This page lists the IAM roles and permissions for Cloud Logging. To search through all roles and permissions, see the role and permission index .
Cloud Logging roles
Logging Admin
( roles/  
)
Provides all permissions necessary to use all features of Cloud Logging.
Lowest-level resources where you can grant this role:
- Project
 logging.buckets.copyLogEntries 
 logging.buckets.create 
 logging.  
 logging.buckets.delete 
 logging.  
 logging.buckets.get 
 logging.buckets.list 
 logging.  
 logging.  
 logging.buckets.undelete 
 logging.buckets.update 
  logging.exclusions.* 
 
-  logging.exclusions.create
-  logging.exclusions.delete
-  logging.exclusions.get
-  logging.exclusions.list
-  logging.exclusions.update
 logging.fields.access 
  logging.links.* 
 
-  logging.links.create
-  logging.links.delete
-  logging.links.get
-  logging.links.list
  logging.locations.* 
 
-  logging.locations.get
-  logging.locations.list
  logging.logEntries.* 
 
-  logging.logEntries.create
-  logging.logEntries.download
-  logging.logEntries.list
-  logging.logEntries.route
  logging.logMetrics.* 
 
-  logging.logMetrics.create
-  logging.logMetrics.delete
-  logging.logMetrics.get
-  logging.logMetrics.list
-  logging.logMetrics.update
  logging.logScopes.* 
 
-  logging.logScopes.create
-  logging.logScopes.delete
-  logging.logScopes.get
-  logging.logScopes.list
-  logging.logScopes.update
 logging.logServiceIndexes.list 
 logging.logServices.list 
  logging.logs.* 
 
-  logging.logs.delete
-  logging.logs.list
  logging.notificationRules.* 
 
-  logging.notificationRules. create 
-  logging.notificationRules. delete 
-  logging.notificationRules.get
-  logging.notificationRules.list
-  logging.notificationRules. update 
  logging.operations.* 
 
-  logging.operations.cancel
-  logging.operations.get
-  logging.operations.list
 logging.privateLogEntries.list 
  logging.queries.* 
 
-  logging.queries.deleteShared
-  logging.queries.getShared
-  logging.queries.listShared
-  logging.queries.share
-  logging.queries.updateShared
-  logging.queries.usePrivate
  logging.settings.* 
 
-  logging.settings.get
-  logging.settings.update
  logging.sinks.* 
 
-  logging.sinks.create
-  logging.sinks.delete
-  logging.sinks.get
-  logging.sinks.list
-  logging.sinks.update
  logging.sqlAlerts.* 
 
-  logging.sqlAlerts.create
-  logging.sqlAlerts.update
 logging.usage.get 
  logging.views.* 
 
-  logging.views.access
-  logging.views.create
-  logging.views.delete
-  logging.views.get
-  logging.views.getIamPolicy
-  logging.views.list
-  logging.views.listLogs
-  logging.views.listResourceKeys
-  logging.views. listResourceValues 
-  logging.views.setIamPolicy
-  logging.views.update
 observability.scopes.get 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Logs Bucket Writer
( roles/  
)
Ability to write logs to a log bucket.
Lowest-level resources where you can grant this role:
- Project
 logging.buckets.write 
Logs Configuration Writer
( roles/  
)
Provides permissions to read and write the configurations of logs-based metrics and sinks for exporting logs.
Lowest-level resources where you can grant this role:
- Project
 logging.buckets.create 
 logging.  
 logging.buckets.delete 
 logging.  
 logging.buckets.get 
 logging.buckets.list 
 logging.  
 logging.  
 logging.buckets.undelete 
 logging.buckets.update 
  logging.exclusions.* 
 
-  logging.exclusions.create
-  logging.exclusions.delete
-  logging.exclusions.get
-  logging.exclusions.list
-  logging.exclusions.update
  logging.links.* 
 
-  logging.links.create
-  logging.links.delete
-  logging.links.get
-  logging.links.list
  logging.locations.* 
 
-  logging.locations.get
-  logging.locations.list
  logging.logMetrics.* 
 
-  logging.logMetrics.create
-  logging.logMetrics.delete
-  logging.logMetrics.get
-  logging.logMetrics.list
-  logging.logMetrics.update
  logging.logScopes.* 
 
-  logging.logScopes.create
-  logging.logScopes.delete
-  logging.logScopes.get
-  logging.logScopes.list
-  logging.logScopes.update
 logging.logServiceIndexes.list 
 logging.logServices.list 
 logging.logs.list 
  logging.notificationRules.* 
 
-  logging.notificationRules. create 
-  logging.notificationRules. delete 
-  logging.notificationRules.get
-  logging.notificationRules.list
-  logging.notificationRules. update 
  logging.operations.* 
 
-  logging.operations.cancel
-  logging.operations.get
-  logging.operations.list
  logging.settings.* 
 
-  logging.settings.get
-  logging.settings.update
  logging.sinks.* 
 
-  logging.sinks.create
-  logging.sinks.delete
-  logging.sinks.get
-  logging.sinks.list
-  logging.sinks.update
  logging.sqlAlerts.* 
 
-  logging.sqlAlerts.create
-  logging.sqlAlerts.update
 logging.views.create 
 logging.views.delete 
 logging.views.get 
 logging.views.getIamPolicy 
 logging.views.list 
 logging.views.update 
 observability.scopes.get 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Log Field Accessor
( roles/  
)
Ability to read restricted fields in a log bucket.
Lowest-level resources where you can grant this role:
- Project
 logging.fields.access 
Log Link Accessor
( roles/  
)
Ability to see links for a bucket.
 logging.links.get 
 logging.links.list 
Logs Writer
( roles/  
)
Provides the permissions to write log entries.
Lowest-level resources where you can grant this role:
- Project
 logging.logEntries.create 
 logging.logEntries.route 
Private Logs Viewer
( roles/  
)
Provides permissions of the Logs Viewer role and in addition, provides read-only access to log entries in private logs.
Lowest-level resources where you can grant this role:
- Project
 logging.buckets.get 
 logging.buckets.list 
 logging.exclusions.get 
 logging.exclusions.list 
 logging.links.get 
 logging.links.list 
  logging.locations.* 
 
-  logging.locations.get
-  logging.locations.list
 logging.logEntries.list 
 logging.logMetrics.get 
 logging.logMetrics.list 
 logging.logServiceIndexes.list 
 logging.logServices.list 
 logging.logs.list 
 logging.operations.get 
 logging.operations.list 
 logging.privateLogEntries.list 
 logging.queries.getShared 
 logging.queries.listShared 
 logging.queries.usePrivate 
 logging.sinks.get 
 logging.sinks.list 
 logging.usage.get 
 logging.views.access 
 logging.views.get 
 logging.views.list 
 observability.scopes.get 
 resourcemanager.projects.get 
Cloud Logging Service Agent
( roles/  
)
Grants a Cloud Logging Service Account the ability to create and link datasets.
 bigquery.datasets.create 
 bigquery.datasets.get 
 bigquery.datasets.link 
SQL Alert Writer Beta
( roles/  
)
Ability to write SQL Alerts.
  logging.sqlAlerts.* 
 
-  logging.sqlAlerts.create
-  logging.sqlAlerts.update
Logs View Accessor
( roles/  
)
Ability to read logs in a view.
Lowest-level resources where you can grant this role:
- Project
 logging.logEntries.download 
 logging.views.access 
 logging.views.listLogs 
 logging.views.listResourceKeys 
 logging.  
Logs Viewer
( roles/  
)
Provides access to view logs.
Lowest-level resources where you can grant this role:
- Project
 logging.buckets.get 
 logging.buckets.list 
 logging.exclusions.get 
 logging.exclusions.list 
 logging.links.get 
 logging.links.list 
  logging.locations.* 
 
-  logging.locations.get
-  logging.locations.list
 logging.logEntries.list 
 logging.logMetrics.get 
 logging.logMetrics.list 
 logging.logScopes.get 
 logging.logScopes.list 
 logging.logServiceIndexes.list 
 logging.logServices.list 
 logging.logs.list 
 logging.operations.get 
 logging.operations.list 
 logging.queries.getShared 
 logging.queries.listShared 
 logging.queries.usePrivate 
 logging.sinks.get 
 logging.sinks.list 
 logging.usage.get 
 logging.views.get 
 logging.views.list 
 observability.scopes.get 
 resourcemanager.projects.get 
Cloud Logging permissions
 logging.buckets.copyLogEntries 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 logging.buckets.create 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Apigee Service Agent 
( roles/)apigee.serviceAgent 
 logging.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.buckets.delete 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.buckets.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Apigee Service Agent 
( roles/)apigee.serviceAgent 
 logging.buckets.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Audit Manager Auditing Service Agent 
( roles/)auditmanager.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Apigee Service Agent 
( roles/)apigee.serviceAgent 
 logging.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.buckets.undelete 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.buckets.update 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.buckets.write 
 
 Logs Bucket Writer 
( roles/  
)
Service agent roles
-  Cloud Build Logging Service Agent 
( roles/)cloudbuild.loggingServiceAgent 
 logging.exclusions.create 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.exclusions.delete 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.exclusions.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.exclusions.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.exclusions.update 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.fields.access 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Log Field Accessor 
( roles/  
)
 logging.links.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.links.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.links.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Log Link Accessor 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.links.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Log Link Accessor 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Monitoring Service Agent 
( roles/)monitoring.notificationServiceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.locations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.locations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logEntries.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Build Service Account 
( roles/  
)
 Cloud Deploy Runner 
( roles/  
)
 Composer Worker 
( roles/  
)
 Confidential Space Workload User 
( roles/  
)
 Cloud Infrastructure Manager Agent 
( roles/  
)
 Kubernetes Engine Default Node Service Account 
( roles/  
)
 Dataflow Worker 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Dataproc Worker 
( roles/  
)
 Developer Connect Insights Config Agent 
( roles/  
)
 Firebase App Hosting Compute Runner 
( roles/  
)
 Anthos Multi-cloud Telemetry Writer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Writer 
( roles/  
)
 Cloud Run Builder 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Vertex AI Extension Custom Code Service Agent 
( roles/)aiplatform.extensionCustomCodeServiceAgent 
-  Vertex AI Extension Service Agent 
( roles/)aiplatform.extensionServiceAgent 
-  Vertex AI Notebook Service Agent 
( roles/)aiplatform.notebookServiceAgent 
-  Vertex AI RAG Data Service Agent 
( roles/)aiplatform.ragServiceAgent 
-  Vertex AI Reasoning Engine Service Agent 
( roles/)aiplatform.reasoningEngineServiceAgent 
-  Vertex AI Service Agent 
( roles/)aiplatform.serviceAgent 
-  Vertex AI Telemetry Service Agent 
( roles/)aiplatform.telemetryServiceAgent 
-  Anthos Service Mesh Service Agent 
( roles/)anthosservicemesh.serviceAgent 
-  App Engine flexible environment Service Agent 
( roles/)appengineflex.serviceAgent 
-  Recommendations AI Service Agent 
( roles/)automlrecommendations.serviceAgent 
-  BigQuery Connection Service Agent 
( roles/)bigqueryconnection.serviceAgent 
-  BigQuery Data Transfer Service Agent 
( roles/)bigquerydatatransfer.serviceAgent 
-  Customer Engagement Suite Service Agent 
( roles/)ces.serviceAgent 
-  Gemini for Google Cloud Service Agent 
( roles/)cloudaicompanion.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Infrastructure Manager Service Agent 
( roles/)cloudconfig.serviceAgent 
-  Cloud Deploy Service Agent 
( roles/)clouddeploy.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud IoT Core Service Agent 
( roles/)cloudiot.serviceAgent 
-  Cloud Scheduler Service Agent 
( roles/)cloudscheduler.serviceAgent 
-  Cloud Tasks Service Agent 
( roles/)cloudtasks.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Compute Engine Service Agent 
( roles/)compute.serviceAgent 
-  Kubernetes Engine Default Node Service Agent 
( roles/)container.defaultNodeServiceAgent 
-  [Deprecated] Kubernetes Engine Node Service Agent 
( roles/)container.nodeServiceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
-  Dataproc Resource Manager Node Service Agent 
( roles/)dataprocrm.nodeServiceAgent 
-  Dialogflow Service Agent 
( roles/)dialogflow.serviceAgent 
-  Discovery Engine Service Agent 
( roles/)discoveryengine.serviceAgent 
-  Edge Container Cluster Service Agent 
( roles/)edgecontainer.clusterServiceAgent 
-  Firebase Machine Learning Service Agent 
( roles/)firebaseml.serviceAgent 
-  Anthos Multi-Cloud Container Service Agent 
( roles/)gkemulticloud.containerServiceAgent 
-  Mesh Managed Control Plane Service Agent 
( roles/)meshcontrolplane.serviceAgent 
-  Mesh Data Plane Service Agent 
( roles/)meshdataplane.serviceAgent 
-  AI Platform Service Agent 
( roles/)ml.serviceAgent 
-  RMA Service Agent 
( roles/)rapidmigrationassessment.serviceAgent 
-  Retail Service Agent 
( roles/)retail.serviceAgent 
-  Cloud Spanner API Service Agent 
( roles/)spanner.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Serverless VPC Access Service Agent 
( roles/)vpcaccess.serviceAgent 
-  Vertex AI Custom Code Service Agent 
( roles/)aiplatform.customCodeServiceAgent 
 logging.logEntries.download 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs View Accessor 
( roles/  
)
 logging.logEntries.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Billing Account Administrator 
( roles/  
)
 Cloud Build Service Account 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Firebase Admin 
( roles/  
)
 Firebase Develop Admin 
( roles/  
)
 Firebase Develop Viewer 
( roles/  
)
 Firebase Viewer 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Vertex AI Telemetry Service Agent 
( roles/)aiplatform.telemetryServiceAgent 
 logging.logEntries.route 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dataflow Worker 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Dataproc Worker 
( roles/  
)
 Firebase App Hosting Compute Runner 
( roles/  
)
 Anthos Multi-cloud Telemetry Writer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Writer 
( roles/  
)
Service agent roles
-  Vertex AI Extension Custom Code Service Agent 
( roles/)aiplatform.extensionCustomCodeServiceAgent 
-  Vertex AI Extension Service Agent 
( roles/)aiplatform.extensionServiceAgent 
-  Vertex AI Notebook Service Agent 
( roles/)aiplatform.notebookServiceAgent 
-  Vertex AI RAG Data Service Agent 
( roles/)aiplatform.ragServiceAgent 
-  Vertex AI Reasoning Engine Service Agent 
( roles/)aiplatform.reasoningEngineServiceAgent 
-  Vertex AI Service Agent 
( roles/)aiplatform.serviceAgent 
-  Vertex AI Telemetry Service Agent 
( roles/)aiplatform.telemetryServiceAgent 
-  Recommendations AI Service Agent 
( roles/)automlrecommendations.serviceAgent 
-  BigQuery Connection Service Agent 
( roles/)bigqueryconnection.serviceAgent 
-  BigQuery Data Transfer Service Agent 
( roles/)bigquerydatatransfer.serviceAgent 
-  Customer Engagement Suite Service Agent 
( roles/)ces.serviceAgent 
-  Gemini for Google Cloud Service Agent 
( roles/)cloudaicompanion.serviceAgent 
-  Infrastructure Manager Service Agent 
( roles/)cloudconfig.serviceAgent 
-  Cloud IoT Core Service Agent 
( roles/)cloudiot.serviceAgent 
-  Cloud Scheduler Service Agent 
( roles/)cloudscheduler.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
-  Dataproc Resource Manager Node Service Agent 
( roles/)dataprocrm.nodeServiceAgent 
-  Dialogflow Service Agent 
( roles/)dialogflow.serviceAgent 
-  Firebase Machine Learning Service Agent 
( roles/)firebaseml.serviceAgent 
-  Anthos Multi-Cloud Container Service Agent 
( roles/)gkemulticloud.containerServiceAgent 
-  Mesh Managed Control Plane Service Agent 
( roles/)meshcontrolplane.serviceAgent 
-  Mesh Data Plane Service Agent 
( roles/)meshdataplane.serviceAgent 
-  AI Platform Service Agent 
( roles/)ml.serviceAgent 
-  Retail Service Agent 
( roles/)retail.serviceAgent 
-  Vertex AI Custom Code Service Agent 
( roles/)aiplatform.customCodeServiceAgent 
 logging.logMetrics.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Serverless VPC Access Service Agent 
( roles/)vpcaccess.serviceAgent 
-  App Engine flexible environment Service Agent 
( roles/)appengineflex.serviceAgent 
 logging.logMetrics.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Serverless VPC Access Service Agent 
( roles/)vpcaccess.serviceAgent 
-  App Engine flexible environment Service Agent 
( roles/)appengineflex.serviceAgent 
 logging.logMetrics.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Serverless VPC Access Service Agent 
( roles/)vpcaccess.serviceAgent 
-  App Engine flexible environment Service Agent 
( roles/)appengineflex.serviceAgent 
 logging.logMetrics.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logMetrics.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Serverless VPC Access Service Agent 
( roles/)vpcaccess.serviceAgent 
-  App Engine flexible environment Service Agent 
( roles/)appengineflex.serviceAgent 
 logging.logScopes.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logScopes.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logScopes.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logScopes.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logScopes.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logServiceIndexes.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Billing Account Administrator 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logServices.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Billing Account Administrator 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.logs.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 logging.logs.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Billing Account Administrator 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Error Reporting Admin 
( roles/  
)
 Error Reporting User 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Error Reporting Admin 
( roles/  
)
 Error Reporting User 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.notificationRules.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Error Reporting Admin 
( roles/  
)
 Error Reporting User 
( roles/  
)
 Error Reporting Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.notificationRules.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Error Reporting Admin 
( roles/  
)
 Error Reporting User 
( roles/  
)
 Error Reporting Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Error Reporting Admin 
( roles/  
)
 Error Reporting User 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.operations.cancel 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.privateLogEntries.list 
 
 Owner 
( roles/  
)
 Billing Account Administrator 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Logging Admin 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 logging.queries.deleteShared 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 logging.queries.getShared 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
 logging.queries.listShared 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
 logging.queries.share 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 logging.queries.updateShared 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 logging.queries.usePrivate 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
 logging.settings.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.settings.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Assured Workloads Administrator 
( roles/  
)
 Assured Workloads Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
 logging.sinks.create 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.sinks.delete 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.sinks.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.sinks.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.sinks.update 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 logging.sqlAlerts.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 SQL Alert Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.sqlAlerts.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 SQL Alert Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.usage.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 VPC Service Controls Troubleshooter Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
 logging.views.access 
 
 Owner 
( roles/  
)
 Cloud Build Service Account 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs View Accessor 
( roles/  
)
Service agent roles
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 logging.views.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Apigee Service Agent 
( roles/)apigee.serviceAgent 
 logging.views.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.views.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Apigee Service Agent 
( roles/)apigee.serviceAgent 
 logging.views.getIamPolicy 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 logging.views.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Apigee Service Agent 
( roles/)apigee.serviceAgent 
 logging.views.listLogs 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs View Accessor 
( roles/  
)
 logging.views.listResourceKeys 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs View Accessor 
( roles/  
)
 logging.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs View Accessor 
( roles/  
)
 logging.views.setIamPolicy 
 
 Owner 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Logging Admin 
( roles/  
)
 logging.views.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 

