This page lists the IAM roles and permissions for Cloud Trace. To search through all roles and permissions, see the role and permission index .
Cloud Trace roles
Cloud Trace Admin
( roles/  
)
Provides full access to the Trace console and read-write access to traces.
Lowest-level resources where you can grant this role:
- Project
  cloudtrace.* 
 
-  cloudtrace.insights.get
-  cloudtrace.insights.list
-  cloudtrace.stats.get
-  cloudtrace.tasks.create
-  cloudtrace.tasks.delete
-  cloudtrace.tasks.get
-  cloudtrace.tasks.list
-  cloudtrace.traceScopes.create
-  cloudtrace.traceScopes.delete
-  cloudtrace.traceScopes.get
-  cloudtrace.traceScopes.list
-  cloudtrace.traceScopes.update
-  cloudtrace.traces.get
-  cloudtrace.traces.list
-  cloudtrace.traces.patch
 observability.scopes.get 
  observability.traceScopes.* 
 
-  observability.traceScopes. create 
-  observability.traceScopes. delete 
-  observability.traceScopes.get
-  observability.traceScopes.list
-  observability.traceScopes. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 telemetry.traces.write 
Cloud Trace Agent
( roles/  
)
For service accounts. Provides ability to write traces by sending the data to Stackdriver Trace.
Lowest-level resources where you can grant this role:
- Project
 cloudtrace.traces.patch 
 telemetry.traces.write 
Cloud Trace User
( roles/  
)
Provides full access to the Trace console and read access to traces.
Lowest-level resources where you can grant this role:
- Project
  cloudtrace.insights.* 
 
-  cloudtrace.insights.get
-  cloudtrace.insights.list
 cloudtrace.stats.get 
  cloudtrace.tasks.* 
 
-  cloudtrace.tasks.create
-  cloudtrace.tasks.delete
-  cloudtrace.tasks.get
-  cloudtrace.tasks.list
  cloudtrace.traceScopes.* 
 
-  cloudtrace.traceScopes.create
-  cloudtrace.traceScopes.delete
-  cloudtrace.traceScopes.get
-  cloudtrace.traceScopes.list
-  cloudtrace.traceScopes.update
 cloudtrace.traces.get 
 cloudtrace.traces.list 
 observability.scopes.get 
  observability.traceScopes.* 
 
-  observability.traceScopes. create 
-  observability.traceScopes. delete 
-  observability.traceScopes.get
-  observability.traceScopes.list
-  observability.traceScopes. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Cloud Trace permissions
 cloudtrace.insights.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.insights.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.stats.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.tasks.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.tasks.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 cloudtrace.tasks.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.tasks.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.traceScopes.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 cloudtrace.traceScopes.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 cloudtrace.traceScopes.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.traceScopes.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.traceScopes.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 cloudtrace.traces.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.traces.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 cloudtrace.traces.patch 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace Agent 
( roles/  
)
 Firebase App Hosting Compute Runner 
( roles/  
)
Service agent roles
-  Apigee Service Agent 
( roles/)apigee.serviceAgent 
-  KubeRun Events Data Plane Service Agent 
( roles/)kuberun.eventsDataPlaneServiceAgent 
-  Mesh Data Plane Service Agent 
( roles/)meshdataplane.serviceAgent 
-  Monitoring Service Agent 
( roles/)monitoring.notificationServiceAgent 
-  Vertex AI Reasoning Engine Service Agent 
( roles/)aiplatform.reasoningEngineServiceAgent 

