This page lists the IAM roles and permissions for Security Center Management API. To search through all roles and permissions, see the role and permission index .
Security Center Management API roles
Security Center Management Admin
( roles/  
)
Full access to manage Cloud Security Command Center services and custom modules configuration.
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  securitycenter.  
 
-  securitycenter.organizationsettings. get 
-  securitycenter.organizationsettings. update 
  securitycenter.  
 
-  securitycenter.securitycentersettings. get 
-  securitycenter.securitycentersettings. update 
  securitycentermanagement.* 
 
-  securitycentermanagement.billingMetadata. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. list 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list 
-  securitycentermanagement.eventThreatDetectionCustomModules. create 
-  securitycentermanagement.eventThreatDetectionCustomModules. delete 
-  securitycentermanagement.eventThreatDetectionCustomModules. get 
-  securitycentermanagement.eventThreatDetectionCustomModules. list 
-  securitycentermanagement.eventThreatDetectionCustomModules. update 
-  securitycentermanagement.eventThreatDetectionCustomModules. validate 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
-  securitycentermanagement.securityCenterServices. get 
-  securitycentermanagement.securityCenterServices. list 
-  securitycentermanagement.securityCenterServices. update 
-  securitycentermanagement.securityCommandCenter. activate 
-  securitycentermanagement.securityCommandCenter. checkActivationOperation 
-  securitycentermanagement.securityCommandCenter. checkEligibility 
-  securitycentermanagement.securityCommandCenter. checkOnboardingStatus 
-  securitycentermanagement.securityCommandCenter. generateServiceAccounts 
-  securitycentermanagement.securityCommandCenter. get 
-  securitycentermanagement.securityCommandCenter. update 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. create 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. delete 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. list 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. simulate 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. test 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. update 
Security Center Management Custom Modules Editor
( roles/  
)
Full access to manage Cloud Security Command Center custom modules.
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list 
  securitycentermanagement.  
 
-  securitycentermanagement.eventThreatDetectionCustomModules. create 
-  securitycentermanagement.eventThreatDetectionCustomModules. delete 
-  securitycentermanagement.eventThreatDetectionCustomModules. get 
-  securitycentermanagement.eventThreatDetectionCustomModules. list 
-  securitycentermanagement.eventThreatDetectionCustomModules. update 
-  securitycentermanagement.eventThreatDetectionCustomModules. validate 
  securitycentermanagement.  
 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
  securitycentermanagement.  
 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. create 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. delete 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. list 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. simulate 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. test 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. update 
Security Center Management Custom Modules Viewer
( roles/  
)
Readonly access to Cloud Security Command Center custom modules.
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list 
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
  securitycentermanagement.  
 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
Security Center Management Custom ETD Modules Editor
( roles/  
)
Full access to manage Cloud Security Command Center ETD custom modules.
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. list 
  securitycentermanagement.  
 
-  securitycentermanagement.eventThreatDetectionCustomModules. create 
-  securitycentermanagement.eventThreatDetectionCustomModules. delete 
-  securitycentermanagement.eventThreatDetectionCustomModules. get 
-  securitycentermanagement.eventThreatDetectionCustomModules. list 
-  securitycentermanagement.eventThreatDetectionCustomModules. update 
-  securitycentermanagement.eventThreatDetectionCustomModules. validate 
  securitycentermanagement.  
 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
Security Center Management ETD Custom Modules Viewer
( roles/  
)
Readonly access to Cloud Security Command Center ETD custom modules.
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. list 
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
  securitycentermanagement.  
 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
Security Center Management Services Editor
( roles/  
)
Full access to manage Cloud Security Command Center services configuration.
  securitycentermanagement.  
 
-  securitycentermanagement.securityCenterServices. get 
-  securitycentermanagement.securityCenterServices. list 
-  securitycentermanagement.securityCenterServices. update 
Security Center Management Services Viewer
( roles/  
)
Readonly access to Cloud Security Command Center services configuration.
 securitycentermanagement.  
 securitycentermanagement.  
Security Center Management Settings Editor
( roles/  
)
Full access to manage Cloud Security Command Center settings
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  securitycenter.  
 
-  securitycenter.organizationsettings. get 
-  securitycenter.organizationsettings. update 
  securitycenter.  
 
-  securitycenter.securitycentersettings. get 
-  securitycenter.securitycentersettings. update 
  securitycentermanagement.* 
 
-  securitycentermanagement.billingMetadata. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. list 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list 
-  securitycentermanagement.eventThreatDetectionCustomModules. create 
-  securitycentermanagement.eventThreatDetectionCustomModules. delete 
-  securitycentermanagement.eventThreatDetectionCustomModules. get 
-  securitycentermanagement.eventThreatDetectionCustomModules. list 
-  securitycentermanagement.eventThreatDetectionCustomModules. update 
-  securitycentermanagement.eventThreatDetectionCustomModules. validate 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
-  securitycentermanagement.securityCenterServices. get 
-  securitycentermanagement.securityCenterServices. list 
-  securitycentermanagement.securityCenterServices. update 
-  securitycentermanagement.securityCommandCenter. activate 
-  securitycentermanagement.securityCommandCenter. checkActivationOperation 
-  securitycentermanagement.securityCommandCenter. checkEligibility 
-  securitycentermanagement.securityCommandCenter. checkOnboardingStatus 
-  securitycentermanagement.securityCommandCenter. generateServiceAccounts 
-  securitycentermanagement.securityCommandCenter. get 
-  securitycentermanagement.securityCommandCenter. update 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. create 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. delete 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. list 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. simulate 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. test 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. update 
Security Center Management Settings Viewer
( roles/  
)
Readonly access to Cloud Security Command Center settings
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 securitycenter.  
 securitycenter.  
 securitycentermanagement.  
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list 
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
  securitycentermanagement.  
 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
Security Center Management SHA Custom Modules Editor
( roles/  
)
Full access to manage Cloud Security Command Center SHA custom modules.
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list 
  securitycentermanagement.  
 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
  securitycentermanagement.  
 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. create 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. delete 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. list 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. simulate 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. test 
-  securitycentermanagement.securityHealthAnalyticsCustomModules. update 
Security Center Management SHA Custom Modules Viewer
( roles/  
)
Readonly access to Cloud Security Command Center SHA custom modules.
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list 
  securitycentermanagement.  
 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
Security Center Management Viewer
( roles/  
)
Readonly access to Cloud Security Command Center services and custom modules configuration.
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 securitycenter.  
 securitycenter.  
 securitycentermanagement.  
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. get 
-  securitycentermanagement.effectiveEventThreatDetectionCustomModules. list 
  securitycentermanagement.  
 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get 
-  securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list 
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
  securitycentermanagement.  
 
-  securitycentermanagement.locations. get 
-  securitycentermanagement.locations. list 
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
 securitycentermanagement.  
Security Center Management API permissions
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management ETD Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management ETD Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
 Security Posture Admin 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  DSPM Service Agent 
( roles/)dspm.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
 Security Posture Admin 
( roles/  
)
Service agent roles
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management ETD Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management ETD Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management ETD Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management ETD Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Custom ETD Modules Editor 
( roles/  
)
 Security Center Management ETD Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Services Editor 
( roles/  
)
 Security Center Management Services Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  DSPM Service Agent 
( roles/)dspm.serviceAgent 
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Services Editor 
( roles/  
)
 Security Center Management Services Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Services Editor 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
Service agent roles
-  DSPM Service Agent 
( roles/)dspm.serviceAgent 
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
Service agent roles
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  DSPM Service Agent 
( roles/)dspm.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
Service agent roles
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
 Security Posture Admin 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  DSPM Service Agent 
( roles/)dspm.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
 Security Posture Admin 
( roles/  
)
Service agent roles
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Health Analytics Custom Modules Tester 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Admin Editor 
( roles/  
)
 Security Center Admin Viewer 
( roles/  
)
 Security Health Analytics Custom Modules Tester 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Settings Viewer 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Custom Modules Viewer 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management Settings Viewer 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Viewer 
( roles/  
)
 Security Center Management Viewer 
( roles/  
)
Service agent roles
-  Risk Manager Service Agent 
( roles/)riskmanager.serviceAgent 
 securitycentermanagement.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Security Center Admin 
( roles/  
)
 Security Center Settings Admin 
( roles/  
)
 Security Center Settings Editor 
( roles/  
)
 Security Center Management Admin 
( roles/  
)
 Security Center Management Custom Modules Editor 
( roles/  
)
 Security Center Management Settings Editor 
( roles/  
)
 Security Center Management SHA Custom Modules Editor 
( roles/  
)
 Security Posture Admin 
( roles/  
)
 Security Posture Deployer 
( roles/  
)
Service agent roles
-  Security Center Service Agent 
( roles/)securitycenter.serviceAgent 
-  Security Center Control Service Agent 
( roles/)securitycenter.controlServiceAgent 

