This page lists the IAM roles and permissions for Network Connectivity Center. To search through all roles and permissions, see the role and permission index .
Network Connectivity Center roles
Service Automation Consumer Network Admin
( roles/  
)
Service Automation Consumer Network Admin is responsible for setting up ServiceConnectionPolicies.
  networkconnectivity.  
 
-  networkconnectivity.serviceConnectionPolicies. create 
-  networkconnectivity.serviceConnectionPolicies. delete 
-  networkconnectivity.serviceConnectionPolicies. get 
-  networkconnectivity.serviceConnectionPolicies. list 
-  networkconnectivity.serviceConnectionPolicies. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Group Admin
( roles/  
)
Enables full access to group resources and read-only access to hub and spoke resources
 networkconnectivity.  
 networkconnectivity.  
  networkconnectivity.groups.* 
 
-  networkconnectivity.groups. acceptSpoke 
-  networkconnectivity.groups. acceptSpokeUpdate 
-  networkconnectivity.groups.get
-  networkconnectivity.groups. getIamPolicy 
-  networkconnectivity.groups. list 
-  networkconnectivity.groups. rejectSpoke 
-  networkconnectivity.groups. rejectSpokeUpdate 
-  networkconnectivity.groups. setIamPolicy 
-  networkconnectivity.groups.use
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.hubs.get 
 networkconnectivity.  
 networkconnectivity.hubs.list 
  networkconnectivity.  
 
-  networkconnectivity.locations. get 
-  networkconnectivity.locations. list 
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.spokes.get 
 networkconnectivity.  
 networkconnectivity.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Group User
( roles/  
)
Enables use access on group resources
 networkconnectivity.groups.use 
Hub & Spoke Admin
( roles/  
)
Enables full access to hub and spoke resources.
Lowest-level resources where you can grant this role:
- Project
  networkconnectivity.  
 
-  networkconnectivity.gatewayAdvertisedRoutes. create 
-  networkconnectivity.gatewayAdvertisedRoutes. delete 
-  networkconnectivity.gatewayAdvertisedRoutes. get 
-  networkconnectivity.gatewayAdvertisedRoutes. list 
-  networkconnectivity.gatewayAdvertisedRoutes. update 
  networkconnectivity.groups.* 
 
-  networkconnectivity.groups. acceptSpoke 
-  networkconnectivity.groups. acceptSpokeUpdate 
-  networkconnectivity.groups.get
-  networkconnectivity.groups. getIamPolicy 
-  networkconnectivity.groups. list 
-  networkconnectivity.groups. rejectSpoke 
-  networkconnectivity.groups. rejectSpokeUpdate 
-  networkconnectivity.groups. setIamPolicy 
-  networkconnectivity.groups.use
  networkconnectivity.  
 
-  networkconnectivity.hubRouteTables. get 
-  networkconnectivity.hubRouteTables. getIamPolicy 
-  networkconnectivity.hubRouteTables. list 
-  networkconnectivity.hubRouteTables. setIamPolicy 
  networkconnectivity.  
 
-  networkconnectivity.hubRoutes. get 
-  networkconnectivity.hubRoutes. getIamPolicy 
-  networkconnectivity.hubRoutes. list 
-  networkconnectivity.hubRoutes. setIamPolicy 
  networkconnectivity.hubs.* 
 
-  networkconnectivity.hubs. create 
-  networkconnectivity.hubs. delete 
-  networkconnectivity.hubs.get
-  networkconnectivity.hubs. getIamPolicy 
-  networkconnectivity.hubs.list
-  networkconnectivity.hubs. listSpokes 
-  networkconnectivity.hubs. queryStatus 
-  networkconnectivity.hubs. setIamPolicy 
-  networkconnectivity.hubs. update 
  networkconnectivity.  
 
-  networkconnectivity.locations. get 
-  networkconnectivity.locations. list 
  networkconnectivity.  
 
-  networkconnectivity.operations. cancel 
-  networkconnectivity.operations. delete 
-  networkconnectivity.operations. get 
-  networkconnectivity.operations. list 
  networkconnectivity.spokes.* 
 
-  networkconnectivity.spokes. create 
-  networkconnectivity.spokes. delete 
-  networkconnectivity.spokes.get
-  networkconnectivity.spokes. getIamPolicy 
-  networkconnectivity.spokes. list 
-  networkconnectivity.spokes. setIamPolicy 
-  networkconnectivity.spokes. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Hub & Spoke Viewer
( roles/  
)
Enables read-only access to hub and spoke resources.
Lowest-level resources where you can grant this role:
- Project
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.groups.get 
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.hubs.get 
 networkconnectivity.  
 networkconnectivity.hubs.list 
 networkconnectivity.  
 networkconnectivity.  
  networkconnectivity.  
 
-  networkconnectivity.locations. get 
-  networkconnectivity.locations. list 
 networkconnectivity.spokes.get 
 networkconnectivity.  
 networkconnectivity.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Multicloud Data Transfer Config Admin
( roles/  
)
Full access to all Multicloud Data Transfer Config resources.
  networkconnectivity.  
 
-  networkconnectivity.multicloudDataTransferConfigs. create 
-  networkconnectivity.multicloudDataTransferConfigs. delete 
-  networkconnectivity.multicloudDataTransferConfigs. get 
-  networkconnectivity.multicloudDataTransferConfigs. list 
-  networkconnectivity.multicloudDataTransferConfigs. update 
  networkconnectivity.  
 
-  networkconnectivity.multicloudDataTransferDestinations. create 
-  networkconnectivity.multicloudDataTransferDestinations. delete 
-  networkconnectivity.multicloudDataTransferDestinations. get 
-  networkconnectivity.multicloudDataTransferDestinations. list 
-  networkconnectivity.multicloudDataTransferDestinations. update 
  networkconnectivity.  
 
-  networkconnectivity.multicloudDataTransferSupportedServices. get 
-  networkconnectivity.multicloudDataTransferSupportedServices. list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Multicloud Data Transfer Config Viewer
( roles/  
)
Read-only access to all Multicloud Data Transfer Config resources.
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
  networkconnectivity.  
 
-  networkconnectivity.multicloudDataTransferSupportedServices. get 
-  networkconnectivity.multicloudDataTransferSupportedServices. list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Destination Admin
( roles/  
)
Access to all Destination resources.
  networkconnectivity.  
 
-  networkconnectivity.multicloudDataTransferDestinations. create 
-  networkconnectivity.multicloudDataTransferDestinations. delete 
-  networkconnectivity.multicloudDataTransferDestinations. get 
-  networkconnectivity.multicloudDataTransferDestinations. list 
-  networkconnectivity.multicloudDataTransferDestinations. update 
  networkconnectivity.  
 
-  networkconnectivity.multicloudDataTransferSupportedServices. get 
-  networkconnectivity.multicloudDataTransferSupportedServices. list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Destination Viewer
( roles/  
)
Read-only access to all Destination resources.
 networkconnectivity.  
 networkconnectivity.  
  networkconnectivity.  
 
-  networkconnectivity.multicloudDataTransferSupportedServices. get 
-  networkconnectivity.multicloudDataTransferSupportedServices. list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Regional Endpoint Admin
( roles/  
)
Full access to all Regional Endpoint resources.
  networkconnectivity.  
 
-  networkconnectivity.regionalEndpoints. create 
-  networkconnectivity.regionalEndpoints. delete 
-  networkconnectivity.regionalEndpoints. get 
-  networkconnectivity.regionalEndpoints. list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Regional Endpoint Viewer
( roles/  
)
Read-only access to all Regional Endpoint resources.
 networkconnectivity.  
 networkconnectivity.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Network Connectivity Service Agent
( roles/  
)
Grants the Network Connectivity API authority to read some networking resources. It does not mutate these resources.
 compute.addresses.create 
 compute.  
 compute.addresses.delete 
 compute.  
 compute.addresses.get 
 compute.addresses.setLabels 
 compute.addresses.use 
 compute.forwardingRules.create 
 compute.forwardingRules.delete 
 compute.forwardingRules.get 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.instances.get 
 compute.  
 compute.networks.get 
 compute.networks.use 
 compute.projects.get 
 compute.regionOperations.get 
 compute.routers.get 
 compute.subnetworks.create 
 compute.subnetworks.delete 
 compute.subnetworks.get 
 compute.  
 compute.subnetworks.list 
 compute.  
 compute.subnetworks.use 
 compute.vpnTunnels.get 
 dns.managedZones.create 
 dns.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 servicedirectory.  
 servicedirectory.  
 servicedirectory.  
 servicedirectory.  
 servicedirectory.  
Service Class User
( roles/  
)
Service Class User uses a ServiceClass
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Service Automation Service Producer Admin
( roles/  
)
Service Automation Producer Admin uses information from a consumer request to manage ServiceClasses and ServiceConnectionMaps
 networkconnectivity.  
 networkconnectivity.  
  networkconnectivity.  
 
-  networkconnectivity.serviceClasses. create 
-  networkconnectivity.serviceClasses. delete 
-  networkconnectivity.serviceClasses. get 
-  networkconnectivity.serviceClasses. list 
-  networkconnectivity.serviceClasses. update 
-  networkconnectivity.serviceClasses. use 
  networkconnectivity.  
 
-  networkconnectivity.serviceConnectionMaps. create 
-  networkconnectivity.serviceConnectionMaps. delete 
-  networkconnectivity.serviceConnectionMaps. get 
-  networkconnectivity.serviceConnectionMaps. list 
-  networkconnectivity.serviceConnectionMaps. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Spoke Admin
( roles/  
)
Enables full access to spoke resources and read-only access to hub resources.
Lowest-level resources where you can grant this role:
- Project
  networkconnectivity.  
 
-  networkconnectivity.gatewayAdvertisedRoutes. create 
-  networkconnectivity.gatewayAdvertisedRoutes. delete 
-  networkconnectivity.gatewayAdvertisedRoutes. get 
-  networkconnectivity.gatewayAdvertisedRoutes. list 
-  networkconnectivity.gatewayAdvertisedRoutes. update 
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.  
 networkconnectivity.hubs.get 
 networkconnectivity.  
 networkconnectivity.hubs.list 
  networkconnectivity.  
 
-  networkconnectivity.locations. get 
-  networkconnectivity.locations. list 
 networkconnectivity.  
 networkconnectivity.  
  networkconnectivity.spokes.* 
 
-  networkconnectivity.spokes. create 
-  networkconnectivity.spokes. delete 
-  networkconnectivity.spokes.get
-  networkconnectivity.spokes. getIamPolicy 
-  networkconnectivity.spokes. list 
-  networkconnectivity.spokes. setIamPolicy 
-  networkconnectivity.spokes. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Network Connectivity Center permissions
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.groups.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.groups.use 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Group Admin 
( roles/  
)
 Group User 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
Service agent roles
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
Service agent roles
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
Service agent roles
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
Service agent roles
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.hubs.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.hubs.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Multicloud Data Transfer Config Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Multicloud Data Transfer Config Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Destination Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Destination Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Multicloud Data Transfer Config Viewer 
( roles/  
)
 Destination Admin 
( roles/  
)
 Destination Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Multicloud Data Transfer Config Viewer 
( roles/  
)
 Destination Admin 
( roles/  
)
 Destination Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Destination Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Multicloud Data Transfer Config Viewer 
( roles/  
)
 Destination Admin 
( roles/  
)
 Destination Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Multicloud Data Transfer Config Admin 
( roles/  
)
 Multicloud Data Transfer Config Viewer 
( roles/  
)
 Destination Admin 
( roles/  
)
 Destination Viewer 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Regional Endpoint Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Regional Endpoint Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Regional Endpoint Admin 
( roles/  
)
 Regional Endpoint Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Regional Endpoint Admin 
( roles/  
)
 Regional Endpoint Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Service Class User 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Service Class User 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Class User 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Service Producer Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Consumer Network Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Consumer Network Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Service Automation Consumer Network Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Databases Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Service Automation Consumer Network Admin 
( roles/  
)
 Cloud Memorystore Redis Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Automation Consumer Network Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.spokes.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Group Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Hub & Spoke Viewer 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)
 networkconnectivity.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Hub & Spoke Admin 
( roles/  
)
 Spoke Admin 
( roles/  
)

