This page lists the IAM roles and permissions for Workflows. To search through all roles and permissions, see the role and permission index .
Workflows roles
Workflows Admin
( roles/
)
Full access to workflows and related resources.
Lowest-level resources where you can grant this role:
- Project
resourcemanager.projects.get
resourcemanager.projects.list
workflows.*
-
workflows.callbacks.list
-
workflows.callbacks.send
-
workflows.executions.cancel
-
workflows.executions.create
-
workflows.executions.get
-
workflows.executions.list
-
workflows.locations.get
-
workflows.locations.list
-
workflows.operations.cancel
-
workflows.operations.get
-
workflows.operations.list
-
workflows.stepEntries.get
-
workflows.stepEntries.list
-
workflows.workflows.create
-
workflows.
workflows. createTagBinding -
workflows.workflows.delete
-
workflows.
workflows. deleteTagBinding -
workflows.workflows.get
-
workflows.workflows.list
-
workflows.
workflows. listEffectiveTags -
workflows.
workflows. listRevision -
workflows.
workflows. listTagBindings -
workflows.workflows.update
Workflows Editor
( roles/
)
Read and write access to workflows and related resources, including development and debugging of workflows.
Lowest-level resources where you can grant this role:
- Project
resourcemanager.projects.get
resourcemanager.projects.list
workflows.*
-
workflows.callbacks.list
-
workflows.callbacks.send
-
workflows.executions.cancel
-
workflows.executions.create
-
workflows.executions.get
-
workflows.executions.list
-
workflows.locations.get
-
workflows.locations.list
-
workflows.operations.cancel
-
workflows.operations.get
-
workflows.operations.list
-
workflows.stepEntries.get
-
workflows.stepEntries.list
-
workflows.workflows.create
-
workflows.
workflows. createTagBinding -
workflows.workflows.delete
-
workflows.
workflows. deleteTagBinding -
workflows.workflows.get
-
workflows.workflows.list
-
workflows.
workflows. listEffectiveTags -
workflows.
workflows. listRevision -
workflows.
workflows. listTagBindings -
workflows.workflows.update
Workflows Invoker
( roles/
)
Access to execute workflows and manage the executions using the API. Does not provide access to develop and debug workflows.
Lowest-level resources where you can grant this role:
- Project
resourcemanager.projects.get
resourcemanager.projects.list
workflows.callbacks.*
-
workflows.callbacks.list
-
workflows.callbacks.send
workflows.executions.*
-
workflows.executions.cancel
-
workflows.executions.create
-
workflows.executions.get
-
workflows.executions.list
workflows.stepEntries.*
-
workflows.stepEntries.get
-
workflows.stepEntries.list
Cloud Workflows Service Agent
( roles/
)
Gives Cloud Workflows service account access to managed resources.
container.clusters.connect
iam.serviceAccounts.get
iam.
iam.
serviceusage.services.use
Workflows Viewer
( roles/
)
Read-only access to workflows and related resources.
Lowest-level resources where you can grant this role:
- Project
resourcemanager.projects.get
resourcemanager.projects.list
workflows.callbacks.list
workflows.executions.get
workflows.executions.list
workflows.locations.*
-
workflows.locations.get
-
workflows.locations.list
workflows.operations.get
workflows.operations.list
workflows.stepEntries.*
-
workflows.stepEntries.get
-
workflows.stepEntries.list
workflows.workflows.get
workflows.workflows.list
workflows.
workflows.
workflows.
Workflows permissions
workflows.callbacks.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Invoker
( roles/
)
Workflows Viewer
( roles/
)
workflows.callbacks.send
Owner
( roles/
)
Editor
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Invoker
( roles/
)
workflows.executions.cancel
Owner
( roles/
)
Editor
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Invoker
( roles/
)
workflows.executions.create
Owner
( roles/
)
Editor
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Invoker
( roles/
)
workflows.executions.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Invoker
( roles/
)
Workflows Viewer
( roles/
)
workflows.executions.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Invoker
( roles/
)
Workflows Viewer
( roles/
)
workflows.locations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
workflows.locations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
workflows.operations.cancel
Owner
( roles/
)
Editor
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
workflows.operations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
workflows.operations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
workflows.stepEntries.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Invoker
( roles/
)
Workflows Viewer
( roles/
)
workflows.stepEntries.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Invoker
( roles/
)
Workflows Viewer
( roles/
)
workflows.workflows.create
Owner
( roles/
)
Editor
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
workflows.
workflows.
createTagBinding
Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Tag User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
workflows.workflows.delete
Owner
( roles/
)
Editor
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
workflows.
workflows.
deleteTagBinding
Owner
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Tag User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
workflows.workflows.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
Service agent roles
- Eventarc Service Agent
(
roles/
)eventarc.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
workflows.workflows.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
workflows.
workflows.
listEffectiveTags
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
workflows.
workflows.
listRevision
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
workflows.
workflows.
listTagBindings
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
DLP Organization Data Profiles Driver
( roles/
)
DLP Project Data Profiles Driver
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Tag User
( roles/
)
Tag Viewer
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)
Workflows Viewer
( roles/
)
workflows.workflows.update
Owner
( roles/
)
Editor
( roles/
)
Workflows Admin
( roles/
)
Workflows Editor
( roles/
)