Send feedback  
  
 Secured Landing Zone roles and permissions  This page lists the IAM roles and permissions for Secured Landing Zone. To
search through all roles and permissions, see the  role and
permission index  
. 
 
 Secured Landing Zone roles  
  
    
  
     
 (  roles/  securedlandingzone.bqdwOrgRemediator ) 
 
  Access to modify (remediate) resources in SLZ BQDW Blueprint at Organization.
 
  
  
   accesscontextmanager.  servicePerimeters.  get 
 
  accesscontextmanager.  servicePerimeters.  list 
 
  accesscontextmanager.  servicePerimeters.  update 
 
  
  
    
 (  roles/  securedlandingzone.bqdwProjectRemediator ) 
 
  Access to modify (remediate) resources in SLZ BQDW Blueprint at Project.
 
  
  
   bigquery.datasets.get 
 
  bigquery.datasets.getIamPolicy 
 
  bigquery.datasets.setIamPolicy 
 
  bigquery.datasets.update 
 
  cloudkms.cryptoKeys.get 
 
  cloudkms.  cryptoKeys.  getIamPolicy 
 
  cloudkms.cryptoKeys.list 
 
  cloudkms.  cryptoKeys.  setIamPolicy 
 
  cloudkms.cryptoKeys.update 
 
  cloudkms.keyRings.getIamPolicy 
 
  cloudkms.keyRings.setIamPolicy 
 
  pubsub.topics.get 
 
  pubsub.topics.getIamPolicy 
 
  pubsub.topics.list 
 
  pubsub.topics.setIamPolicy 
 
  pubsub.topics.update 
 
  resourcemanager.  projects.  update 
 
  serviceusage.services.use 
 
  storage.buckets.get 
 
  storage.buckets.getIamPolicy 
 
  storage.buckets.list 
 
  storage.buckets.setIamPolicy 
 
  storage.buckets.update 
 
  
  
   Overwatch Activator  Beta  
(  roles/  securedlandingzone.overwatchActivator ) 
 
  This role can activate or suspend Overwatches
 
  
  
   resourcemanager.projects.get 
 
  resourcemanager.projects.list 
 
  securedlandingzone.  overwatches.  activate 
 
  securedlandingzone.  overwatches.  suspend 
 
  
  
   Overwatch Admin  Beta  
(  roles/  securedlandingzone.overwatchAdmin ) 
 
  Full access to Overwatches
 
  
  
   resourcemanager.projects.get 
 
  resourcemanager.projects.list 
 
    securedlandingzone.* 
  
 
   securedlandingzone.  operations.  get   
  securedlandingzone.  overwatches.  activate   
  securedlandingzone.  overwatches.  create   
  securedlandingzone.  overwatches.  delete   
  securedlandingzone.  overwatches.  get   
  securedlandingzone.  overwatches.  list   
  securedlandingzone.  overwatches.  suspend   
  securedlandingzone.  overwatches.  update   
  
  
  
  
   Overwatch Viewer  Beta  
(  roles/  securedlandingzone.overwatchViewer ) 
 
  This role can view all properties of Overwatches
 
  
  
   resourcemanager.projects.get 
 
  resourcemanager.projects.list 
 
  securedlandingzone.  operations.  get 
 
  securedlandingzone.  overwatches.  get 
 
  securedlandingzone.  overwatches.  list 
 
  
  
   Secured Landing Zone Service Agent  
 (  roles/  securedlandingzone.serviceAgent ) 
 
  Grants Secured Landing Zone service account permissions to manage resources in the customer project
 
  
  Warning: Do not grant service agent roles to any principals except  service agents  
.   
  
   cloudasset.  assets.  exportOrgPolicy 
 
  cloudasset.  assets.  exportResource 
 
  cloudasset.feeds.create 
 
  cloudasset.feeds.delete 
 
  cloudasset.feeds.update 
 
  logging.logEntries.list 
 
  pubsub.subscriptions.consume 
 
  pubsub.subscriptions.create 
 
  pubsub.subscriptions.delete 
 
  pubsub.  topics.  attachSubscription 
 
  pubsub.topics.create 
 
  pubsub.topics.delete 
 
  pubsub.  topics.  detachSubscription 
 
  pubsub.topics.getIamPolicy 
 
  pubsub.topics.setIamPolicy 
 
  resourcemanager.projects.get 
 
  securitycenter.  assetsecuritymarks.  update 
 
  securitycenter.findings.list 
 
  securitycenter.findings.update 
 
  securitycenter.sources.list 
 
  securitycenter.sources.update 
 
  serviceusage.services.use 
 
  
  
  
  
Secured Landing Zone permissions  
  
  
  
  Send feedback  
  
 
 
  
  Except as otherwise noted, the content of this page is licensed under the  Creative Commons Attribution 4.0 License  
, and code samples are licensed under the  Apache 2.0 License  
. For details, see the  Google Developers Site Policies  
. Java is a registered trademark of Oracle and/or its affiliates. 
 
 Last updated 2025-10-29 UTC.
 
  
    Need to tell us more?  
  
  
 [[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-10-29 UTC."],[],[]]