This page lists the IAM roles and permissions for Dataproc Metastore. To search through all roles and permissions, see the role and permission index .
Dataproc Metastore roles
Dataproc Metastore Admin
( roles/  
)
Full access to all Dataproc Metastore resources.
  metastore.backups.* 
 
-  metastore.backups.create
-  metastore.backups.delete
-  metastore.backups.get
-  metastore.backups.getIamPolicy
-  metastore.backups.list
-  metastore.backups.setIamPolicy
-  metastore.backups.use
  metastore.federations.* 
 
-  metastore.federations.create
-  metastore.federations. createTagBinding 
-  metastore.federations.delete
-  metastore.federations. deleteTagBinding 
-  metastore.federations.get
-  metastore.federations. getIamPolicy 
-  metastore.federations.list
-  metastore.federations. listEffectiveTags 
-  metastore.federations. listTagBindings 
-  metastore.federations. setIamPolicy 
-  metastore.federations.update
-  metastore.federations.use
  metastore.imports.* 
 
-  metastore.imports.create
-  metastore.imports.get
-  metastore.imports.list
-  metastore.imports.update
  metastore.locations.* 
 
-  metastore.locations.get
-  metastore.locations.list
  metastore.migrations.* 
 
-  metastore.migrations.cancel
-  metastore.migrations.complete
-  metastore.migrations.delete
-  metastore.migrations.get
-  metastore.migrations.list
-  metastore.migrations.start
  metastore.operations.* 
 
-  metastore.operations.cancel
-  metastore.operations.delete
-  metastore.operations.get
-  metastore.operations.list
 metastore.services.create 
 metastore.  
 metastore.services.delete 
 metastore.  
 metastore.services.export 
 metastore.services.get 
 metastore.  
 metastore.services.list 
 metastore.  
 metastore.  
 metastore.services.restore 
 metastore.  
 metastore.services.update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Dataproc Metastore Editor
( roles/  
)
Read and write access to all Dataproc Metastore resources.
 metastore.backups.create 
 metastore.backups.delete 
 metastore.backups.get 
 metastore.backups.list 
 metastore.backups.use 
 metastore.federations.create 
 metastore.federations.delete 
 metastore.federations.get 
 metastore.federations.list 
 metastore.  
 metastore.  
 metastore.federations.update 
  metastore.imports.* 
 
-  metastore.imports.create
-  metastore.imports.get
-  metastore.imports.list
-  metastore.imports.update
  metastore.locations.* 
 
-  metastore.locations.get
-  metastore.locations.list
  metastore.migrations.* 
 
-  metastore.migrations.cancel
-  metastore.migrations.complete
-  metastore.migrations.delete
-  metastore.migrations.get
-  metastore.migrations.list
-  metastore.migrations.start
  metastore.operations.* 
 
-  metastore.operations.cancel
-  metastore.operations.delete
-  metastore.operations.get
-  metastore.operations.list
 metastore.services.create 
 metastore.  
 metastore.services.delete 
 metastore.  
 metastore.services.export 
 metastore.services.get 
 metastore.  
 metastore.services.list 
 metastore.  
 metastore.  
 metastore.services.restore 
 metastore.services.update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Metastore Federation Accessor
( roles/  
)
Access to the Metastore Federation resource.
 metastore.federations.use 
Dataproc Metastore Metadata Editor
( roles/  
)
Access to read and modify the metadata of databases and tables under those databases.
 metastore.databases.create 
 metastore.databases.delete 
 metastore.databases.get 
 metastore.  
 metastore.databases.list 
 metastore.databases.update 
 metastore.services.get 
 metastore.services.use 
 metastore.tables.create 
 metastore.tables.delete 
 metastore.tables.get 
 metastore.tables.getIamPolicy 
 metastore.tables.list 
 metastore.tables.update 
Dataproc Metastore Metadata Mutate Admin
( roles/  
)
Access to mutate metadata from a Dataproc Metastore service's underlying metadata store.
 metastore.  
Dataproc Metastore Metadata Operator
( roles/  
)
Read-only access to Dataproc Metastore resources with additional metadata operations permission.
 metastore.backups.create 
 metastore.backups.delete 
 metastore.backups.get 
 metastore.backups.list 
 metastore.backups.use 
  metastore.imports.* 
 
-  metastore.imports.create
-  metastore.imports.get
-  metastore.imports.list
-  metastore.imports.update
  metastore.locations.* 
 
-  metastore.locations.get
-  metastore.locations.list
 metastore.operations.get 
 metastore.operations.list 
 metastore.services.export 
 metastore.services.get 
 metastore.  
 metastore.services.list 
 metastore.  
 metastore.  
 metastore.services.restore 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Dataproc Metastore Data Owner
( roles/  
)
Full access to the metadata of databases and tables under those databases.
  metastore.databases.* 
 
-  metastore.databases.create
-  metastore.databases.delete
-  metastore.databases.get
-  metastore.databases. getIamPolicy 
-  metastore.databases.list
-  metastore.databases. setIamPolicy 
-  metastore.databases.update
 metastore.services.get 
 metastore.  
 metastore.services.list 
 metastore.  
 metastore.  
 metastore.services.use 
  metastore.tables.* 
 
-  metastore.tables.create
-  metastore.tables.delete
-  metastore.tables.get
-  metastore.tables.getIamPolicy
-  metastore.tables.list
-  metastore.tables.setIamPolicy
-  metastore.tables.update
Dataproc Metastore Metadata Query Admin
( roles/  
)
Access to query metadata from a Dataproc Metastore service's underlying metadata store.
 metastore.  
Dataproc Metastore Metadata User
( roles/  
)
Access to the Dataproc Metastore gRPC endpoint
 metastore.databases.get 
 metastore.databases.list 
 metastore.services.get 
 metastore.services.use 
Dataproc Metastore Metadata Viewer
( roles/  
)
Access to read the metadata of databases and tables under those databases
 metastore.databases.get 
 metastore.  
 metastore.databases.list 
 metastore.services.get 
 metastore.services.use 
 metastore.tables.get 
 metastore.tables.getIamPolicy 
 metastore.tables.list 
Dataproc Metastore Managed Migration Admin
( roles/  
)
Access to Dataproc Metastore Managed Migration resources and workflow.
 cloudsql.instances.connect 
 cloudsql.instances.get 
 cloudsql.instances.login 
 compute.autoscalers.create 
 compute.autoscalers.delete 
 compute.disks.create 
 compute.disks.delete 
 compute.forwardingRules.create 
 compute.forwardingRules.delete 
 compute.forwardingRules.use 
 compute.  
 compute.  
 compute.  
 compute.instanceGroups.delete 
 compute.instanceGroups.use 
 compute.  
 compute.  
 compute.instanceTemplates.get 
 compute.  
 compute.instances.create 
 compute.instances.delete 
 compute.instances.get 
 compute.instances.setMetadata 
 compute.machineTypes.list 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.regionHealthChecks.use 
 compute.  
 compute.  
 compute.  
 compute.subnetworks.get 
 compute.subnetworks.use 
 compute.zones.list 
 datastream.  
 datastream.  
  datastream.objects.* 
 
-  datastream.objects.get
-  datastream.objects.list
-  datastream.objects. startBackfillJob 
-  datastream.objects. stopBackfillJob 
 datastream.operations.get 
 datastream.  
 datastream.  
 datastream.streams.create 
 datastream.streams.delete 
 datastream.streams.get 
 datastream.streams.update 
Dataproc Metastore Service Agent
( roles/  
)
Gives the Dataproc Metastore service account access to managed resources.
 compute.  
 compute.  
 compute.addresses.get 
 compute.addresses.use 
 compute.forwardingRules.create 
 compute.forwardingRules.delete 
 compute.forwardingRules.get 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.globalAddresses.get 
 compute.globalAddresses.list 
 compute.globalOperations.get 
 compute.globalOperations.list 
 compute.networks.addPeering 
 compute.networks.get 
 compute.networks.removePeering 
 compute.networks.updatePeering 
 compute.networks.use 
 compute.regionOperations.get 
 compute.subnetworks.get 
 compute.subnetworks.use 
 dns.changes.create 
 dns.changes.get 
 dns.managedZones.create 
 dns.managedZones.delete 
 dns.managedZones.get 
 dns.managedZones.list 
 dns.  
 dns.  
  dns.resourceRecordSets.* 
 
-  dns.resourceRecordSets.create
-  dns.resourceRecordSets.delete
-  dns.resourceRecordSets.get
-  dns.resourceRecordSets.list
-  dns.resourceRecordSets.update
 metastore.databases.get 
 metastore.  
 metastore.databases.update 
 metastore.federations.use 
 metastore.services.get 
 metastore.tables.get 
 metastore.tables.setIamPolicy 
 metastore.tables.update 
 servicedirectory.  
 servicedirectory.  
 servicedirectory.  
 servicedirectory.  
 storage.buckets.create 
 storage.buckets.delete 
 storage.buckets.get 
 storage.buckets.update 
 storage.objects.create 
 storage.objects.delete 
 storage.objects.get 
 storage.objects.list 
 storage.objects.update 
Dataproc Metastore Viewer
( roles/  
)
Read-only access to all Dataproc Metastore resources.
 metastore.backups.get 
 metastore.backups.list 
 metastore.federations.get 
 metastore.  
 metastore.federations.list 
 metastore.  
 metastore.  
 metastore.imports.get 
 metastore.imports.list 
  metastore.locations.* 
 
-  metastore.locations.get
-  metastore.locations.list
 metastore.operations.get 
 metastore.operations.list 
 metastore.services.export 
 metastore.services.get 
 metastore.  
 metastore.services.list 
 metastore.  
 metastore.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Dataproc Metastore permissions
 metastore.backups.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 metastore.backups.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 metastore.backups.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.backups.getIamPolicy 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 metastore.backups.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.backups.setIamPolicy 
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 metastore.backups.use 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 metastore.databases.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 metastore.databases.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 metastore.databases.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Metadata User 
( roles/  
)
 Dataproc Metastore Metadata Viewer 
( roles/  
)
Service agent roles
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
 metastore.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Metadata Viewer 
( roles/  
)
 metastore.databases.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Metadata User 
( roles/  
)
 Dataproc Metastore Metadata Viewer 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
Service agent roles
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
 metastore.databases.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
Service agent roles
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
 metastore.federations.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Tag User 
( roles/  
)
 metastore.federations.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Tag User 
( roles/  
)
 metastore.federations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.federations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 metastore.federations.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.federations.use 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Metastore Federation Accessor 
( roles/  
)
Service agent roles
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
 metastore.imports.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 metastore.imports.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.imports.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.imports.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 metastore.locations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.locations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.migrations.cancel 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.migrations.complete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.migrations.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.migrations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.migrations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.migrations.start 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.operations.cancel 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.operations.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.services.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Tag User 
( roles/  
)
 metastore.services.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Tag User 
( roles/  
)
 metastore.services.export 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.services.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Metadata User 
( roles/  
)
 Dataproc Metastore Metadata Viewer 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
Service agent roles
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
 metastore.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.services.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Dataproc Metastore Metadata Mutate Admin 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Dataproc Metastore Metadata Query Admin 
( roles/  
)
 metastore.services.restore 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 Dataproc Metastore Metadata Operator 
( roles/  
)
 metastore.  
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 metastore.services.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Admin 
( roles/  
)
 Dataproc Metastore Editor 
( roles/  
)
 metastore.services.use 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Metadata User 
( roles/  
)
 Dataproc Metastore Metadata Viewer 
( roles/  
)
 metastore.tables.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 metastore.tables.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 metastore.tables.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Metadata Viewer 
( roles/  
)
Service agent roles
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
 metastore.tables.getIamPolicy 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Metadata Viewer 
( roles/  
)
 metastore.tables.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
 Dataproc Metastore Metadata Viewer 
( roles/  
)
 metastore.tables.setIamPolicy 
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
Service agent roles
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
 metastore.tables.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Dataproc Metastore Metadata Editor 
( roles/  
)
 Dataproc Metastore Data Owner 
( roles/  
)
Service agent roles
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 

