This page lists the IAM roles and permissions for Network Management API. To search through all roles and permissions, see the role and permission index .
Network Management API roles
Network Management Admin
( roles/  
)
Full access to Network Management resources.
Lowest-level resources where you can grant this role:
- Project
  networkmanagement.* 
 
-  networkmanagement.connectivitytests. create 
-  networkmanagement.connectivitytests. delete 
-  networkmanagement.connectivitytests. get 
-  networkmanagement.connectivitytests. getIamPolicy 
-  networkmanagement.connectivitytests. list 
-  networkmanagement.connectivitytests. rerun 
-  networkmanagement.connectivitytests. setIamPolicy 
-  networkmanagement.connectivitytests. update 
-  networkmanagement.locations. get 
-  networkmanagement.locations. list 
-  networkmanagement.operations. cancel 
-  networkmanagement.operations. delete 
-  networkmanagement.operations. get 
-  networkmanagement.operations. list 
-  networkmanagement.topologygraphs. read 
-  networkmanagement.vpcflowlogsconfigs. create 
-  networkmanagement.vpcflowlogsconfigs. delete 
-  networkmanagement.vpcflowlogsconfigs. get 
-  networkmanagement.vpcflowlogsconfigs. list 
-  networkmanagement.vpcflowlogsconfigs. update 
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
GCP Network Management Service Agent
( roles/  
)
Grants the GCP Network Management API the authority to complete analysis based on network configurations from Compute Engine and Container Engine.
 cloudsql.instances.get 
 cloudsql.instances.list 
 compute.addresses.get 
 compute.addresses.list 
 compute.backendServices.get 
 compute.backendServices.list 
 compute.  
 compute.  
 compute.firewalls.get 
 compute.firewalls.list 
 compute.forwardingRules.get 
 compute.forwardingRules.list 
 compute.globalAddresses.get 
 compute.globalAddresses.list 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.healthChecks.get 
 compute.healthChecks.list 
 compute.httpHealthChecks.get 
 compute.httpHealthChecks.list 
 compute.httpsHealthChecks.get 
 compute.httpsHealthChecks.list 
 compute.instanceGroups.get 
 compute.instanceGroups.list 
 compute.instances.get 
 compute.instances.list 
 compute.  
 compute.  
 compute.networks.get 
 compute.  
 compute.networks.list 
 compute.  
 compute.packetMirrorings.get 
 compute.packetMirrorings.list 
 compute.  
 compute.  
 compute.regionHealthChecks.get 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.regionUrlMaps.get 
 compute.regionUrlMaps.list 
 compute.routers.get 
 compute.routers.list 
 compute.routes.get 
 compute.routes.list 
 compute.subnetworks.get 
 compute.subnetworks.list 
 compute.targetGrpcProxies.get 
 compute.targetGrpcProxies.list 
 compute.targetHttpProxies.get 
 compute.targetHttpProxies.list 
 compute.targetHttpsProxies.get 
 compute.  
 compute.targetInstances.get 
 compute.targetInstances.list 
 compute.targetPools.get 
 compute.targetPools.list 
 compute.targetSslProxies.get 
 compute.targetSslProxies.list 
 compute.targetTcpProxies.get 
 compute.targetTcpProxies.list 
 compute.targetVpnGateways.get 
 compute.targetVpnGateways.list 
 compute.urlMaps.get 
 compute.urlMaps.list 
 compute.vpnGateways.get 
 compute.vpnGateways.list 
 compute.vpnTunnels.get 
 compute.vpnTunnels.list 
 container.clusters.get 
 container.clusters.list 
 container.nodes.get 
 container.nodes.list 
Network Management Viewer
( roles/  
)
Read-only access to Network Management resources.
Lowest-level resources where you can grant this role:
- Project
 networkmanagement.  
 networkmanagement.  
 networkmanagement.  
  networkmanagement.locations.* 
 
-  networkmanagement.locations. get 
-  networkmanagement.locations. list 
 networkmanagement.  
 networkmanagement.  
 networkmanagement.  
 networkmanagement.  
 networkmanagement.  
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Network Management API permissions
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Database Migration Service Agent 
( roles/)datamigration.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Network Management Admin 
( roles/  
)
 Network Management Viewer 
( roles/  
)
 networkmanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Network Administrator 
( roles/  
)
 Network Management Admin 
( roles/  
)

