This page lists the IAM roles and permissions for Organization Policy Service. To search through all roles and permissions, see the role and permission index .
Organization Policy Service roles
Organization Policy Administrator
( roles/
)
Provides access to define what restrictions an organization wants to place on the configuration of cloud resources by setting Organization Policies.
Lowest-level resources where you can grant this role:
- Organization
cloudasset.
cloudasset.
cloudasset.assets.listResource
cloudasset.
orgpolicy.*
-
orgpolicy.constraints.list
-
orgpolicy.
customConstraints. create -
orgpolicy.
customConstraints. delete -
orgpolicy.
customConstraints. get -
orgpolicy.
customConstraints. list -
orgpolicy.
customConstraints. update -
orgpolicy.policies.create
-
orgpolicy.policies.delete
-
orgpolicy.policies.list
-
orgpolicy.policies.update
-
orgpolicy.policy.get
-
orgpolicy.policy.set
policysimulator.
policysimulator.
-
policysimulator.
orgPolicyViolationsPreviews. create -
policysimulator.
orgPolicyViolationsPreviews. get -
policysimulator.
orgPolicyViolationsPreviews. list
recommender.
-
recommender.
orgPolicyInsights. get -
recommender.
orgPolicyInsights. list -
recommender.
orgPolicyInsights. update
recommender.
-
recommender.
orgPolicyRecommendations. get -
recommender.
orgPolicyRecommendations. list -
recommender.
orgPolicyRecommendations. update
Organization Policy Viewer
( roles/
)
Provides access to view Organization Policies on resources.
Lowest-level resources where you can grant this role:
- Project
orgpolicy.constraints.list
orgpolicy.
orgpolicy.
orgpolicy.policies.list
orgpolicy.policy.get
Organization Policy Service permissions
orgpolicy.constraints.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Organization Policy Administrator
( roles/
)
Organization Policy Viewer
( roles/
)
Folder Admin
( roles/
)
Folder Creator
( roles/
)
Folder Editor
( roles/
)
Folder Viewer
( roles/
)
Organization Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
Service agent roles
- Cloud Security Compliance Service Agent
(
roles/
)cloudsecuritycompliance.serviceAgent - Audit Manager Auditing Service Agent
(
roles/
)auditmanager.serviceAgent
orgpolicy.
customConstraints.
create
Organization Policy Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
orgpolicy.
customConstraints.
delete
Organization Policy Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
orgpolicy.
customConstraints.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Organization Policy Administrator
( roles/
)
Organization Policy Viewer
( roles/
)
OrgPolicy Simulator Admin
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
orgpolicy.
customConstraints.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Organization Policy Administrator
( roles/
)
Organization Policy Viewer
( roles/
)
OrgPolicy Simulator Admin
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
orgpolicy.
customConstraints.
update
Organization Policy Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
orgpolicy.policies.create
Assured Workloads Administrator
( roles/
)
Assured Workloads Editor
( roles/
)
Organization Policy Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
orgpolicy.policies.delete
Assured Workloads Administrator
( roles/
)
Assured Workloads Editor
( roles/
)
Organization Policy Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
orgpolicy.policies.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Assured Workloads Administrator
( roles/
)
Assured Workloads Editor
( roles/
)
Assured Workloads Reader
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Organization Policy Administrator
( roles/
)
Organization Policy Viewer
( roles/
)
OrgPolicy Simulator Admin
( roles/
)
Folder Admin
( roles/
)
Folder Creator
( roles/
)
Folder Editor
( roles/
)
Folder Viewer
( roles/
)
Organization Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
Service agent roles
- Security Center Control Service Agent
(
roles/
)securitycenter.controlServiceAgent - Security Center Service Agent
(
roles/
)securitycenter.serviceAgent - Assured Workloads Service Agent
(
roles/
)assuredworkloads.serviceAgent
orgpolicy.policies.update
Assured Workloads Administrator
( roles/
)
Assured Workloads Editor
( roles/
)
Organization Policy Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
orgpolicy.policy.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Assured Workloads Administrator
( roles/
)
Assured Workloads Editor
( roles/
)
Assured Workloads Reader
( roles/
)
Environment and Storage Object Administrator
( roles/
)
Composer Worker
( roles/
)
Consumer Procurement Entitlement Manager
( roles/
)
Consumer Procurement Entitlement Viewer
( roles/
)
Consumer Procurement Administrator
( roles/
)
Consumer Procurement Viewer
( roles/
)
Application Design Center Admin
( roles/
)
Application Design Center User
( roles/
)
Firebase Admin
( roles/
)
Firebase Develop Admin
( roles/
)
Firebase Admin SDK Administrator Service Agent
( roles/
)
Data Scientist
( roles/
)
Databases Admin
( roles/
)
Dev Ops
( roles/
)
Infrastructure Administrator
( roles/
)
ML Engineer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Organization Policy Administrator
( roles/
)
Organization Policy Viewer
( roles/
)
OrgPolicy Simulator Admin
( roles/
)
Folder Admin
( roles/
)
Folder Creator
( roles/
)
Folder Editor
( roles/
)
Folder Viewer
( roles/
)
Organization Administrator
( roles/
)
Cloud Run Source Developer
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)
API Keys Admin
( roles/
)
Storage Admin
( roles/
)
Storage Express Mode User Access
( roles/
)
Storage Folder Admin
( roles/
)
Storage HMAC Key Admin
( roles/
)
Storage Object Admin
( roles/
)
Storage Object Creator
( roles/
)
Storage Object User
( roles/
)
Workload Manager Admin
( roles/
)
Workload Manager Evaluation Admin
( roles/
)
Workload Manager Evaluation Viewer
( roles/
)
Workload Manager Viewer
( roles/
)
Workload Manager Worker
( roles/
)
Service agent roles
- Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - Assured Workloads Service Agent
(
roles/
)assuredworkloads.serviceAgent - Audit Manager Auditing Service Agent
(
roles/
)auditmanager.serviceAgent - Cloud Security Compliance Service Agent
(
roles/
)cloudsecuritycompliance.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/
)datafusion.serviceAgent - Datapipelines Service Agent
(
roles/
)datapipelines.serviceAgent - Cloud Dataplex Service Agent
(
roles/
)dataplex.serviceAgent - Dataprep Service Agent
(
roles/
)dataprep.serviceAgent - Dataproc Service Agent
(
roles/
)dataproc.serviceAgent - DLP API Service Agent
(
roles/
)dlp.serviceAgent - AI Platform Service Agent
(
roles/
)ml.serviceAgent - Security Center Control Service Agent
(
roles/
)securitycenter.controlServiceAgent - Security Health Analytics Service Agent
(
roles/
)securitycenter.securityHealthAnalyticsServiceAgent - Security Center Service Agent
(
roles/
)securitycenter.serviceAgent - Visual Inspection AI Service Agent
(
roles/
)visualinspection.serviceAgent - Vertex AI Extension Custom Code Service Agent
(
roles/
)aiplatform.extensionCustomCodeServiceAgent
orgpolicy.policy.set
Assured Workloads Administrator
( roles/
)
Assured Workloads Editor
( roles/
)
Organization Policy Administrator
( roles/
)
Security Posture Admin
( roles/
)
Security Posture Deployer
( roles/
)