This page lists the IAM roles and permissions for Data Catalog. To search through all roles and permissions, see the role and permission index .
Data Catalog roles
Data Catalog Admin
( roles/  
)
Full access to all DataCatalog resources
 bigquery.connections.get 
 bigquery.connections.updateTag 
 bigquery.datasets.get 
 bigquery.datasets.updateTag 
 bigquery.models.getMetadata 
 bigquery.models.updateTag 
 bigquery.routines.get 
 bigquery.routines.updateTag 
 bigquery.tables.get 
 bigquery.tables.updateTag 
 datacatalog.catalogs.searchAll 
 datacatalog.  
 datacatalog.  
  datacatalog.entries.* 
 
-  datacatalog.entries.create
-  datacatalog.entries. createGlossary 
-  datacatalog.entries. createGlossaryCategory 
-  datacatalog.entries. createGlossaryTerm 
-  datacatalog.entries.delete
-  datacatalog.entries. deleteGlossary 
-  datacatalog.entries. deleteGlossaryCategory 
-  datacatalog.entries. deleteGlossaryTerm 
-  datacatalog.entries.get
-  datacatalog.entries. getIamPolicy 
-  datacatalog.entries.list
-  datacatalog.entries. setIamPolicy 
-  datacatalog.entries.update
-  datacatalog.entries. updateContacts 
-  datacatalog.entries. updateGlossary 
-  datacatalog.entries. updateGlossaryCategory 
-  datacatalog.entries. updateGlossaryTerm 
-  datacatalog.entries. updateOverview 
-  datacatalog.entries.updateTag
  datacatalog.entryGroups.* 
 
-  datacatalog.entryGroups.create
-  datacatalog.entryGroups.delete
-  datacatalog.entryGroups.get
-  datacatalog.entryGroups. getIamPolicy 
-  datacatalog.entryGroups.list
-  datacatalog.entryGroups. setIamPolicy 
-  datacatalog.entryGroups.update
-  datacatalog.entryGroups. updateTag 
  datacatalog.migrationConfig.* 
 
-  datacatalog.migrationConfig. get 
-  datacatalog.migrationConfig. set 
 datacatalog.operations.list 
  datacatalog.relationships.* 
 
-  datacatalog.relationships. create 
-  datacatalog.relationships. createBelongsTo 
-  datacatalog.relationships. createIsDescribedBy 
-  datacatalog.relationships. createIsRelatedTo 
-  datacatalog.relationships. createIsSynonymousTo 
-  datacatalog.relationships. delete 
-  datacatalog.relationships. deleteBelongsTo 
-  datacatalog.relationships. deleteIsDescribedBy 
-  datacatalog.relationships. deleteIsRelatedTo 
-  datacatalog.relationships. deleteIsSynonymousTo 
-  datacatalog.relationships.list
  datacatalog.tagTemplates.* 
 
-  datacatalog.tagTemplates. create 
-  datacatalog.tagTemplates. delete 
-  datacatalog.tagTemplates.get
-  datacatalog.tagTemplates. getIamPolicy 
-  datacatalog.tagTemplates. getTag 
-  datacatalog.tagTemplates. setIamPolicy 
-  datacatalog.tagTemplates. update 
-  datacatalog.tagTemplates.use
  datacatalog.taxonomies.* 
 
-  datacatalog.taxonomies.create
-  datacatalog.taxonomies.delete
-  datacatalog.taxonomies.get
-  datacatalog.taxonomies. getIamPolicy 
-  datacatalog.taxonomies.list
-  datacatalog.taxonomies. setIamPolicy 
-  datacatalog.taxonomies.update
  dataplex.aspectTypes.* 
 
-  dataplex.aspectTypes.create
-  dataplex.aspectTypes.delete
-  dataplex.aspectTypes.get
-  dataplex.aspectTypes. getIamPolicy 
-  dataplex.aspectTypes.list
-  dataplex.aspectTypes. setIamPolicy 
-  dataplex.aspectTypes.update
-  dataplex.aspectTypes.use
  dataplex.entries.* 
 
-  dataplex.entries.create
-  dataplex.entries.delete
-  dataplex.entries.get
-  dataplex.entries.getData
-  dataplex.entries.link
-  dataplex.entries.list
-  dataplex.entries.update
  dataplex.entryGroups.* 
 
-  dataplex.entryGroups.create
-  dataplex.entryGroups.delete
-  dataplex.entryGroups.export
-  dataplex.entryGroups.get
-  dataplex.entryGroups. getIamPolicy 
-  dataplex.entryGroups.import
-  dataplex.entryGroups.list
-  dataplex.entryGroups. setIamPolicy 
-  dataplex.entryGroups.update
-  dataplex.entryGroups. useContactsAspect 
-  dataplex.entryGroups. useDataQualityScorecardAspect 
-  dataplex.entryGroups. useDefinitionEntryLink 
-  dataplex.entryGroups. useDescriptionsAspect 
-  dataplex.entryGroups. useGenericAspect 
-  dataplex.entryGroups. useGenericEntry 
-  dataplex.entryGroups. useOverviewAspect 
-  dataplex.entryGroups. useQueriesAspect 
-  dataplex.entryGroups. useRelatedEntryLink 
-  dataplex.entryGroups. useSchemaAspect 
-  dataplex.entryGroups. useSynonymEntryLink 
  dataplex.entryLinks.* 
 
-  dataplex.entryLinks.create
-  dataplex.entryLinks.delete
-  dataplex.entryLinks.get
-  dataplex.entryLinks.reference
  dataplex.entryTypes.* 
 
-  dataplex.entryTypes.create
-  dataplex.entryTypes.delete
-  dataplex.entryTypes.get
-  dataplex.entryTypes. getIamPolicy 
-  dataplex.entryTypes.list
-  dataplex.entryTypes. setIamPolicy 
-  dataplex.entryTypes.update
-  dataplex.entryTypes.use
  dataplex.glossaries.* 
 
-  dataplex.glossaries.create
-  dataplex.glossaries.delete
-  dataplex.glossaries.get
-  dataplex.glossaries. getIamPolicy 
-  dataplex.glossaries.import
-  dataplex.glossaries.list
-  dataplex.glossaries. setIamPolicy 
-  dataplex.glossaries.update
  dataplex.glossaryCategories.* 
 
-  dataplex.glossaryCategories. create 
-  dataplex.glossaryCategories. delete 
-  dataplex.glossaryCategories. get 
-  dataplex.glossaryCategories. list 
-  dataplex.glossaryCategories. update 
  dataplex.glossaryTerms.* 
 
-  dataplex.glossaryTerms.create
-  dataplex.glossaryTerms.delete
-  dataplex.glossaryTerms.get
-  dataplex.glossaryTerms.list
-  dataplex.glossaryTerms.update
-  dataplex.glossaryTerms.use
 dataplex.operations.get 
 dataplex.projects.search 
 pubsub.topics.get 
 pubsub.topics.updateTag 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Policy Tag Admin
( roles/  
)
Manage taxonomies
 datacatalog.  
 datacatalog.  
  datacatalog.taxonomies.* 
 
-  datacatalog.taxonomies.create
-  datacatalog.taxonomies.delete
-  datacatalog.taxonomies.get
-  datacatalog.taxonomies. getIamPolicy 
-  datacatalog.taxonomies.list
-  datacatalog.taxonomies. setIamPolicy 
-  datacatalog.taxonomies.update
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Fine-Grained Reader
( roles/  
)
Read access to sub-resources tagged by a policy tag, for example, BigQuery columns
 datacatalog.  
DataCatalog Data Steward Beta
( roles/  
)
Can update overview and data steward fields
 datacatalog.entries.get 
 datacatalog.entries.list 
 datacatalog.  
 datacatalog.  
 datacatalog.entryGroups.get 
 datacatalog.  
 datacatalog.relationships.list 
 dataplex.entries.get 
 dataplex.entries.list 
 dataplex.entryGroups.get 
 dataplex.  
 dataplex.  
 dataplex.projects.search 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DataCatalog EntryGroup Creator
( roles/  
)
Can create new entryGroups
 datacatalog.entryGroups.create 
 datacatalog.entryGroups.get 
 datacatalog.entryGroups.list 
 dataplex.entryGroups.create 
 dataplex.entryGroups.get 
 dataplex.projects.search 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DataCatalog EntryGroup Owner
( roles/  
)
Full access to entryGroups
  datacatalog.entries.* 
 
-  datacatalog.entries.create
-  datacatalog.entries. createGlossary 
-  datacatalog.entries. createGlossaryCategory 
-  datacatalog.entries. createGlossaryTerm 
-  datacatalog.entries.delete
-  datacatalog.entries. deleteGlossary 
-  datacatalog.entries. deleteGlossaryCategory 
-  datacatalog.entries. deleteGlossaryTerm 
-  datacatalog.entries.get
-  datacatalog.entries. getIamPolicy 
-  datacatalog.entries.list
-  datacatalog.entries. setIamPolicy 
-  datacatalog.entries.update
-  datacatalog.entries. updateContacts 
-  datacatalog.entries. updateGlossary 
-  datacatalog.entries. updateGlossaryCategory 
-  datacatalog.entries. updateGlossaryTerm 
-  datacatalog.entries. updateOverview 
-  datacatalog.entries.updateTag
  datacatalog.entryGroups.* 
 
-  datacatalog.entryGroups.create
-  datacatalog.entryGroups.delete
-  datacatalog.entryGroups.get
-  datacatalog.entryGroups. getIamPolicy 
-  datacatalog.entryGroups.list
-  datacatalog.entryGroups. setIamPolicy 
-  datacatalog.entryGroups.update
-  datacatalog.entryGroups. updateTag 
 datacatalog.  
 dataplex.aspectTypes.get 
 dataplex.aspectTypes.list 
 dataplex.aspectTypes.use 
  dataplex.entries.* 
 
-  dataplex.entries.create
-  dataplex.entries.delete
-  dataplex.entries.get
-  dataplex.entries.getData
-  dataplex.entries.link
-  dataplex.entries.list
-  dataplex.entries.update
  dataplex.entryGroups.* 
 
-  dataplex.entryGroups.create
-  dataplex.entryGroups.delete
-  dataplex.entryGroups.export
-  dataplex.entryGroups.get
-  dataplex.entryGroups. getIamPolicy 
-  dataplex.entryGroups.import
-  dataplex.entryGroups.list
-  dataplex.entryGroups. setIamPolicy 
-  dataplex.entryGroups.update
-  dataplex.entryGroups. useContactsAspect 
-  dataplex.entryGroups. useDataQualityScorecardAspect 
-  dataplex.entryGroups. useDefinitionEntryLink 
-  dataplex.entryGroups. useDescriptionsAspect 
-  dataplex.entryGroups. useGenericAspect 
-  dataplex.entryGroups. useGenericEntry 
-  dataplex.entryGroups. useOverviewAspect 
-  dataplex.entryGroups. useQueriesAspect 
-  dataplex.entryGroups. useRelatedEntryLink 
-  dataplex.entryGroups. useSchemaAspect 
-  dataplex.entryGroups. useSynonymEntryLink 
  dataplex.entryLinks.* 
 
-  dataplex.entryLinks.create
-  dataplex.entryLinks.delete
-  dataplex.entryLinks.get
-  dataplex.entryLinks.reference
 dataplex.entryTypes.get 
 dataplex.entryTypes.list 
 dataplex.entryTypes.use 
 dataplex.operations.get 
 dataplex.projects.search 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DataCatalog Entry Owner
( roles/  
)
Full access to entries
  datacatalog.entries.* 
 
-  datacatalog.entries.create
-  datacatalog.entries. createGlossary 
-  datacatalog.entries. createGlossaryCategory 
-  datacatalog.entries. createGlossaryTerm 
-  datacatalog.entries.delete
-  datacatalog.entries. deleteGlossary 
-  datacatalog.entries. deleteGlossaryCategory 
-  datacatalog.entries. deleteGlossaryTerm 
-  datacatalog.entries.get
-  datacatalog.entries. getIamPolicy 
-  datacatalog.entries.list
-  datacatalog.entries. setIamPolicy 
-  datacatalog.entries.update
-  datacatalog.entries. updateContacts 
-  datacatalog.entries. updateGlossary 
-  datacatalog.entries. updateGlossaryCategory 
-  datacatalog.entries. updateGlossaryTerm 
-  datacatalog.entries. updateOverview 
-  datacatalog.entries.updateTag
 datacatalog.entryGroups.get 
 datacatalog.  
 dataplex.aspectTypes.get 
 dataplex.aspectTypes.list 
 dataplex.aspectTypes.use 
  dataplex.entries.* 
 
-  dataplex.entries.create
-  dataplex.entries.delete
-  dataplex.entries.get
-  dataplex.entries.getData
-  dataplex.entries.link
-  dataplex.entries.list
-  dataplex.entries.update
 dataplex.entryGroups.get 
 dataplex.  
 dataplex.  
 dataplex.  
 dataplex.  
 dataplex.  
 dataplex.  
 dataplex.  
 dataplex.  
 dataplex.  
 dataplex.  
 dataplex.  
  dataplex.entryLinks.* 
 
-  dataplex.entryLinks.create
-  dataplex.entryLinks.delete
-  dataplex.entryLinks.get
-  dataplex.entryLinks.reference
 dataplex.entryTypes.get 
 dataplex.entryTypes.list 
 dataplex.entryTypes.use 
 dataplex.projects.search 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DataCatalog Entry Viewer
( roles/  
)
Read access to entries
 datacatalog.entries.get 
 datacatalog.entries.list 
 datacatalog.entryGroups.get 
 datacatalog.  
 datacatalog.relationships.list 
 dataplex.entries.get 
 dataplex.entries.list 
 dataplex.entryGroups.get 
 dataplex.projects.search 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DataCatalog Glossary Owner Beta
( roles/  
)
Full access to glossaries
  datacatalog.entries.* 
 
-  datacatalog.entries.create
-  datacatalog.entries. createGlossary 
-  datacatalog.entries. createGlossaryCategory 
-  datacatalog.entries. createGlossaryTerm 
-  datacatalog.entries.delete
-  datacatalog.entries. deleteGlossary 
-  datacatalog.entries. deleteGlossaryCategory 
-  datacatalog.entries. deleteGlossaryTerm 
-  datacatalog.entries.get
-  datacatalog.entries. getIamPolicy 
-  datacatalog.entries.list
-  datacatalog.entries. setIamPolicy 
-  datacatalog.entries.update
-  datacatalog.entries. updateContacts 
-  datacatalog.entries. updateGlossary 
-  datacatalog.entries. updateGlossaryCategory 
-  datacatalog.entries. updateGlossaryTerm 
-  datacatalog.entries. updateOverview 
-  datacatalog.entries.updateTag
  datacatalog.relationships.* 
 
-  datacatalog.relationships. create 
-  datacatalog.relationships. createBelongsTo 
-  datacatalog.relationships. createIsDescribedBy 
-  datacatalog.relationships. createIsRelatedTo 
-  datacatalog.relationships. createIsSynonymousTo 
-  datacatalog.relationships. delete 
-  datacatalog.relationships. deleteBelongsTo 
-  datacatalog.relationships. deleteIsDescribedBy 
-  datacatalog.relationships. deleteIsRelatedTo 
-  datacatalog.relationships. deleteIsSynonymousTo 
-  datacatalog.relationships.list
 dataplex.projects.search 
DataCatalog Glossary User Beta
( roles/  
)
Can view glossaries and associate terms to entries
 datacatalog.entries.get 
 datacatalog.entries.list 
  datacatalog.relationships.* 
 
-  datacatalog.relationships. create 
-  datacatalog.relationships. createBelongsTo 
-  datacatalog.relationships. createIsDescribedBy 
-  datacatalog.relationships. createIsRelatedTo 
-  datacatalog.relationships. createIsSynonymousTo 
-  datacatalog.relationships. delete 
-  datacatalog.relationships. deleteBelongsTo 
-  datacatalog.relationships. deleteIsDescribedBy 
-  datacatalog.relationships. deleteIsRelatedTo 
-  datacatalog.relationships. deleteIsSynonymousTo 
-  datacatalog.relationships.list
 dataplex.projects.search 
DataCatalog Migration Config Admin
( roles/  
)
Full access to Migration Config
  datacatalog.migrationConfig.* 
 
-  datacatalog.migrationConfig. get 
-  datacatalog.migrationConfig. set 
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DataCatalog Search Admin
( roles/  
)
Can search all metadata for a project/org in DataCatalog
 datacatalog.catalogs.searchAll 
 dataplex.projects.search 
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Data Catalog Tag Editor
( roles/  
)
Access to modify metadata tags for entries, as well as BigQuery and Pub/Sub data assets
 bigquery.connections.updateTag 
 bigquery.datasets.updateTag 
 bigquery.models.updateTag 
 bigquery.routines.updateTag 
 bigquery.tables.updateTag 
 datacatalog.entries.updateTag 
 datacatalog.  
 dataplex.entries.update 
 pubsub.topics.updateTag 
Data Catalog TagTemplate Creator
( roles/  
)
Access to create new tag templates
 datacatalog.  
 datacatalog.tagTemplates.get 
 dataplex.aspectTypes.create 
 dataplex.aspectTypes.get 
 dataplex.projects.search 
Data Catalog TagTemplate Owner
( roles/  
)
Full access to tag templates
 datacatalog.  
  datacatalog.tagTemplates.* 
 
-  datacatalog.tagTemplates. create 
-  datacatalog.tagTemplates. delete 
-  datacatalog.tagTemplates.get
-  datacatalog.tagTemplates. getIamPolicy 
-  datacatalog.tagTemplates. getTag 
-  datacatalog.tagTemplates. setIamPolicy 
-  datacatalog.tagTemplates. update 
-  datacatalog.tagTemplates.use
  dataplex.aspectTypes.* 
 
-  dataplex.aspectTypes.create
-  dataplex.aspectTypes.delete
-  dataplex.aspectTypes.get
-  dataplex.aspectTypes. getIamPolicy 
-  dataplex.aspectTypes.list
-  dataplex.aspectTypes. setIamPolicy 
-  dataplex.aspectTypes.update
-  dataplex.aspectTypes.use
 dataplex.operations.get 
 dataplex.projects.search 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Data Catalog TagTemplate User
( roles/  
)
Access to apply a tag template to an entry (to modify tags, see Data Catalog Tag Editor)
 datacatalog.  
 datacatalog.tagTemplates.get 
 datacatalog.  
 datacatalog.tagTemplates.use 
 dataplex.aspectTypes.get 
 dataplex.aspectTypes.list 
 dataplex.aspectTypes.use 
 dataplex.projects.search 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Data Catalog TagTemplate Viewer
( roles/  
)
Read access to templates and tags created using the templates
 datacatalog.tagTemplates.get 
 datacatalog.  
 dataplex.aspectTypes.get 
 dataplex.aspectTypes.list 
 dataplex.projects.search 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Data Catalog Viewer
( roles/  
)
Provides metadata read access to catalogued Google Cloud assets for BigQuery and Pub/Sub
 bigquery.connections.get 
 bigquery.datasets.get 
 bigquery.models.getMetadata 
 bigquery.routines.get 
 bigquery.tables.get 
 datacatalog.entries.get 
 datacatalog.entries.list 
 datacatalog.entryGroups.get 
 datacatalog.entryGroups.list 
 datacatalog.  
 datacatalog.operations.list 
 datacatalog.relationships.list 
 datacatalog.tagTemplates.get 
 datacatalog.  
 datacatalog.taxonomies.get 
 datacatalog.taxonomies.list 
 dataplex.aspectTypes.get 
 dataplex.  
 dataplex.aspectTypes.list 
 dataplex.entries.get 
 dataplex.entries.list 
 dataplex.entryGroups.get 
 dataplex.  
 dataplex.entryGroups.list 
 dataplex.entryLinks.get 
 dataplex.entryTypes.get 
 dataplex.  
 dataplex.entryTypes.list 
 dataplex.glossaries.get 
 dataplex.  
 dataplex.glossaries.list 
 dataplex.  
 dataplex.  
 dataplex.glossaryTerms.get 
 dataplex.glossaryTerms.list 
 dataplex.projects.search 
 pubsub.topics.get 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Data Catalog permissions
 datacatalog.catalogs.searchAll 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Search Admin 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
 datacatalog.  
 
 Fine-Grained Reader 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
 Security Admin 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
 datacatalog.entries.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.entries.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.entries.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Data Steward 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Entry Viewer 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 datacatalog.entries.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Data Steward 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Entry Viewer 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 datacatalog.entries.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Data Steward 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Data Steward 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 datacatalog.entries.updateTag 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 Data Catalog Tag Editor 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 datacatalog.entryGroups.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Creator 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 datacatalog.entryGroups.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 datacatalog.entryGroups.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Data Steward 
( roles/  
)
 DataCatalog EntryGroup Creator 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Entry Viewer 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Support User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 datacatalog.entryGroups.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Creator 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 datacatalog.entryGroups.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 Data Catalog Tag Editor 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Data Steward 
( roles/  
)
 DataCatalog EntryGroup Owner 
( roles/  
)
 DataCatalog Entry Owner 
( roles/  
)
 DataCatalog Entry Viewer 
( roles/  
)
 DataCatalog Migration Config Admin 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
 Data Catalog TagTemplate User 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Dataplex Aspect Type Owner 
( roles/  
)
 Dataplex Aspect Type User 
( roles/  
)
 Dataplex Catalog Admin 
( roles/  
)
 Dataplex Catalog Editor 
( roles/  
)
 Dataplex Catalog Viewer 
( roles/  
)
 Dataplex Entry Group Owner 
( roles/  
)
 Dataplex Entry and EntryLink Owner 
( roles/  
)
 Dataplex Entry Type Owner 
( roles/  
)
 Dataplex Entry Type User 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Migration Config Admin 
( roles/  
)
 datacatalog.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 datacatalog.relationships.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 DataCatalog Data Steward 
( roles/  
)
 DataCatalog Entry Viewer 
( roles/  
)
 DataCatalog Glossary Owner 
( roles/  
)
 DataCatalog Glossary User 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog TagTemplate Creator 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.tagTemplates.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog TagTemplate Creator 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
 Data Catalog TagTemplate User 
( roles/  
)
 Data Catalog TagTemplate Viewer 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
 Data Catalog TagTemplate User 
( roles/  
)
 Data Catalog TagTemplate Viewer 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
 Security Admin 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.tagTemplates.use 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog TagTemplate Owner 
( roles/  
)
 Data Catalog TagTemplate User 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
 datacatalog.taxonomies.create 
 
 Owner 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
 datacatalog.taxonomies.delete 
 
 Owner 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
 datacatalog.taxonomies.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 datacatalog.taxonomies.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
 datacatalog.  
 
 Owner 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 datacatalog.taxonomies.update 
 
 Owner 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Policy Tag Admin 
( roles/  
)
Service agent roles
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 

