This page lists the IAM roles and permissions for Workflows. To search through all roles and permissions, see the role and permission index .
Workflows roles
Workflows Admin
( roles/  
)
Full access to workflows and related resources.
Lowest-level resources where you can grant this role:
- Project
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  workflows.* 
 
-  workflows.callbacks.list
-  workflows.callbacks.send
-  workflows.executions.cancel
-  workflows.executions.create
-  workflows.executions.get
-  workflows.executions.list
-  workflows.locations.get
-  workflows.locations.list
-  workflows.operations.cancel
-  workflows.operations.get
-  workflows.operations.list
-  workflows.stepEntries.get
-  workflows.stepEntries.list
-  workflows.workflows.create
-  workflows.workflows. createTagBinding 
-  workflows.workflows.delete
-  workflows.workflows. deleteTagBinding 
-  workflows.workflows.get
-  workflows.workflows.list
-  workflows.workflows. listEffectiveTags 
-  workflows.workflows. listRevision 
-  workflows.workflows. listTagBindings 
-  workflows.workflows.update
Workflows Editor
( roles/  
)
Read and write access to workflows and related resources, including development and debugging of workflows.
Lowest-level resources where you can grant this role:
- Project
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  workflows.* 
 
-  workflows.callbacks.list
-  workflows.callbacks.send
-  workflows.executions.cancel
-  workflows.executions.create
-  workflows.executions.get
-  workflows.executions.list
-  workflows.locations.get
-  workflows.locations.list
-  workflows.operations.cancel
-  workflows.operations.get
-  workflows.operations.list
-  workflows.stepEntries.get
-  workflows.stepEntries.list
-  workflows.workflows.create
-  workflows.workflows. createTagBinding 
-  workflows.workflows.delete
-  workflows.workflows. deleteTagBinding 
-  workflows.workflows.get
-  workflows.workflows.list
-  workflows.workflows. listEffectiveTags 
-  workflows.workflows. listRevision 
-  workflows.workflows. listTagBindings 
-  workflows.workflows.update
Workflows Invoker
( roles/  
)
Access to execute workflows and manage the executions using the API. Does not provide access to develop and debug workflows.
Lowest-level resources where you can grant this role:
- Project
 resourcemanager.projects.get 
 resourcemanager.projects.list 
  workflows.callbacks.* 
 
-  workflows.callbacks.list
-  workflows.callbacks.send
  workflows.executions.* 
 
-  workflows.executions.cancel
-  workflows.executions.create
-  workflows.executions.get
-  workflows.executions.list
  workflows.stepEntries.* 
 
-  workflows.stepEntries.get
-  workflows.stepEntries.list
Cloud Workflows Service Agent
( roles/  
)
Gives Cloud Workflows service account access to managed resources.
 container.clusters.connect 
 iam.serviceAccounts.get 
 iam.  
 iam.  
 serviceusage.services.use 
Workflows Viewer
( roles/  
)
Read-only access to workflows and related resources.
Lowest-level resources where you can grant this role:
- Project
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 workflows.callbacks.list 
 workflows.executions.get 
 workflows.executions.list 
  workflows.locations.* 
 
-  workflows.locations.get
-  workflows.locations.list
 workflows.operations.get 
 workflows.operations.list 
  workflows.stepEntries.* 
 
-  workflows.stepEntries.get
-  workflows.stepEntries.list
 workflows.workflows.get 
 workflows.workflows.list 
 workflows.  
 workflows.  
 workflows.  
Workflows permissions
 workflows.callbacks.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Invoker 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.callbacks.send 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Invoker 
( roles/  
)
 workflows.executions.cancel 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Invoker 
( roles/  
)
 workflows.executions.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Invoker 
( roles/  
)
 workflows.executions.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Invoker 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.executions.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Invoker 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.locations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.locations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.operations.cancel 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 workflows.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 workflows.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.stepEntries.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Invoker 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.stepEntries.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Invoker 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.workflows.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 workflows.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 workflows.workflows.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 workflows.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Tag User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 workflows.workflows.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
Service agent roles
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 workflows.workflows.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)
 Workflows Viewer 
( roles/  
)
 workflows.workflows.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Workflows Admin 
( roles/  
)
 Workflows Editor 
( roles/  
)

