This page lists the IAM roles and permissions for Cloud Config Manager API. To search through all roles and permissions, see the role and permission index .
Cloud Config Manager API roles
Cloud Infrastructure Manager Admin Beta
( roles/  
)
Full access to Cloud Infrastructure Manager resources.
  config.* 
 
-  config.artifacts.import
-  config.deployments.create
-  config.deployments.delete
-  config.deployments.deleteState
-  config.deployments.get
-  config.deployments. getIamPolicy 
-  config.deployments.getLock
-  config.deployments.getState
-  config.deployments.list
-  config.deployments.lock
-  config.deployments. setIamPolicy 
-  config.deployments.unlock
-  config.deployments.update
-  config.deployments.updateState
-  config.locations.get
-  config.locations.list
-  config.operations.cancel
-  config.operations.delete
-  config.operations.get
-  config.operations.list
-  config.previews.create
-  config.previews.delete
-  config.previews.export
-  config.previews.get
-  config.previews.list
-  config.previews.upload
-  config.resourcechanges.get
-  config.resourcechanges.list
-  config.resourcedrifts.get
-  config.resourcedrifts.list
-  config.resources.get
-  config.resources.list
-  config.revisions.get
-  config.revisions.getState
-  config.revisions.list
-  config.terraformversions.get
-  config.terraformversions.list
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Cloud Infrastructure Manager Agent Beta
( roles/  
)
Required permissions to make Cloud Infrastructure Manager work with the user-specified service account
 cloudbuild.connections.list 
 cloudbuild.  
 cloudbuild.repositories.list 
 cloudquotas.quotas.get 
 config.artifacts.import 
 config.deployments.deleteState 
 config.deployments.getLock 
 config.deployments.getState 
 config.deployments.updateState 
 config.previews.upload 
 config.revisions.getState 
 logging.logEntries.create 
 monitoring.timeSeries.list 
 storage.buckets.create 
 storage.buckets.delete 
 storage.buckets.get 
 storage.buckets.list 
 storage.buckets.update 
 storage.objects.create 
 storage.objects.delete 
 storage.objects.get 
 storage.objects.list 
 storage.objects.update 
Cloud Infrastructure Manager Viewer Beta
( roles/  
)
Read-only access to Cloud Infrastructure Manager resources.
 config.deployments.get 
 config.  
 config.deployments.list 
  config.locations.* 
 
-  config.locations.get
-  config.locations.list
 config.operations.get 
 config.operations.list 
 config.previews.get 
 config.previews.list 
  config.resources.* 
 
-  config.resources.get
-  config.resources.list
 config.revisions.get 
 config.revisions.list 
  config.terraformversions.* 
 
-  config.terraformversions.get
-  config.terraformversions.list
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Cloud Config Manager API permissions
 config.artifacts.import 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Agent 
( roles/  
)
 config.deployments.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  SaaS Service Management Service Agent 
( roles/)saasservicemgmt.serviceAgent 
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.deployments.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  SaaS Service Management Service Agent 
( roles/)saasservicemgmt.serviceAgent 
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.deployments.deleteState 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Agent 
( roles/  
)
 config.deployments.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  SaaS Service Management Service Agent 
( roles/)saasservicemgmt.serviceAgent 
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 config.deployments.getLock 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Agent 
( roles/  
)
 config.deployments.getState 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Agent 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.deployments.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.deployments.lock 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.  
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 config.deployments.unlock 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.deployments.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  SaaS Service Management Service Agent 
( roles/)saasservicemgmt.serviceAgent 
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.deployments.updateState 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Agent 
( roles/  
)
 config.locations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.locations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.operations.cancel 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.operations.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  SaaS Service Management Service Agent 
( roles/)saasservicemgmt.serviceAgent 
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.previews.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.previews.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.previews.export 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 config.previews.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.previews.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.previews.upload 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Agent 
( roles/  
)
 config.resourcechanges.get 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 config.resourcechanges.list 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 config.resourcedrifts.get 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 config.resourcedrifts.list 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 config.resources.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.resources.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.revisions.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  SaaS Service Management Service Agent 
( roles/)saasservicemgmt.serviceAgent 
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.revisions.getState 
 
 Owner 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Agent 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.revisions.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Workload Manager Service Agent 
( roles/)workloadmanager.serviceAgent 
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.terraformversions.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 
 config.terraformversions.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 App Management Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Infrastructure Manager Admin 
( roles/  
)
 Cloud Infrastructure Manager Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Admin 
( roles/  
)
 Application Editor 
( roles/  
)
 Application Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DesignCenter Service Agent 
( roles/)designcenter.serviceAgent 

