This page lists the IAM roles and permissions for Organization Policy Service. To search through all roles and permissions, see the role and permission index .
Organization Policy Service roles
Organization Policy Administrator
( roles/  
)
Provides access to define what restrictions an organization wants to place on the configuration of cloud resources by setting Organization Policies.
Lowest-level resources where you can grant this role:
- Organization
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listResource 
 cloudasset.  
  orgpolicy.* 
 
-  orgpolicy.constraints.list
-  orgpolicy.customConstraints. create 
-  orgpolicy.customConstraints. delete 
-  orgpolicy.customConstraints. get 
-  orgpolicy.customConstraints. list 
-  orgpolicy.customConstraints. update 
-  orgpolicy.policies.create
-  orgpolicy.policies.delete
-  orgpolicy.policies.list
-  orgpolicy.policies.update
-  orgpolicy.policy.get
-  orgpolicy.policy.set
 policysimulator.  
  policysimulator.  
 
-  policysimulator.orgPolicyViolationsPreviews. create 
-  policysimulator.orgPolicyViolationsPreviews. get 
-  policysimulator.orgPolicyViolationsPreviews. list 
  recommender.  
 
-  recommender.orgPolicyInsights. get 
-  recommender.orgPolicyInsights. list 
-  recommender.orgPolicyInsights. update 
  recommender.  
 
-  recommender.orgPolicyRecommendations. get 
-  recommender.orgPolicyRecommendations. list 
-  recommender.orgPolicyRecommendations. update 
Organization Policy Viewer
( roles/  
)
Provides access to view Organization Policies on resources.
Lowest-level resources where you can grant this role:
- Project
 orgpolicy.constraints.list 
 orgpolicy.  
 orgpolicy.  
 orgpolicy.policies.list 
 orgpolicy.policy.get 
Organization Policy Service permissions
 orgpolicy.constraints.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Organization Policy Viewer 
( roles/  
)
 Folder Admin 
( roles/  
)
 Folder Creator 
( roles/  
)
 Folder Editor 
( roles/  
)
 Folder Viewer 
( roles/  
)
 Organization Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
Service agent roles
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
-  Audit Manager Auditing Service Agent 
( roles/)auditmanager.serviceAgent 
 orgpolicy.  
 
 Organization Policy Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 orgpolicy.  
 
 Organization Policy Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 orgpolicy.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Organization Policy Viewer 
( roles/  
)
 OrgPolicy Simulator Admin 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 orgpolicy.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Organization Policy Viewer 
( roles/  
)
 OrgPolicy Simulator Admin 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 orgpolicy.  
 
 Organization Policy Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 orgpolicy.policies.create 
 
 Assured Workloads Administrator 
( roles/  
)
 Assured Workloads Editor 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 orgpolicy.policies.delete 
 
 Assured Workloads Administrator 
( roles/  
)
 Assured Workloads Editor 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 orgpolicy.policies.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured Workloads Administrator 
( roles/  
)
 Assured Workloads Editor 
( roles/  
)
 Assured Workloads Reader 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Organization Policy Viewer 
( roles/  
)
 OrgPolicy Simulator Admin 
( roles/  
)
 Folder Admin 
( roles/  
)
 Folder Creator 
( roles/  
)
 Folder Editor 
( roles/  
)
 Folder Viewer 
( roles/  
)
 Organization Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
Service agent roles
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Assured Workloads Service Agent 
( roles/)assuredworkloads.serviceAgent 
 orgpolicy.policies.update 
 
 Assured Workloads Administrator 
( roles/  
)
 Assured Workloads Editor 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 orgpolicy.policy.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured Workloads Administrator 
( roles/  
)
 Assured Workloads Editor 
( roles/  
)
 Assured Workloads Reader 
( roles/  
)
 Environment and Storage Object Administrator 
( roles/  
)
 Composer Worker 
( roles/  
)
 Consumer Procurement Entitlement Manager 
( roles/  
)
 Consumer Procurement Entitlement Viewer 
( roles/  
)
 Consumer Procurement Administrator 
( roles/  
)
 Consumer Procurement Viewer 
( roles/  
)
 Application Design Center Admin 
( roles/  
)
 Application Design Center User 
( roles/  
)
 Firebase Admin 
( roles/  
)
 Firebase Develop Admin 
( roles/  
)
 Firebase Admin SDK Administrator Service Agent 
( roles/  
)
 Firebase App Hosting Compute Runner 
( roles/  
)
 Data Scientist 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 ML Engineer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Organization Policy Viewer 
( roles/  
)
 OrgPolicy Simulator Admin 
( roles/  
)
 Folder Admin 
( roles/  
)
 Folder Creator 
( roles/  
)
 Folder Editor 
( roles/  
)
 Folder Viewer 
( roles/  
)
 Organization Administrator 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
 API Keys Admin 
( roles/  
)
 Storage Admin 
( roles/  
)
 Storage Express Mode User Access 
( roles/  
)
 Storage Folder Admin 
( roles/  
)
 Storage HMAC Key Admin 
( roles/  
)
 Storage Object Admin 
( roles/  
)
 Storage Object Creator 
( roles/  
)
 Storage Object User 
( roles/  
)
 Workload Manager Admin 
( roles/  
)
 Workload Manager Evaluation Admin 
( roles/  
)
 Workload Manager Evaluation Viewer 
( roles/  
)
 Workload Manager Viewer 
( roles/  
)
 Workload Manager Worker 
( roles/  
)
Service agent roles
-  Anthos Service Mesh Service Agent 
( roles/)anthosservicemesh.serviceAgent 
-  Assured Workloads Service Agent 
( roles/)assuredworkloads.serviceAgent 
-  Audit Manager Auditing Service Agent 
( roles/)auditmanager.serviceAgent 
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Datapipelines Service Agent 
( roles/)datapipelines.serviceAgent 
-  Cloud Dataplex Service Agent 
( roles/)dataplex.serviceAgent 
-  Dataprep Service Agent 
( roles/)dataprep.serviceAgent 
-  Dataproc Service Agent 
( roles/)dataproc.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  AI Platform Service Agent 
( roles/)ml.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Health Analytics Service Agent 
( roles/)securitycenter.securityHealthAnalyticsServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Visual Inspection AI Service Agent 
( roles/)visualinspection.serviceAgent 
-  Vertex AI Extension Custom Code Service Agent 
( roles/)aiplatform.extensionCustomCodeServiceAgent 
 orgpolicy.policy.set 
 
 Assured Workloads Administrator 
( roles/  
)
 Assured Workloads Editor 
( roles/  
)
 Organization Policy Administrator 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)

