This page lists the IAM roles and permissions for Google Cloud Observability. To search through all roles and permissions, see the role and permission index .
Google Cloud Observability roles
Observability Admin Beta
( roles/  
)
Full access to Observability resources.
  observability.* 
 
-  observability.analyticsViews. create 
-  observability.analyticsViews. delete 
-  observability.analyticsViews. get 
-  observability.analyticsViews. list 
-  observability.analyticsViews. update 
-  observability.buckets.create
-  observability.buckets.delete
-  observability.buckets.get
-  observability.buckets.list
-  observability.buckets.undelete
-  observability.buckets.update
-  observability.datasets.create
-  observability.datasets.delete
-  observability.datasets.get
-  observability.datasets.list
-  observability.datasets. undelete 
-  observability.datasets.update
-  observability.links.create
-  observability.links.delete
-  observability.links.get
-  observability.links.list
-  observability.links.update
-  observability.operations. cancel 
-  observability.operations. delete 
-  observability.operations.get
-  observability.operations.list
-  observability.scopes.get
-  observability.scopes.update
-  observability.traceScopes. create 
-  observability.traceScopes. delete 
-  observability.traceScopes.get
-  observability.traceScopes.list
-  observability.traceScopes. update 
-  observability.views.access
-  observability.views.create
-  observability.views.delete
-  observability.views.get
-  observability.views.list
-  observability.views.update
Observability Analytics User Beta
( roles/  
)
Grants permissions to use Cloud Observability Analytics.
 logging.queries.getShared 
 logging.queries.listShared 
 logging.queries.usePrivate 
  observability.analyticsViews.* 
 
-  observability.analyticsViews. create 
-  observability.analyticsViews. delete 
-  observability.analyticsViews. get 
-  observability.analyticsViews. list 
-  observability.analyticsViews. update 
 observability.buckets.get 
 observability.buckets.list 
 observability.datasets.get 
 observability.datasets.list 
 observability.links.get 
 observability.links.list 
 observability.operations.get 
 observability.operations.list 
 observability.scopes.get 
 observability.traceScopes.get 
 observability.traceScopes.list 
 observability.views.get 
 observability.views.list 
Observability Editor Beta
( roles/  
)
Edit access to Observability resources.
  observability.analyticsViews.* 
 
-  observability.analyticsViews. create 
-  observability.analyticsViews. delete 
-  observability.analyticsViews. get 
-  observability.analyticsViews. list 
-  observability.analyticsViews. update 
 observability.buckets.create 
 observability.buckets.get 
 observability.buckets.list 
 observability.buckets.update 
 observability.datasets.create 
 observability.datasets.get 
 observability.datasets.list 
 observability.datasets.update 
  observability.links.* 
 
-  observability.links.create
-  observability.links.delete
-  observability.links.get
-  observability.links.list
-  observability.links.update
  observability.operations.* 
 
-  observability.operations. cancel 
-  observability.operations. delete 
-  observability.operations.get
-  observability.operations.list
  observability.scopes.* 
 
-  observability.scopes.get
-  observability.scopes.update
  observability.traceScopes.* 
 
-  observability.traceScopes. create 
-  observability.traceScopes. delete 
-  observability.traceScopes.get
-  observability.traceScopes.list
-  observability.traceScopes. update 
 observability.views.create 
 observability.views.delete 
 observability.views.get 
 observability.views.list 
 observability.views.update 
Observability Scopes Editor Beta
( roles/  
)
Grants permission to view and edit Observability, Logging, Trace, and Monitoring scopes
  logging.logScopes.* 
 
-  logging.logScopes.create
-  logging.logScopes.delete
-  logging.logScopes.get
-  logging.logScopes.list
-  logging.logScopes.update
 monitoring.metricsScopes.link 
  observability.scopes.* 
 
-  observability.scopes.get
-  observability.scopes.update
  observability.traceScopes.* 
 
-  observability.traceScopes. create 
-  observability.traceScopes. delete 
-  observability.traceScopes.get
-  observability.traceScopes.list
-  observability.traceScopes. update 
Observability Service Agent
( roles/  
)
Grants Observability service account the ability to list, create and link datasets in the consumer project.
 bigquery.datasets.create 
 bigquery.datasets.get 
 bigquery.datasets.link 
Observability View Accessor Beta
( roles/  
)
Read only access to data defined by an Observability View.
 observability.views.access 
Observability Viewer Beta
( roles/  
)
Read only access to Observability resources.
 observability.  
 observability.  
 observability.buckets.get 
 observability.buckets.list 
 observability.datasets.get 
 observability.datasets.list 
 observability.links.get 
 observability.links.list 
 observability.operations.get 
 observability.operations.list 
 observability.scopes.get 
 observability.traceScopes.get 
 observability.traceScopes.list 
 observability.views.get 
 observability.views.list 
Google Cloud Observability permissions
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.buckets.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.buckets.delete 
 
 observability.buckets.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.buckets.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.buckets.undelete 
 
 observability.buckets.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.datasets.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.datasets.delete 
 
 observability.datasets.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.datasets.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.  
 
 observability.datasets.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.links.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.links.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.links.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.links.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.links.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.scopes.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Hub Operator 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Dataproc Hub Agent 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Logging Admin 
( roles/  
)
 Logs Configuration Writer 
( roles/  
)
 Private Logs Viewer 
( roles/  
)
 Logs Viewer 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 Telco Automation Admin 
( roles/  
)
 Telco Automation Tier 1 Operations Admin 
( roles/  
)
 Telco Automation Tier 4 Operations Admin 
( roles/  
)
Service agent roles
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
 observability.scopes.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 observability.traceScopes.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.traceScopes.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Trace Admin 
( roles/  
)
 Cloud Trace User 
( roles/  
)
 Site Reliability Engineer 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Scopes Editor 
( roles/  
)
 observability.views.access 
 
 Owner 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability View Accessor 
( roles/  
)
 observability.views.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.views.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)
 observability.views.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.views.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Analytics User 
( roles/  
)
 Observability Editor 
( roles/  
)
 Observability Viewer 
( roles/  
)
 observability.views.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Observability Admin 
( roles/  
)
 Observability Editor 
( roles/  
)

