This page lists the IAM roles and permissions for Pub/Sub. To search through all roles and permissions, see the role and permission index .
Pub/Sub roles
Pub/Sub Admin
( roles/  
)
Provides full access to topics and subscriptions.
Lowest-level resources where you can grant this role:
- Schema
- Snapshot
- Subscription
- Topic
  pubsub.* 
 
-  pubsub.messageTransforms. validate 
-  pubsub.schemas.attach
-  pubsub.schemas.commit
-  pubsub.schemas.create
-  pubsub.schemas.delete
-  pubsub.schemas.get
-  pubsub.schemas.getIamPolicy
-  pubsub.schemas.list
-  pubsub.schemas.listRevisions
-  pubsub.schemas.rollback
-  pubsub.schemas.setIamPolicy
-  pubsub.schemas.validate
-  pubsub.snapshots.create
-  pubsub.snapshots. createTagBinding 
-  pubsub.snapshots.delete
-  pubsub.snapshots. deleteTagBinding 
-  pubsub.snapshots.get
-  pubsub.snapshots.getIamPolicy
-  pubsub.snapshots.list
-  pubsub.snapshots. listEffectiveTags 
-  pubsub.snapshots. listTagBindings 
-  pubsub.snapshots.seek
-  pubsub.snapshots.setIamPolicy
-  pubsub.snapshots.update
-  pubsub.subscriptions.consume
-  pubsub.subscriptions.create
-  pubsub.subscriptions. createTagBinding 
-  pubsub.subscriptions.delete
-  pubsub.subscriptions. deleteTagBinding 
-  pubsub.subscriptions.get
-  pubsub.subscriptions. getIamPolicy 
-  pubsub.subscriptions.list
-  pubsub.subscriptions. listEffectiveTags 
-  pubsub.subscriptions. listTagBindings 
-  pubsub.subscriptions. setIamPolicy 
-  pubsub.subscriptions.update
-  pubsub.topics. attachSubscription 
-  pubsub.topics.create
-  pubsub.topics.createTagBinding
-  pubsub.topics.delete
-  pubsub.topics.deleteTagBinding
-  pubsub.topics. detachSubscription 
-  pubsub.topics.get
-  pubsub.topics.getIamPolicy
-  pubsub.topics.list
-  pubsub.topics. listEffectiveTags 
-  pubsub.topics.listTagBindings
-  pubsub.topics.publish
-  pubsub.topics.setIamPolicy
-  pubsub.topics.update
-  pubsub.topics.updateTag
 resourcemanager.projects.get 
 serviceusage.quotas.get 
 serviceusage.services.get 
 serviceusage.services.list 
Pub/Sub Editor
( roles/  
)
Provides access to modify topics and subscriptions, and access to publish and consume messages.
Lowest-level resources where you can grant this role:
- Schema
- Snapshot
- Subscription
- Topic
 pubsub.  
 pubsub.schemas.attach 
 pubsub.schemas.commit 
 pubsub.schemas.create 
 pubsub.schemas.delete 
 pubsub.schemas.get 
 pubsub.schemas.list 
 pubsub.schemas.listRevisions 
 pubsub.schemas.rollback 
 pubsub.schemas.validate 
 pubsub.snapshots.create 
 pubsub.  
 pubsub.snapshots.delete 
 pubsub.  
 pubsub.snapshots.get 
 pubsub.snapshots.list 
 pubsub.  
 pubsub.  
 pubsub.snapshots.seek 
 pubsub.snapshots.update 
 pubsub.subscriptions.consume 
 pubsub.subscriptions.create 
 pubsub.  
 pubsub.subscriptions.delete 
 pubsub.  
 pubsub.subscriptions.get 
 pubsub.subscriptions.list 
 pubsub.  
 pubsub.  
 pubsub.subscriptions.update 
 pubsub.  
 pubsub.topics.create 
 pubsub.topics.createTagBinding 
 pubsub.topics.delete 
 pubsub.topics.deleteTagBinding 
 pubsub.  
 pubsub.topics.get 
 pubsub.topics.list 
 pubsub.  
 pubsub.topics.listTagBindings 
 pubsub.topics.publish 
 pubsub.topics.update 
 pubsub.topics.updateTag 
 resourcemanager.projects.get 
 serviceusage.quotas.get 
 serviceusage.services.get 
 serviceusage.services.list 
Pub/Sub Publisher
( roles/  
)
Provides access to publish messages to a topic.
Lowest-level resources where you can grant this role:
- Topic
 pubsub.topics.publish 
Cloud Pub/Sub Service Agent
( roles/  
)
Grants Cloud Pub/Sub Service Account access to manage resources.
 iam.serviceAccounts.get 
 iam.  
 iam.  
 iam.  
 iam.serviceAccounts.list 
 iam.serviceAccounts.signBlob 
 iam.serviceAccounts.signJwt 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 serviceusage.services.use 
Pub/Sub Subscriber
( roles/  
)
Provides access to consume messages from a subscription and to attach subscriptions to a topic.
Lowest-level resources where you can grant this role:
- Snapshot
- Subscription
- Topic
 pubsub.snapshots.seek 
 pubsub.subscriptions.consume 
 pubsub.  
Pub/Sub Viewer
( roles/  
)
Provides access to view topics and subscriptions.
Lowest-level resources where you can grant this role:
- Schema
- Snapshot
- Subscription
- Topic
 pubsub.  
 pubsub.schemas.get 
 pubsub.schemas.list 
 pubsub.schemas.listRevisions 
 pubsub.schemas.validate 
 pubsub.snapshots.get 
 pubsub.snapshots.list 
 pubsub.  
 pubsub.  
 pubsub.subscriptions.get 
 pubsub.subscriptions.list 
 pubsub.  
 pubsub.  
 pubsub.topics.get 
 pubsub.topics.list 
 pubsub.  
 pubsub.topics.listTagBindings 
 resourcemanager.projects.get 
 serviceusage.quotas.get 
 serviceusage.services.get 
 serviceusage.services.list 
Pub/Sub permissions
 pubsub.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.attach 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 pubsub.schemas.commit 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Datapipelines Service Agent 
( roles/)datapipelines.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.getIamPolicy 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.listRevisions 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.rollback 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.setIamPolicy 
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.schemas.validate 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.snapshots.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Tag User 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
 pubsub.snapshots.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Tag User 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
 pubsub.snapshots.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.snapshots.getIamPolicy 
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.snapshots.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.snapshots.seek 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Composer Worker 
( roles/  
)
 Data Scientist 
( roles/  
)
 Dev Ops 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Subscriber 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dialogflow Service Agent 
( roles/)dialogflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Healthcare Service Agent 
( roles/)healthcare.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.snapshots.setIamPolicy 
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.snapshots.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.subscriptions.consume 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Data Scientist 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Subscriber 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dialogflow Service Agent 
( roles/)dialogflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Healthcare Service Agent 
( roles/)healthcare.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Data Plane Service Agent 
( roles/)kuberun.eventsDataPlaneServiceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
 pubsub.subscriptions.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Tag User 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
 pubsub.subscriptions.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Tag User 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
 pubsub.subscriptions.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  KubeRun Events Data Plane Service Agent 
( roles/)kuberun.eventsDataPlaneServiceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
 pubsub.subscriptions.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
 pubsub.subscriptions.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Security Center Admin 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Data Scientist 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Subscriber 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Dialogflow Service Agent 
( roles/)dialogflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Healthcare Service Agent 
( roles/)healthcare.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 pubsub.topics.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Build Service Account 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 pubsub.topics.createTagBinding 
 
 Owner 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Tag User 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
 pubsub.topics.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 pubsub.topics.deleteTagBinding 
 
 Owner 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Tag User 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.topics.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog Viewer 
( roles/  
)
 Firebase Rules System 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 SLZ BQDW Blueprint Project Level Remediator 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Cloud Deploy Service Agent 
( roles/)clouddeploy.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Contact Center AI Insights Service Agent 
( roles/)contactcenterinsights.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Datapipelines Service Agent 
( roles/)datapipelines.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  KubeRun Events Data Plane Service Agent 
( roles/)kuberun.eventsDataPlaneServiceAgent 
-  Media Asset Service Agent 
( roles/)mediaasset.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
 pubsub.topics.getIamPolicy 
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 SLZ BQDW Blueprint Project Level Remediator 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 pubsub.topics.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 Firebase Rules System 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 SLZ BQDW Blueprint Project Level Remediator 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Functions Service Agent 
( roles/)cloudfunctions.serviceAgent 
 pubsub.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.topics.listTagBindings 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Assured OSS Admin 
( roles/  
)
 Assured OSS Project Admin 
( roles/  
)
 Assured OSS Reader 
( roles/  
)
 Composer Worker 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Databases Admin 
( roles/  
)
 Dev Ops 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Viewer 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Source Viewer 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.topics.publish 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Build Service Account 
( roles/  
)
 Composer Worker 
( roles/  
)
 Firebase Rules System 
( roles/  
)
 Data Scientist 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Pub/Sub Publisher 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 Cloud Run Service Agent 
( roles/  
)
 Storage Transfer Agent 
( roles/  
)
Service agent roles
-  Google Batch Service Agent 
( roles/)batch.serviceAgent 
-  Cloud Asset Service Agent 
( roles/)cloudasset.serviceAgent 
-  Cloud Build Service Agent 
( roles/)cloudbuild.serviceAgent 
-  Cloud Deploy Service Agent 
( roles/)clouddeploy.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud IoT Core Service Agent 
( roles/)cloudiot.serviceAgent 
-  Cloud Scheduler Service Agent 
( roles/)cloudscheduler.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Contact Center AI Insights Service Agent 
( roles/)contactcenterinsights.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Container Registry Service Agent 
( roles/)containerregistry.ServiceAgent 
-  Content Warehouse Service Agent 
( roles/)contentwarehouse.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Datastream Service Agent 
( roles/)datastream.serviceAgent 
-  Dialogflow Service Agent 
( roles/)dialogflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Firebase Realtime Database Service Agent 
( roles/)firebasedatabase.serviceAgent 
-  Genomics Service Agent 
( roles/)genomics.serviceAgent 
-  Healthcare Service Agent 
( roles/)healthcare.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  KubeRun Events Data Plane Service Agent 
( roles/)kuberun.eventsDataPlaneServiceAgent 
-  Cloud Life Sciences Service Agent 
( roles/)lifesciences.serviceAgent 
-  Media Asset Service Agent 
( roles/)mediaasset.serviceAgent 
-  Pub/Sub Lite Service Agent 
( roles/)pubsublite.serviceAgent 
-  Security Center Notification Service Agent 
( roles/)securitycenter.notificationServiceAgent 
-  Google Cloud Security Response Service Agent 
( roles/)securitycenter.securityResponseServiceAgent 
-  Cloud Source Repositories Service Agent 
( roles/)sourcerepo.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Transcoder Service Agent 
( roles/)transcoder.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Artifact Registry Service Agent 
( roles/)artifactregistry.serviceAgent 
 pubsub.topics.setIamPolicy 
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 SLZ BQDW Blueprint Project Level Remediator 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  KubeRun Events Control Plane Service Agent 
( roles/)kuberun.eventsControlPlaneServiceAgent 
-  Secured Landing Zone Service Agent 
( roles/)securedlandingzone.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 pubsub.topics.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
 SLZ BQDW Blueprint Project Level Remediator 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Storage Transfer Service Agent 
( roles/)storagetransfer.serviceAgent 
-  Cloud Vision AI Service Agent 
( roles/)visionai.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 pubsub.topics.updateTag 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Worker 
( roles/  
)
 Data Catalog Admin 
( roles/  
)
 Data Catalog Tag Editor 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Dev Ops 
( roles/  
)
 Pub/Sub Admin 
( roles/  
)
 Pub/Sub Editor 
( roles/  
)
 Cloud Run Source Developer 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Container Analysis Service Agent 
( roles/)containeranalysis.ServiceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  DLP API Service Agent 
( roles/)dlp.serviceAgent 
-  Application Integration Service Agent 
( roles/)integrations.serviceAgent 
-  Spectrum SAS Service Agent 
( roles/)spectrumsas.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 

