This page lists the IAM roles and permissions for Google Cloud VMware Engine. To search through all roles and permissions, see the role and permission index .
Google Cloud VMware Engine roles
VMware Engine Service Agent
( roles/  
)
Gives permission to manage network configuration, such as establishing network peering, necessary for GCVE
 compute.globalAddresses.get 
 compute.globalAddresses.list 
 compute.globalOperations.get 
 compute.networks.addPeering 
 compute.networks.get 
 compute.networks.list 
 compute.  
 compute.networks.removePeering 
 compute.networks.update 
 compute.networks.updatePeering 
 compute.networks.updatePolicy 
 compute.projects.get 
 compute.regionOperations.get 
 compute.routers.get 
 compute.routers.list 
 compute.routes.list 
 compute.subnetworks.get 
 compute.subnetworks.list 
  dns.changes.* 
 
-  dns.changes.create
-  dns.changes.get
-  dns.changes.list
  dns.dnsKeys.* 
 
-  dns.dnsKeys.get
-  dns.dnsKeys.list
  dns.gkeClusters.* 
 
-  dns.gkeClusters. bindDNSResponsePolicy 
-  dns.gkeClusters. bindPrivateDNSZone 
  dns.managedZoneOperations.* 
 
-  dns.managedZoneOperations.get
-  dns.managedZoneOperations.list
 dns.managedZones.create 
 dns.managedZones.delete 
 dns.managedZones.get 
 dns.managedZones.getIamPolicy 
 dns.managedZones.list 
 dns.managedZones.update 
  dns.networks.* 
 
-  dns.networks. bindDNSResponsePolicy 
-  dns.networks. bindPrivateDNSPolicy 
-  dns.networks. bindPrivateDNSZone 
-  dns.networks. targetWithPeeringZone 
-  dns.networks.useHealthSignals
 dns.policies.create 
 dns.policies.delete 
 dns.policies.get 
 dns.policies.list 
 dns.policies.listEffectiveTags 
 dns.policies.listTagBindings 
 dns.policies.update 
 dns.projects.get 
  dns.resourceRecordSets.* 
 
-  dns.resourceRecordSets.create
-  dns.resourceRecordSets.delete
-  dns.resourceRecordSets.get
-  dns.resourceRecordSets.list
-  dns.resourceRecordSets.update
  dns.responsePolicies.* 
 
-  dns.responsePolicies.create
-  dns.responsePolicies.delete
-  dns.responsePolicies.get
-  dns.responsePolicies.list
-  dns.responsePolicies.update
  dns.responsePolicyRules.* 
 
-  dns.responsePolicyRules.create
-  dns.responsePolicyRules.delete
-  dns.responsePolicyRules.get
-  dns.responsePolicyRules.list
-  dns.responsePolicyRules.update
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 vmwareengine.  
 vmwareengine.  
  vmwareengine.nodes.* 
 
-  vmwareengine.nodes.get
-  vmwareengine.nodes.list
VMware Engine Service Admin
( roles/  
)
Admin has full access to VMware Engine Service
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  vmwareengine.* 
 
-  vmwareengine.clusters.create
-  vmwareengine.clusters.delete
-  vmwareengine.clusters.get
-  vmwareengine.clusters. getIamPolicy 
-  vmwareengine.clusters.list
-  vmwareengine.clusters. setIamPolicy 
-  vmwareengine.clusters.update
-  vmwareengine.dnsBindPermission. get 
-  vmwareengine.dnsBindPermission. grant 
-  vmwareengine.dnsBindPermission. revoke 
-  vmwareengine.dnsForwarding.get
-  vmwareengine.dnsForwarding. update 
-  vmwareengine.externalAccessRules. create 
-  vmwareengine.externalAccessRules. delete 
-  vmwareengine.externalAccessRules. get 
-  vmwareengine.externalAccessRules. list 
-  vmwareengine.externalAccessRules. update 
-  vmwareengine.externalAddresses. create 
-  vmwareengine.externalAddresses. delete 
-  vmwareengine.externalAddresses. get 
-  vmwareengine.externalAddresses. list 
-  vmwareengine.externalAddresses. update 
-  vmwareengine.hcxActivationKeys. create 
-  vmwareengine.hcxActivationKeys. get 
-  vmwareengine.hcxActivationKeys. getIamPolicy 
-  vmwareengine.hcxActivationKeys. list 
-  vmwareengine.hcxActivationKeys. setIamPolicy 
-  vmwareengine.locations.get
-  vmwareengine.locations.list
-  vmwareengine.loggingServers. create 
-  vmwareengine.loggingServers. delete 
-  vmwareengine.loggingServers. get 
-  vmwareengine.loggingServers. list 
-  vmwareengine.loggingServers. update 
-  vmwareengine.managementDnsZoneBindings. create 
-  vmwareengine.managementDnsZoneBindings. delete 
-  vmwareengine.managementDnsZoneBindings. get 
-  vmwareengine.managementDnsZoneBindings. list 
-  vmwareengine.managementDnsZoneBindings. repair 
-  vmwareengine.managementDnsZoneBindings. update 
-  vmwareengine.networkPeerings. create 
-  vmwareengine.networkPeerings. createTagBinding 
-  vmwareengine.networkPeerings. delete 
-  vmwareengine.networkPeerings. deleteTagBinding 
-  vmwareengine.networkPeerings. get 
-  vmwareengine.networkPeerings. list 
-  vmwareengine.networkPeerings. listEffectiveTags 
-  vmwareengine.networkPeerings. listPeeringRoutes 
-  vmwareengine.networkPeerings. listTagBindings 
-  vmwareengine.networkPeerings. update 
-  vmwareengine.networkPolicies. create 
-  vmwareengine.networkPolicies. createTagBinding 
-  vmwareengine.networkPolicies. delete 
-  vmwareengine.networkPolicies. deleteTagBinding 
-  vmwareengine.networkPolicies. fetchExternalAddresses 
-  vmwareengine.networkPolicies. get 
-  vmwareengine.networkPolicies. list 
-  vmwareengine.networkPolicies. listEffectiveTags 
-  vmwareengine.networkPolicies. listTagBindings 
-  vmwareengine.networkPolicies. update 
-  vmwareengine.nodeTypes.get
-  vmwareengine.nodeTypes.list
-  vmwareengine.nodes.get
-  vmwareengine.nodes.list
-  vmwareengine.operations.delete
-  vmwareengine.operations.get
-  vmwareengine.operations.list
-  vmwareengine.privateClouds. create 
-  vmwareengine.privateClouds. createTagBinding 
-  vmwareengine.privateClouds. delete 
-  vmwareengine.privateClouds. deleteTagBinding 
-  vmwareengine.privateClouds.get
-  vmwareengine.privateClouds. getIamPolicy 
-  vmwareengine.privateClouds. list 
-  vmwareengine.privateClouds. listEffectiveTags 
-  vmwareengine.privateClouds. listTagBindings 
-  vmwareengine.privateClouds. resetNsxCredentials 
-  vmwareengine.privateClouds. resetVcenterCredentials 
-  vmwareengine.privateClouds. setIamPolicy 
-  vmwareengine.privateClouds. showNsxCredentials 
-  vmwareengine.privateClouds. showVcenterCredentials 
-  vmwareengine.privateClouds. undelete 
-  vmwareengine.privateClouds. update 
-  vmwareengine.privateConnections. create 
-  vmwareengine.privateConnections. createTagBinding 
-  vmwareengine.privateConnections. delete 
-  vmwareengine.privateConnections. deleteTagBinding 
-  vmwareengine.privateConnections. get 
-  vmwareengine.privateConnections. list 
-  vmwareengine.privateConnections. listEffectiveTags 
-  vmwareengine.privateConnections. listPeeringRoutes 
-  vmwareengine.privateConnections. listTagBindings 
-  vmwareengine.privateConnections. update 
-  vmwareengine.projectState.get
-  vmwareengine.services.use
-  vmwareengine.services.view
-  vmwareengine.subnets.get
-  vmwareengine.subnets.list
-  vmwareengine.subnets.update
-  vmwareengine.vmwareEngineNetworks. create 
-  vmwareengine.vmwareEngineNetworks. createTagBinding 
-  vmwareengine.vmwareEngineNetworks. delete 
-  vmwareengine.vmwareEngineNetworks. deleteTagBinding 
-  vmwareengine.vmwareEngineNetworks. get 
-  vmwareengine.vmwareEngineNetworks. list 
-  vmwareengine.vmwareEngineNetworks. listEffectiveTags 
-  vmwareengine.vmwareEngineNetworks. listTagBindings 
-  vmwareengine.vmwareEngineNetworks. update 
VMware Engine Service Privileged User
( roles/  
)
Privileged User has access to VMWare Engine Service Privileged API
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 vmwareengine.clusters.delete 
 vmwareengine.clusters.get 
 vmwareengine.  
 vmwareengine.clusters.list 
 vmwareengine.  
 vmwareengine.dnsForwarding.get 
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
  vmwareengine.locations.* 
 
-  vmwareengine.locations.get
-  vmwareengine.locations.list
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
  vmwareengine.nodeTypes.* 
 
-  vmwareengine.nodeTypes.get
-  vmwareengine.nodeTypes.list
  vmwareengine.nodes.* 
 
-  vmwareengine.nodes.get
-  vmwareengine.nodes.list
 vmwareengine.operations.get 
 vmwareengine.operations.list 
 vmwareengine.privateClouds.get 
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.projectState.get 
  vmwareengine.services.* 
 
-  vmwareengine.services.use
-  vmwareengine.services.view
 vmwareengine.subnets.get 
 vmwareengine.subnets.list 
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
VMware Engine Service Viewer
( roles/  
)
Viewer has read-only access to VMware Engine Service
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 vmwareengine.clusters.get 
 vmwareengine.  
 vmwareengine.clusters.list 
 vmwareengine.  
 vmwareengine.dnsForwarding.get 
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
  vmwareengine.locations.* 
 
-  vmwareengine.locations.get
-  vmwareengine.locations.list
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
  vmwareengine.nodeTypes.* 
 
-  vmwareengine.nodeTypes.get
-  vmwareengine.nodeTypes.list
  vmwareengine.nodes.* 
 
-  vmwareengine.nodes.get
-  vmwareengine.nodes.list
 vmwareengine.operations.get 
 vmwareengine.operations.list 
 vmwareengine.privateClouds.get 
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.projectState.get 
 vmwareengine.services.view 
 vmwareengine.subnets.get 
 vmwareengine.subnets.list 
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
Google Cloud VMware Engine permissions
 vmwareengine.clusters.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.clusters.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 vmwareengine.clusters.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.clusters.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.clusters.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.dnsForwarding.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
Service agent roles
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
Service agent roles
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.locations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.locations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.nodeTypes.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.nodeTypes.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.nodes.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
Service agent roles
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
 vmwareengine.nodes.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
Service agent roles
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
 vmwareengine.operations.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.privateClouds.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.projectState.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.services.use 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 vmwareengine.services.view 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.subnets.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.subnets.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.subnets.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)
 VMware Engine Service Privileged User 
( roles/  
)
 VMware Engine Service Viewer 
( roles/  
)
 vmwareengine.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 VMware Engine Service Admin 
( roles/  
)

