This page lists the IAM roles and permissions for Binary Authorization. To search through all roles and permissions, see the role and permission index .
Binary Authorization roles
Binary Authorization Attestor Admin
( roles/  
)
Administrator of Binary Authorization Attestors
  binaryauthorization.  
 
-  binaryauthorization.attestors. create 
-  binaryauthorization.attestors. delete 
-  binaryauthorization.attestors. get 
-  binaryauthorization.attestors. getIamPolicy 
-  binaryauthorization.attestors. list 
-  binaryauthorization.attestors. setIamPolicy 
-  binaryauthorization.attestors. update 
-  binaryauthorization.attestors. verifyImageAttested 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Binary Authorization Attestor Editor
( roles/  
)
Editor of Binary Authorization Attestors
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Binary Authorization Attestor Image Verifier
( roles/  
)
Caller of Binary Authorization Attestors VerifyImageAttested
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Binary Authorization Attestor Viewer
( roles/  
)
Viewer of Binary Authorization Attestors
 binaryauthorization.  
 binaryauthorization.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Binary Authorization Policy Administrator
( roles/  
)
Administrator of Binary Authorization Policy
  binaryauthorization.  
 
-  binaryauthorization.continuousValidationConfig. get 
-  binaryauthorization.continuousValidationConfig. getIamPolicy 
-  binaryauthorization.continuousValidationConfig. setIamPolicy 
-  binaryauthorization.continuousValidationConfig. update 
  binaryauthorization.  
 
-  binaryauthorization.platformPolicies. create 
-  binaryauthorization.platformPolicies. delete 
-  binaryauthorization.platformPolicies. evaluatePolicy 
-  binaryauthorization.platformPolicies. get 
-  binaryauthorization.platformPolicies. list 
-  binaryauthorization.platformPolicies. replace 
  binaryauthorization.policy.* 
 
-  binaryauthorization.policy. evaluatePolicy 
-  binaryauthorization.policy.get
-  binaryauthorization.policy. getIamPolicy 
-  binaryauthorization.policy. setIamPolicy 
-  binaryauthorization.policy. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Binary Authorization Policy Editor
( roles/  
)
Editor of Binary Authorization Policy
 binaryauthorization.  
 binaryauthorization.  
  binaryauthorization.  
 
-  binaryauthorization.platformPolicies. create 
-  binaryauthorization.platformPolicies. delete 
-  binaryauthorization.platformPolicies. evaluatePolicy 
-  binaryauthorization.platformPolicies. get 
-  binaryauthorization.platformPolicies. list 
-  binaryauthorization.platformPolicies. replace 
 binaryauthorization.  
 binaryauthorization.policy.get 
 binaryauthorization.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Binary Authorization Policy Evaluator
( roles/  
)
Evaluator of Binary Authorization Policy
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.policy.get 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Binary Authorization Policy Viewer
( roles/  
)
Viewer of Binary Authorization Policy
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.policy.get 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Binary Authorization Service Agent
( roles/  
)
Can read Notes and Occurrences from the Container Analysis Service to find and verify signatures.
 artifactregistry.  
 artifactregistry.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 binaryauthorization.  
 cloudasset.  
 cloudasset.feeds.create 
 cloudasset.feeds.delete 
 cloudasset.feeds.get 
 cloudasset.feeds.update 
 containeranalysis.notes.get 
 containeranalysis.notes.list 
 containeranalysis.  
 containeranalysis.  
 containeranalysis.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 storage.objects.list 
Binary Authorization permissions
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Binary Authorization Attestor Admin 
( roles/  
)
 Binary Authorization Attestor Editor 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Binary Authorization Attestor Admin 
( roles/  
)
 Binary Authorization Attestor Editor 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Attestor Admin 
( roles/  
)
 Binary Authorization Attestor Editor 
( roles/  
)
 Binary Authorization Attestor Image Verifier 
( roles/  
)
 Binary Authorization Attestor Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Binary Authorization Service Agent 
( roles/)binaryauthorization.serviceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Attestor Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Attestor Admin 
( roles/  
)
 Binary Authorization Attestor Editor 
( roles/  
)
 Binary Authorization Attestor Image Verifier 
( roles/  
)
 Binary Authorization Attestor Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Binary Authorization Service Agent 
( roles/)binaryauthorization.serviceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Binary Authorization Attestor Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Binary Authorization Attestor Admin 
( roles/  
)
 Binary Authorization Attestor Editor 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Attestor Admin 
( roles/  
)
 Binary Authorization Attestor Editor 
( roles/  
)
 Binary Authorization Attestor Image Verifier 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Binary Authorization Service Agent 
( roles/)binaryauthorization.serviceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Binary Authorization Policy Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Support User 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Binary Authorization Policy Evaluator 
( roles/  
)
 Dev Ops 
( roles/  
)
 Support User 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
Service agent roles
-  Anthos Multi-Cloud Container Service Agent 
( roles/)gkemulticloud.containerServiceAgent 
-  Cloud Run Service Agent 
( roles/)run.serviceAgent 
-  Binary Authorization Service Agent 
( roles/)binaryauthorization.serviceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Binary Authorization Policy Evaluator 
( roles/  
)
 Binary Authorization Policy Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Anthos Multi-Cloud Container Service Agent 
( roles/)gkemulticloud.containerServiceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Binary Authorization Policy Evaluator 
( roles/  
)
 Binary Authorization Policy Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Anthos Multi-Cloud Container Service Agent 
( roles/)gkemulticloud.containerServiceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Binary Authorization Policy Evaluator 
( roles/  
)
 Dev Ops 
( roles/  
)
 Support User 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Anthos Multi-Cloud Container Service Agent 
( roles/)gkemulticloud.containerServiceAgent 
-  Cloud Run Service Agent 
( roles/)run.serviceAgent 
-  Binary Authorization Service Agent 
( roles/)binaryauthorization.serviceAgent 
 binaryauthorization.policy.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Binary Authorization Policy Evaluator 
( roles/  
)
 Binary Authorization Policy Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Health Analytics Service Agent 
( roles/)securitycenter.securityHealthAnalyticsServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Anthos Multi-Cloud Container Service Agent 
( roles/)gkemulticloud.containerServiceAgent 
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 binaryauthorization.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Binary Authorization Policy Administrator 
( roles/  
)
 Binary Authorization Policy Editor 
( roles/  
)
 Dev Ops 
( roles/  
)

