feeds.get
cloudasset.feeds.update
containeranalysis.notes.get
containeranalysis.notes.list
containeranalysis.
containeranalysis.
containeranalysis.
resourcemanager.projects.get
resourcemanager.projects.list
storage.objects.list
Binaryauthorization Viewer
( roles/
)
Viewer role for binaryauthorization
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.policy.get
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization permissions
binaryauthorization.
attestors.
create
Owner
( roles/
)
Editor
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binaryauthorization Editor
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
attestors.
delete
Owner
( roles/
)
Editor
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binaryauthorization Editor
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
attestors.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binary Authorization Attestor Image Verifier
( roles/
)
Binary Authorization Attestor Viewer
( roles/
)
Binaryauthorization Editor
( roles/
)
Binaryauthorization Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent - Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent
binaryauthorization.
attestors.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binaryauthorization Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
binaryauthorization.
attestors.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binary Authorization Attestor Image Verifier
( roles/
)
Binary Authorization Attestor Viewer
( roles/
)
Binaryauthorization Editor
( roles/
)
Binaryauthorization Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent - Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent
binaryauthorization.
attestors.
setIamPolicy
Owner
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Security Admin
( roles/
)
binaryauthorization.
attestors.
update
Owner
( roles/
)
Editor
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binaryauthorization Editor
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
attestors.
verifyImageAttested
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binary Authorization Attestor Image Verifier
( roles/
)
Binaryauthorization Editor
( roles/
)
Binaryauthorization Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent - Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent
binaryauthorization.
continuousValidationConfig.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Viewer
( roles/
)
Binaryauthorization Viewer
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
binaryauthorization.
continuousValidationConfig.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binaryauthorization Viewer
( roles/
)
Dev Ops
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
binaryauthorization.
continuousValidationConfig.
setIamPolicy
Owner
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Dev Ops
( roles/
)
Security Admin
( roles/
)
binaryauthorization.
continuousValidationConfig.
update
Owner
( roles/
)
Editor
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
platformPolicies.
create
Owner
( roles/
)
Editor
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
platformPolicies.
delete
Owner
( roles/
)
Editor
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
platformPolicies.
evaluatePolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Binaryauthorization Viewer
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent - Cloud Run Service Agent
(
roles/)run.serviceAgent - Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent
binaryauthorization.
platformPolicies.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Binary Authorization Policy Viewer
( roles/
)
Binaryauthorization Viewer
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent
binaryauthorization.
platformPolicies.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Binary Authorization Policy Viewer
( roles/
)
Binaryauthorization Viewer
( roles/
)
Dev Ops
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent
binaryauthorization.
platformPolicies.
replace
Owner
( roles/
)
Editor
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
policy.
evaluatePolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Binaryauthorization Viewer
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
Service agent roles
- Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent - Cloud Run Service Agent
(
roles/)run.serviceAgent - Vertex AI Service Agent
(
roles/)aiplatform.serviceAgent
binaryauthorization.policy.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Binary Authorization Policy Viewer
( roles/
)
Binaryauthorization Viewer
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent - Security Center Control Service Agent
(
roles/)securitycenter.controlServiceAgent - Security Health Analytics Service Agent
(
roles/)securitycenter.securityHealthAnalyticsServiceAgent - Security Center Service Agent
(
roles/)securitycenter.serviceAgent - Audit Manager Auditing Service Agent
(
roles/)auditmanager.serviceAgent
binaryauthorization.
policy.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binaryauthorization Viewer
( roles/
)
Dev Ops
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
binaryauthorization.
policy.
setIamPolicy
Owner
( roles/
)
Binaryauthorization Admin
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Dev Ops
( roles/
)
Security Admin
( roles/
)
binaryauthorization.
policy.
update
Owner
( roles/
)
Editor
( roles/
)
Binaryauthorization Admin
( roles/
)
Binaryauthorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)

