This page lists the IAM roles and permissions for Cloud SQL. To search through all roles and permissions, see the role and permission index .
Cloud SQL roles
Cloud SQL Admin
( roles/  
)
Provides full control of Cloud SQL resources.
Lowest-level resources where you can grant this role:
- Project
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.backupPlans.get 
 backupdr.backupPlans.list 
 backupdr.  
 backupdr.backupVaults.get 
 backupdr.backupVaults.list 
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.  
 backupdr.locations.list 
 backupdr.operations.get 
 backupdr.  
  cloudaicompanion.companions.* 
 
-  cloudaicompanion.companions. generateChat 
-  cloudaicompanion.companions. generateCode 
 cloudaicompanion.  
 cloudaicompanion.  
 cloudaicompanion.  
  cloudkms.keyHandles.* 
 
-  cloudkms.keyHandles.create
-  cloudkms.keyHandles.get
-  cloudkms.keyHandles.list
 cloudkms.operations.get 
 cloudkms.  
  cloudsql.* 
 
-  cloudsql.backupRuns.create
-  cloudsql.backupRuns.delete
-  cloudsql.backupRuns.export
-  cloudsql.backupRuns.get
-  cloudsql.backupRuns.list
-  cloudsql.backupRuns.update
-  cloudsql.databases.create
-  cloudsql.databases.delete
-  cloudsql.databases.get
-  cloudsql.databases.list
-  cloudsql.databases.update
-  cloudsql.instances.addServerCa
-  cloudsql.instances. addServerCertificate 
-  cloudsql.instances.clone
-  cloudsql.instances.connect
-  cloudsql.instances.create
-  cloudsql.instances. createBackupDrBackup 
-  cloudsql.instances. createTagBinding 
-  cloudsql.instances.delete
-  cloudsql.instances. deleteTagBinding 
-  cloudsql.instances. demoteMaster 
-  cloudsql.instances.executeSql
-  cloudsql.instances.export
-  cloudsql.instances.failover
-  cloudsql.instances.get
-  cloudsql.instances. getDiskShrinkConfig 
-  cloudsql.instances.import
-  cloudsql.instances.list
-  cloudsql.instances. listEffectiveTags 
-  cloudsql.instances. listServerCas 
-  cloudsql.instances. listServerCertificates 
-  cloudsql.instances. listTagBindings 
-  cloudsql.instances.login
-  cloudsql.instances. manageEncryption 
-  cloudsql.instances.migrate
-  cloudsql.instances. performDiskShrink 
-  cloudsql.instances. preCheckMajorVersionUpgrade 
-  cloudsql.instances. promoteReplica 
-  cloudsql.instances.reencrypt
-  cloudsql.instances. resetReplicaSize 
-  cloudsql.instances. resetSslConfig 
-  cloudsql.instances.restart
-  cloudsql.instances. restoreBackup 
-  cloudsql.instances. rotateServerCa 
-  cloudsql.instances. rotateServerCertificate 
-  cloudsql.instances. startReplica 
-  cloudsql.instances.stopReplica
-  cloudsql.instances.truncateLog
-  cloudsql.instances.update
-  cloudsql.instances. updateBackupDrConfig 
-  cloudsql.schemas.view
-  cloudsql.sslCerts.create
-  cloudsql.sslCerts.delete
-  cloudsql.sslCerts.get
-  cloudsql.sslCerts.list
-  cloudsql.users.create
-  cloudsql.users.delete
-  cloudsql.users.get
-  cloudsql.users.list
-  cloudsql.users.update
  databasesconsole.locations.* 
 
-  databasesconsole.locations.get
-  databasesconsole.locations. list 
  databasesconsole.  
 
-  databasesconsole.studioQueries. create 
-  databasesconsole.studioQueries. delete 
-  databasesconsole.studioQueries. get 
-  databasesconsole.studioQueries. list 
-  databasesconsole.studioQueries. search 
-  databasesconsole.studioQueries. update 
  recommender.  
 
-  recommender.cloudsqlIdleInstanceRecommendations. get 
-  recommender.cloudsqlIdleInstanceRecommendations. list 
-  recommender.cloudsqlIdleInstanceRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstanceActivityInsights. get 
-  recommender.cloudsqlInstanceActivityInsights. list 
-  recommender.cloudsqlInstanceActivityInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceCpuUsageInsights. get 
-  recommender.cloudsqlInstanceCpuUsageInsights. list 
-  recommender.cloudsqlInstanceCpuUsageInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceDiskUsageTrendInsights. get 
-  recommender.cloudsqlInstanceDiskUsageTrendInsights. list 
-  recommender.cloudsqlInstanceDiskUsageTrendInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceMemoryUsageInsights. get 
-  recommender.cloudsqlInstanceMemoryUsageInsights. list 
-  recommender.cloudsqlInstanceMemoryUsageInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceOomProbabilityInsights. get 
-  recommender.cloudsqlInstanceOomProbabilityInsights. list 
-  recommender.cloudsqlInstanceOomProbabilityInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceOutOfDiskRecommendations. get 
-  recommender.cloudsqlInstanceOutOfDiskRecommendations. list 
-  recommender.cloudsqlInstanceOutOfDiskRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstancePerformanceInsights. get 
-  recommender.cloudsqlInstancePerformanceInsights. list 
-  recommender.cloudsqlInstancePerformanceInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstancePerformanceRecommendations. get 
-  recommender.cloudsqlInstancePerformanceRecommendations. list 
-  recommender.cloudsqlInstancePerformanceRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstanceReliabilityInsights. get 
-  recommender.cloudsqlInstanceReliabilityInsights. list 
-  recommender.cloudsqlInstanceReliabilityInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceReliabilityRecommendations. get 
-  recommender.cloudsqlInstanceReliabilityRecommendations. list 
-  recommender.cloudsqlInstanceReliabilityRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstanceSecurityInsights. get 
-  recommender.cloudsqlInstanceSecurityInsights. list 
-  recommender.cloudsqlInstanceSecurityInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceSecurityRecommendations. get 
-  recommender.cloudsqlInstanceSecurityRecommendations. list 
-  recommender.cloudsqlInstanceSecurityRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstanceUnderprovisionedCpuUsageInsights. get 
-  recommender.cloudsqlInstanceUnderprovisionedCpuUsageInsights. list 
-  recommender.cloudsqlInstanceUnderprovisionedCpuUsageInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceUnderprovisionedMemoryUsageInsights. get 
-  recommender.cloudsqlInstanceUnderprovisionedMemoryUsageInsights. list 
-  recommender.cloudsqlInstanceUnderprovisionedMemoryUsageInsights. update 
  recommender.  
 
-  recommender.cloudsqlOverprovisionedInstanceRecommendations. get 
-  recommender.cloudsqlOverprovisionedInstanceRecommendations. list 
-  recommender.cloudsqlOverprovisionedInstanceRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlUnderProvisionedInstanceRecommendations. get 
-  recommender.cloudsqlUnderProvisionedInstanceRecommendations. list 
-  recommender.cloudsqlUnderProvisionedInstanceRecommendations. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 serviceusage.quotas.get 
 serviceusage.services.get 
 serviceusage.services.list 
Cloud SQL Client
( roles/  
)
Provides connectivity access to Cloud SQL instances.
Lowest-level resources where you can grant this role:
- Project
 cloudsql.instances.connect 
 cloudsql.instances.get 
Cloud SQL Editor
( roles/  
)
Provides full control of existing Cloud SQL instances excluding modifying users, SSL certificates or deleting resources.
Lowest-level resources where you can grant this role:
- Project
 cloudaicompanion.  
 cloudsql.backupRuns.create 
 cloudsql.backupRuns.export 
 cloudsql.backupRuns.get 
 cloudsql.backupRuns.list 
 cloudsql.backupRuns.update 
 cloudsql.databases.create 
 cloudsql.databases.get 
 cloudsql.databases.list 
 cloudsql.databases.update 
 cloudsql.instances.addServerCa 
 cloudsql.  
 cloudsql.instances.connect 
 cloudsql.instances.export 
 cloudsql.instances.failover 
 cloudsql.instances.get 
 cloudsql.  
 cloudsql.instances.list 
 cloudsql.  
 cloudsql.  
 cloudsql.  
 cloudsql.  
 cloudsql.instances.migrate 
 cloudsql.  
 cloudsql.  
 cloudsql.instances.reencrypt 
 cloudsql.  
 cloudsql.instances.restart 
 cloudsql.  
 cloudsql.  
 cloudsql.instances.truncateLog 
 cloudsql.instances.update 
 cloudsql.schemas.view 
 cloudsql.sslCerts.get 
 cloudsql.sslCerts.list 
 cloudsql.users.get 
 cloudsql.users.list 
  recommender.  
 
-  recommender.cloudsqlIdleInstanceRecommendations. get 
-  recommender.cloudsqlIdleInstanceRecommendations. list 
-  recommender.cloudsqlIdleInstanceRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstanceActivityInsights. get 
-  recommender.cloudsqlInstanceActivityInsights. list 
-  recommender.cloudsqlInstanceActivityInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceCpuUsageInsights. get 
-  recommender.cloudsqlInstanceCpuUsageInsights. list 
-  recommender.cloudsqlInstanceCpuUsageInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceDiskUsageTrendInsights. get 
-  recommender.cloudsqlInstanceDiskUsageTrendInsights. list 
-  recommender.cloudsqlInstanceDiskUsageTrendInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceMemoryUsageInsights. get 
-  recommender.cloudsqlInstanceMemoryUsageInsights. list 
-  recommender.cloudsqlInstanceMemoryUsageInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceOomProbabilityInsights. get 
-  recommender.cloudsqlInstanceOomProbabilityInsights. list 
-  recommender.cloudsqlInstanceOomProbabilityInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceOutOfDiskRecommendations. get 
-  recommender.cloudsqlInstanceOutOfDiskRecommendations. list 
-  recommender.cloudsqlInstanceOutOfDiskRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstancePerformanceInsights. get 
-  recommender.cloudsqlInstancePerformanceInsights. list 
-  recommender.cloudsqlInstancePerformanceInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstancePerformanceRecommendations. get 
-  recommender.cloudsqlInstancePerformanceRecommendations. list 
-  recommender.cloudsqlInstancePerformanceRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstanceReliabilityInsights. get 
-  recommender.cloudsqlInstanceReliabilityInsights. list 
-  recommender.cloudsqlInstanceReliabilityInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceReliabilityRecommendations. get 
-  recommender.cloudsqlInstanceReliabilityRecommendations. list 
-  recommender.cloudsqlInstanceReliabilityRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlInstanceUnderprovisionedCpuUsageInsights. get 
-  recommender.cloudsqlInstanceUnderprovisionedCpuUsageInsights. list 
-  recommender.cloudsqlInstanceUnderprovisionedCpuUsageInsights. update 
  recommender.  
 
-  recommender.cloudsqlInstanceUnderprovisionedMemoryUsageInsights. get 
-  recommender.cloudsqlInstanceUnderprovisionedMemoryUsageInsights. list 
-  recommender.cloudsqlInstanceUnderprovisionedMemoryUsageInsights. update 
  recommender.  
 
-  recommender.cloudsqlOverprovisionedInstanceRecommendations. get 
-  recommender.cloudsqlOverprovisionedInstanceRecommendations. list 
-  recommender.cloudsqlOverprovisionedInstanceRecommendations. update 
  recommender.  
 
-  recommender.cloudsqlUnderProvisionedInstanceRecommendations. get 
-  recommender.cloudsqlUnderProvisionedInstanceRecommendations. list 
-  recommender.cloudsqlUnderProvisionedInstanceRecommendations. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 serviceusage.quotas.get 
 serviceusage.services.get 
 serviceusage.services.list 
Cloud SQL Instance User
( roles/  
)
Role allowing access to a Cloud SQL instance
 cloudsql.instances.executeSql 
 cloudsql.instances.get 
 cloudsql.instances.login 
Cloud SQL Schema Viewer
( roles/  
)
Role allowing access to the Cloud SQL instance schema on Dataplex
 cloudsql.schemas.view 
Cloud SQL Service Agent
( roles/  
)
Grants Cloud SQL access to services and APIs in the user project
 cloudsql.instances.get 
Cloud SQL Studio User
( roles/  
)
Role allowing access to Cloud SQL Studio
  cloudaicompanion.companions.* 
 
-  cloudaicompanion.companions. generateChat 
-  cloudaicompanion.companions. generateCode 
 cloudaicompanion.  
 cloudaicompanion.  
 cloudsql.databases.list 
 cloudsql.instances.executeSql 
 cloudsql.instances.get 
 cloudsql.instances.login 
 cloudsql.users.list 
  databasesconsole.locations.* 
 
-  databasesconsole.locations.get
-  databasesconsole.locations. list 
 databasesconsole.  
Cloud SQL Viewer
( roles/  
)
Provides read-only access to Cloud SQL resources.
Lowest-level resources where you can grant this role:
- Project
 cloudaicompanion.  
 cloudsql.backupRuns.export 
 cloudsql.backupRuns.get 
 cloudsql.backupRuns.list 
 cloudsql.databases.get 
 cloudsql.databases.list 
 cloudsql.instances.export 
 cloudsql.instances.get 
 cloudsql.  
 cloudsql.instances.list 
 cloudsql.  
 cloudsql.  
 cloudsql.  
 cloudsql.  
 cloudsql.  
 cloudsql.sslCerts.get 
 cloudsql.sslCerts.list 
 cloudsql.users.get 
 cloudsql.users.list 
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 serviceusage.quotas.get 
 serviceusage.services.get 
 serviceusage.services.list 
Cloud SQL permissions
 cloudsql.backupRuns.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.backupRuns.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.backupRuns.export 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.backupRuns.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.backupRuns.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.backupRuns.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.databases.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Firebase Data Connect Service Agent 
( roles/)firebasedataconnect.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.databases.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.databases.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Discovery Engine Service Agent 
( roles/)discoveryengine.serviceAgent 
-  Firebase Data Connect Service Agent 
( roles/)firebasedataconnect.serviceAgent 
-  Serverless Integrations Service Agent 
( roles/)runapps.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.databases.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Studio User 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.databases.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.instances.addServerCa 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.clone 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.connect 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Client 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Dataproc Metastore Managed Migration Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Firebase Data Connect Service Agent 
( roles/)firebasedataconnect.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Health Analytics Service Agent 
( roles/)securitycenter.securityHealthAnalyticsServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  BigQuery Connection Service Agent 
( roles/)bigqueryconnection.serviceAgent 
 cloudsql.instances.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Cloud SQL Operator 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Backup and DR Service Agent 
( roles/)backupdr.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.executeSql 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Instance User 
( roles/  
)
 Cloud SQL Studio User 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.export 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Discovery Engine Service Agent 
( roles/)discoveryengine.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.failover 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Backup and DR Cloud SQL Operator 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Client 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Instance User 
( roles/  
)
 Cloud SQL Studio User 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Managed Migration Admin 
( roles/  
)
Service agent roles
-  Backup and DR Service Agent 
( roles/)backupdr.serviceAgent 
-  BigQuery Connection Service Agent 
( roles/)bigqueryconnection.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
-  Cloud SQL Service Agent 
( roles/)cloudsql.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Discovery Engine Service Agent 
( roles/)discoveryengine.serviceAgent 
-  Firebase Data Connect Service Agent 
( roles/)firebasedataconnect.serviceAgent 
-  GCP Network Management Service Agent 
( roles/)networkmanagement.serviceAgent 
-  Serverless Integrations Service Agent 
( roles/)runapps.serviceAgent 
-  Audit Manager Auditing Service Agent 
( roles/)auditmanager.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.import 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.instances.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  GCP Network Management Service Agent 
( roles/)networkmanagement.serviceAgent 
-  Audit Manager Auditing Service Agent 
( roles/)auditmanager.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.login 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Instance User 
( roles/  
)
 Cloud SQL Studio User 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dataproc Metastore Managed Migration Admin 
( roles/  
)
Service agent roles
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Firebase Data Connect Service Agent 
( roles/)firebasedataconnect.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.migrate 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.reencrypt 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.restart 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.stopReplica 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.truncateLog 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.instances.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.schemas.view 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Schema Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.sslCerts.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.sslCerts.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.sslCerts.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.sslCerts.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.users.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Firebase Data Connect Service Agent 
( roles/)firebasedataconnect.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.users.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 cloudsql.users.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Firebase Data Connect Service Agent 
( roles/)firebasedataconnect.serviceAgent 
-  Serverless Integrations Service Agent 
( roles/)runapps.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.users.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Cloud SQL Editor 
( roles/  
)
 Cloud SQL Studio User 
( roles/  
)
 Cloud SQL Viewer 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Health Analytics Service Agent 
( roles/)securitycenter.securityHealthAnalyticsServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 cloudsql.users.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud SQL Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 

