This topic describes the Identity and Access Management (IAM) roles required to configure Sensitive Data Protection. Roles limit an authenticated identity's ability to access resources. Only grant an identity the permissions it needs in order to interact with applicable Google Cloud APIs, features, or resources.
Standard roles
The following table describes Identity and Access Management roles that are associated with Sensitive Data Protection, and lists permissions that are contained in each role.
DLP Administrator
( roles/  
)
Administer DLP including jobs and templates.
  dlp.* 
 
-  dlp.analyzeRiskTemplates. create 
-  dlp.analyzeRiskTemplates. delete 
-  dlp.analyzeRiskTemplates.get
-  dlp.analyzeRiskTemplates.list
-  dlp.analyzeRiskTemplates. update 
-  dlp.charts.get
-  dlp.columnDataProfiles.get
-  dlp.columnDataProfiles.list
-  dlp.connections.create
-  dlp.connections.delete
-  dlp.connections.get
-  dlp.connections.list
-  dlp.connections.search
-  dlp.connections.update
-  dlp.deidentifyTemplates.create
-  dlp.deidentifyTemplates.delete
-  dlp.deidentifyTemplates.get
-  dlp.deidentifyTemplates.list
-  dlp.deidentifyTemplates.update
-  dlp.estimates.cancel
-  dlp.estimates.create
-  dlp.estimates.delete
-  dlp.estimates.get
-  dlp.estimates.list
-  dlp.fileStoreProfiles.delete
-  dlp.fileStoreProfiles.get
-  dlp.fileStoreProfiles.list
-  dlp.inspectFindings.list
-  dlp.inspectTemplates.create
-  dlp.inspectTemplates.delete
-  dlp.inspectTemplates.get
-  dlp.inspectTemplates.list
-  dlp.inspectTemplates.update
-  dlp.jobTriggers.create
-  dlp.jobTriggers.delete
-  dlp.jobTriggers.get
-  dlp.jobTriggers.hybridInspect
-  dlp.jobTriggers.list
-  dlp.jobTriggers.update
-  dlp.jobs.cancel
-  dlp.jobs.create
-  dlp.jobs.delete
-  dlp.jobs.get
-  dlp.jobs.hybridInspect
-  dlp.jobs.list
-  dlp.kms.encrypt
-  dlp.locations.get
-  dlp.locations.list
-  dlp.projectDataProfiles.get
-  dlp.projectDataProfiles.list
-  dlp.storedInfoTypes.create
-  dlp.storedInfoTypes.delete
-  dlp.storedInfoTypes.get
-  dlp.storedInfoTypes.list
-  dlp.storedInfoTypes.update
-  dlp.subscriptions.cancel
-  dlp.subscriptions.create
-  dlp.subscriptions.get
-  dlp.subscriptions.list
-  dlp.subscriptions.update
-  dlp.tableDataProfiles.delete
-  dlp.tableDataProfiles.get
-  dlp.tableDataProfiles.list
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 serviceusage.services.use 
DLP Analyze Risk Templates Editor
( roles/  
)
Edit DLP analyze risk templates.
  dlp.analyzeRiskTemplates.* 
 
-  dlp.analyzeRiskTemplates. create 
-  dlp.analyzeRiskTemplates. delete 
-  dlp.analyzeRiskTemplates.get
-  dlp.analyzeRiskTemplates.list
-  dlp.analyzeRiskTemplates. update 
DLP Analyze Risk Templates Reader
( roles/  
)
Read DLP analyze risk templates.
 dlp.analyzeRiskTemplates.get 
 dlp.analyzeRiskTemplates.list 
DLP Column Data Profiles Reader
( roles/  
)
Read DLP column profiles.
  dlp.columnDataProfiles.* 
 
-  dlp.columnDataProfiles.get
-  dlp.columnDataProfiles.list
DLP Connections Admin
( roles/  
)
Manage DLP Connections.
  dlp.connections.* 
 
-  dlp.connections.create
-  dlp.connections.delete
-  dlp.connections.get
-  dlp.connections.list
-  dlp.connections.search
-  dlp.connections.update
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DLP Connections Viewer
( roles/  
)
View DLP Connections.
 dlp.connections.get 
 dlp.connections.list 
 dlp.connections.search 
DLP Data Profiles Admin
( roles/  
)
Manage DLP profiles.
 dlp.charts.get 
  dlp.columnDataProfiles.* 
 
-  dlp.columnDataProfiles.get
-  dlp.columnDataProfiles.list
  dlp.fileStoreProfiles.* 
 
-  dlp.fileStoreProfiles.delete
-  dlp.fileStoreProfiles.get
-  dlp.fileStoreProfiles.list
  dlp.projectDataProfiles.* 
 
-  dlp.projectDataProfiles.get
-  dlp.projectDataProfiles.list
  dlp.tableDataProfiles.* 
 
-  dlp.tableDataProfiles.delete
-  dlp.tableDataProfiles.get
-  dlp.tableDataProfiles.list
DLP Data Profiles Reader
( roles/  
)
Read DLP profiles.
 dlp.charts.get 
  dlp.columnDataProfiles.* 
 
-  dlp.columnDataProfiles.get
-  dlp.columnDataProfiles.list
 dlp.fileStoreProfiles.get 
 dlp.fileStoreProfiles.list 
  dlp.projectDataProfiles.* 
 
-  dlp.projectDataProfiles.get
-  dlp.projectDataProfiles.list
 dlp.tableDataProfiles.get 
 dlp.tableDataProfiles.list 
DLP De-identify Templates Editor
( roles/  
)
Edit DLP de-identify templates.
  dlp.deidentifyTemplates.* 
 
-  dlp.deidentifyTemplates.create
-  dlp.deidentifyTemplates.delete
-  dlp.deidentifyTemplates.get
-  dlp.deidentifyTemplates.list
-  dlp.deidentifyTemplates.update
DLP De-identify Templates Reader
( roles/  
)
Read DLP de-identify templates.
 dlp.deidentifyTemplates.get 
 dlp.deidentifyTemplates.list 
DLP Cost Estimation
( roles/  
)
Manage DLP Cost Estimates.
  dlp.estimates.* 
 
-  dlp.estimates.cancel
-  dlp.estimates.create
-  dlp.estimates.delete
-  dlp.estimates.get
-  dlp.estimates.list
DLP File Store Data Profiles Admin
( roles/  
)
Manage DLP file store profiles.
  dlp.fileStoreProfiles.* 
 
-  dlp.fileStoreProfiles.delete
-  dlp.fileStoreProfiles.get
-  dlp.fileStoreProfiles.list
DLP File Store Data Profiles Reader
( roles/  
)
Read DLP file store profiles.
 dlp.charts.get 
 dlp.fileStoreProfiles.get 
 dlp.fileStoreProfiles.list 
DLP Inspect Findings Reader
( roles/  
)
Read DLP stored findings.
 dlp.inspectFindings.list 
DLP Inspect Templates Editor
( roles/  
)
Edit DLP inspect templates.
  dlp.inspectTemplates.* 
 
-  dlp.inspectTemplates.create
-  dlp.inspectTemplates.delete
-  dlp.inspectTemplates.get
-  dlp.inspectTemplates.list
-  dlp.inspectTemplates.update
DLP Inspect Templates Reader
( roles/  
)
Read DLP inspect templates.
 dlp.inspectTemplates.get 
 dlp.inspectTemplates.list 
DLP Job Triggers Editor
( roles/  
)
Edit job triggers configurations.
  dlp.jobTriggers.* 
 
-  dlp.jobTriggers.create
-  dlp.jobTriggers.delete
-  dlp.jobTriggers.get
-  dlp.jobTriggers.hybridInspect
-  dlp.jobTriggers.list
-  dlp.jobTriggers.update
DLP Job Triggers Reader
( roles/  
)
Read job triggers.
 dlp.jobTriggers.get 
 dlp.jobTriggers.list 
DLP Jobs Editor
( roles/  
)
Edit and create jobs
  dlp.jobs.* 
 
-  dlp.jobs.cancel
-  dlp.jobs.create
-  dlp.jobs.delete
-  dlp.jobs.get
-  dlp.jobs.hybridInspect
-  dlp.jobs.list
 dlp.kms.encrypt 
DLP Jobs Reader
( roles/  
)
Read jobs
 dlp.jobs.get 
 dlp.jobs.list 
DLP Organization Data Profiles Driver
( roles/  
)
Permissions needed by the DLP service account to generate data profiles within an organization or folder.
Lowest-level resources where you can grant this role:
- Folder
 aiplatform.agentExamples.get 
 aiplatform.agentExamples.list 
 aiplatform.agents.get 
 aiplatform.agents.list 
 aiplatform.annotationSpecs.get 
 aiplatform.  
 aiplatform.annotations.get 
 aiplatform.annotations.list 
 aiplatform.apps.get 
 aiplatform.apps.list 
 aiplatform.artifacts.get 
 aiplatform.artifacts.list 
 aiplatform.  
 aiplatform.  
 aiplatform.cacheConfigs.get 
 aiplatform.cachedContents.get 
 aiplatform.cachedContents.list 
 aiplatform.consents.get 
 aiplatform.contexts.get 
 aiplatform.contexts.list 
 aiplatform.  
 aiplatform.customJobs.get 
 aiplatform.customJobs.list 
 aiplatform.dataItems.get 
 aiplatform.dataItems.list 
 aiplatform.  
 aiplatform.  
 aiplatform.datasetVersions.get 
 aiplatform.  
 aiplatform.datasets.get 
 aiplatform.datasets.list 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.edgeDevices.get 
 aiplatform.edgeDevices.list 
 aiplatform.endpoints.get 
 aiplatform.endpoints.list 
 aiplatform.entityTypes.get 
 aiplatform.entityTypes.list 
 aiplatform.exampleStores.get 
 aiplatform.exampleStores.list 
 aiplatform.  
 aiplatform.executions.get 
 aiplatform.executions.list 
 aiplatform.  
 aiplatform.extensions.get 
 aiplatform.extensions.list 
 aiplatform.featureGroups.get 
 aiplatform.featureGroups.list 
 aiplatform.  
 aiplatform.  
 aiplatform.featureMonitors.get 
 aiplatform.  
 aiplatform.  
 aiplatform.  
  aiplatform.featureViewSyncs.* 
 
-  aiplatform.featureViewSyncs. get 
-  aiplatform.featureViewSyncs. list 
 aiplatform.  
 aiplatform.featureViews.get 
 aiplatform.featureViews.list 
 aiplatform.  
 aiplatform.features.get 
 aiplatform.features.list 
 aiplatform.featurestores.get 
 aiplatform.featurestores.list 
 aiplatform.humanInTheLoops.get 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.indexEndpoints.get 
 aiplatform.indexEndpoints.list 
 aiplatform.  
 aiplatform.indexes.get 
 aiplatform.indexes.list 
 aiplatform.locations.get 
 aiplatform.locations.list 
 aiplatform.memories.get 
 aiplatform.memories.list 
 aiplatform.metadataSchemas.get 
 aiplatform.  
 aiplatform.metadataStores.get 
 aiplatform.metadataStores.list 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.modelMonitors.get 
 aiplatform.modelMonitors.list 
 aiplatform.  
 aiplatform.  
 aiplatform.models.get 
 aiplatform.models.list 
 aiplatform.nasJobs.get 
 aiplatform.nasJobs.list 
  aiplatform.nasTrialDetails.* 
 
-  aiplatform.nasTrialDetails.get
-  aiplatform.nasTrialDetails. list 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.operations.list 
 aiplatform.  
 aiplatform.  
 aiplatform.pipelineJobs.get 
 aiplatform.pipelineJobs.list 
  aiplatform.  
 
-  aiplatform.provisionedThroughputRevisions. get 
-  aiplatform.provisionedThroughputRevisions. list 
 aiplatform.  
 aiplatform.  
 aiplatform.ragCorpora.get 
 aiplatform.ragCorpora.list 
 aiplatform.ragCorpora.query 
 aiplatform.  
 aiplatform.ragFiles.get 
 aiplatform.ragFiles.list 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.schedules.get 
 aiplatform.schedules.list 
 aiplatform.sessionEvents.list 
 aiplatform.sessions.get 
 aiplatform.sessions.list 
 aiplatform.specialistPools.get 
 aiplatform.  
 aiplatform.  
 aiplatform.studies.get 
 aiplatform.studies.list 
 aiplatform.  
 aiplatform.  
 aiplatform.tensorboardRuns.get 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.tensorboards.get 
 aiplatform.tensorboards.list 
 aiplatform.  
 aiplatform.  
 aiplatform.trials.get 
 aiplatform.trials.list 
 aiplatform.tuningJobs.get 
 aiplatform.tuningJobs.list 
 alloydb.  
 alloydb.  
 alloydb.backups.get 
 alloydb.backups.list 
 alloydb.  
 alloydb.  
 alloydb.  
 alloydb.  
 alloydb.clusters.export 
 alloydb.  
 alloydb.clusters.get 
 alloydb.clusters.list 
 alloydb.  
 alloydb.  
 alloydb.databases.get 
 alloydb.databases.list 
 alloydb.instances.connect 
 alloydb.instances.executeSql 
 alloydb.instances.get 
 alloydb.instances.list 
  alloydb.locations.* 
 
-  alloydb.locations.get
-  alloydb.locations.list
 alloydb.operations.get 
 alloydb.operations.list 
  alloydb.  
 
-  alloydb.supportedDatabaseFlags. get 
-  alloydb.supportedDatabaseFlags. list 
 alloydb.users.get 
 alloydb.users.list 
 alloydb.users.login 
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apihub.apis.createTagBinding 
 apihub.apis.deleteTagBinding 
 apihub.apis.listEffectiveTags 
 apihub.apis.listTagBindings 
 apihub.  
 apihub.  
 apihub.  
 apihub.  
 artifactregistry.  
 artifactregistry.  
 artifactregistry.  
 artifactregistry.  
 bigquery.bireservations.get 
 bigquery.  
 bigquery.  
 bigquery.config.get 
 bigquery.connections.updateTag 
 bigquery.datasets.create 
 bigquery.  
 bigquery.  
 bigquery.datasets.get 
 bigquery.datasets.getIamPolicy 
 bigquery.  
 bigquery.  
 bigquery.datasets.updateTag 
 bigquery.jobs.create 
 bigquery.jobs.get 
 bigquery.jobs.list 
 bigquery.jobs.listAll 
 bigquery.  
  bigquery.models.* 
 
-  bigquery.models.create
-  bigquery.models.delete
-  bigquery.models.export
-  bigquery.models.getData
-  bigquery.models.getMetadata
-  bigquery.models.list
-  bigquery.models.updateData
-  bigquery.models.updateMetadata
-  bigquery.models.updateTag
  bigquery.readsessions.* 
 
-  bigquery.readsessions.create
-  bigquery.readsessions.getData
-  bigquery.readsessions.update
 bigquery.  
 bigquery.  
 bigquery.reservationGroups.get 
 bigquery.  
 bigquery.reservations.get 
 bigquery.reservations.list 
 bigquery.  
 bigquery.reservations.use 
  bigquery.routines.* 
 
-  bigquery.routines.create
-  bigquery.routines.delete
-  bigquery.routines.get
-  bigquery.routines.list
-  bigquery.routines.update
-  bigquery.routines.updateTag
 bigquery.savedqueries.get 
 bigquery.savedqueries.list 
 bigquery.tables.create 
 bigquery.tables.createIndex 
 bigquery.tables.createSnapshot 
 bigquery.  
 bigquery.tables.delete 
 bigquery.tables.deleteIndex 
 bigquery.  
 bigquery.tables.export 
 bigquery.tables.get 
 bigquery.tables.getData 
 bigquery.tables.getIamPolicy 
 bigquery.tables.list 
 bigquery.  
 bigquery.  
 bigquery.tables.replicateData 
 bigquery.  
 bigquery.tables.update 
 bigquery.tables.updateData 
 bigquery.tables.updateIndex 
 bigquery.tables.updateTag 
 bigquery.transfers.get 
 bigquerymigration.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 cloudaicompanion.  
 cloudasset.  
 cloudasset.assets.analyzeMove 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.exportIapWeb 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listIamRoles 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listIapWeb 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listResource 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listTpuNodes 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
  cloudkms.keyHandles.* 
 
-  cloudkms.keyHandles.create
-  cloudkms.keyHandles.get
-  cloudkms.keyHandles.list
 cloudkms.  
 cloudkms.  
 cloudkms.  
 cloudkms.  
 cloudkms.operations.get 
 cloudkms.  
 cloudsql.instances.connect 
 cloudsql.  
 cloudsql.  
 cloudsql.instances.executeSql 
 cloudsql.instances.get 
 cloudsql.  
 cloudsql.  
 cloudsql.instances.login 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.disks.createTagBinding 
 compute.disks.deleteTagBinding 
 compute.  
 compute.disks.listTagBindings 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.images.listTagBindings 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.routes.listTagBindings 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 container.  
 container.  
 container.  
 container.  
  databasesconsole.locations.* 
 
-  databasesconsole.locations.get
-  databasesconsole.locations. list 
 databasesconsole.  
 datacatalog.  
 datacatalog.entries.updateTag 
 datacatalog.  
 datacatalog.  
 datacatalog.  
 datacatalog.tagTemplates.get 
 datacatalog.  
 datacatalog.tagTemplates.use 
  dataform.locations.* 
 
-  dataform.locations.get
-  dataform.locations.list
 dataform.repositories.create 
 dataform.repositories.list 
 datafusion.  
 datafusion.  
 datafusion.  
 datafusion.  
 dataplex.aspectTypes.create 
 dataplex.aspectTypes.get 
 dataplex.aspectTypes.list 
 dataplex.aspectTypes.use 
 dataplex.datascans.create 
 dataplex.datascans.delete 
 dataplex.datascans.get 
 dataplex.datascans.getData 
 dataplex.  
 dataplex.datascans.list 
 dataplex.datascans.run 
 dataplex.datascans.update 
 dataplex.entries.get 
 dataplex.entries.update 
 dataplex.operations.get 
 dataplex.operations.list 
 dataplex.projects.search 
 datastore.  
 datastore.  
 datastore.  
 datastore.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
  dlp.* 
 
-  dlp.analyzeRiskTemplates. create 
-  dlp.analyzeRiskTemplates. delete 
-  dlp.analyzeRiskTemplates.get
-  dlp.analyzeRiskTemplates.list
-  dlp.analyzeRiskTemplates. update 
-  dlp.charts.get
-  dlp.columnDataProfiles.get
-  dlp.columnDataProfiles.list
-  dlp.connections.create
-  dlp.connections.delete
-  dlp.connections.get
-  dlp.connections.list
-  dlp.connections.search
-  dlp.connections.update
-  dlp.deidentifyTemplates.create
-  dlp.deidentifyTemplates.delete
-  dlp.deidentifyTemplates.get
-  dlp.deidentifyTemplates.list
-  dlp.deidentifyTemplates.update
-  dlp.estimates.cancel
-  dlp.estimates.create
-  dlp.estimates.delete
-  dlp.estimates.get
-  dlp.estimates.list
-  dlp.fileStoreProfiles.delete
-  dlp.fileStoreProfiles.get
-  dlp.fileStoreProfiles.list
-  dlp.inspectFindings.list
-  dlp.inspectTemplates.create
-  dlp.inspectTemplates.delete
-  dlp.inspectTemplates.get
-  dlp.inspectTemplates.list
-  dlp.inspectTemplates.update
-  dlp.jobTriggers.create
-  dlp.jobTriggers.delete
-  dlp.jobTriggers.get
-  dlp.jobTriggers.hybridInspect
-  dlp.jobTriggers.list
-  dlp.jobTriggers.update
-  dlp.jobs.cancel
-  dlp.jobs.create
-  dlp.jobs.delete
-  dlp.jobs.get
-  dlp.jobs.hybridInspect
-  dlp.jobs.list
-  dlp.kms.encrypt
-  dlp.locations.get
-  dlp.locations.list
-  dlp.projectDataProfiles.get
-  dlp.projectDataProfiles.list
-  dlp.storedInfoTypes.create
-  dlp.storedInfoTypes.delete
-  dlp.storedInfoTypes.get
-  dlp.storedInfoTypes.list
-  dlp.storedInfoTypes.update
-  dlp.subscriptions.cancel
-  dlp.subscriptions.create
-  dlp.subscriptions.get
-  dlp.subscriptions.list
-  dlp.subscriptions.update
-  dlp.tableDataProfiles.delete
-  dlp.tableDataProfiles.get
-  dlp.tableDataProfiles.list
 domains.  
 domains.  
 domains.  
 domains.  
 file.backups.createTagBinding 
 file.backups.deleteTagBinding 
 file.backups.listEffectiveTags 
 file.backups.listTagBindings 
 file.  
 file.  
 file.  
 file.instances.listTagBindings 
  file.snapshots.* 
 
-  file.snapshots. createTagBinding 
-  file.snapshots. deleteTagBinding 
-  file.snapshots. listEffectiveTags 
-  file.snapshots.listTagBindings
 gkemulticloud.  
 gkemulticloud.  
 gkemulticloud.  
 gkemulticloud.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 iam.  
 iam.  
 iam.  
 iam.  
 logging.  
 logging.  
 logging.  
 logging.  
 managedidentities.  
 managedidentities.  
 managedidentities.  
 managedidentities.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.timeSeries.create 
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.topics.createTagBinding 
 pubsub.topics.deleteTagBinding 
 pubsub.  
 pubsub.topics.listTagBindings 
 pubsub.topics.updateTag 
 recaptchaenterprise.  
 recaptchaenterprise.  
 recaptchaenterprise.  
 recaptchaenterprise.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
  recommender.locations.* 
 
-  recommender.locations.get
-  recommender.locations.list
 redis.  
 redis.  
 redis.  
 redis.  
  resourcemanager.  
 
-  resourcemanager.hierarchyNodes. createTagBinding 
-  resourcemanager.hierarchyNodes. deleteTagBinding 
-  resourcemanager.hierarchyNodes. listEffectiveTags 
-  resourcemanager.hierarchyNodes. listTagBindings 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 resourcemanager.tagKeys.get 
 resourcemanager.tagKeys.list 
  resourcemanager.  
 
-  resourcemanager.tagValueBindings. create 
-  resourcemanager.tagValueBindings. delete 
 resourcemanager.tagValues.get 
 resourcemanager.tagValues.list 
 run.jobs.createTagBinding 
 run.jobs.deleteTagBinding 
 run.jobs.listEffectiveTags 
 run.jobs.listTagBindings 
 run.services.createTagBinding 
 run.services.deleteTagBinding 
 run.services.listEffectiveTags 
 run.services.listTagBindings 
 secretmanager.  
 secretmanager.  
 secretmanager.  
 secretmanager.  
 serviceusage.services.use 
 spanner.  
 spanner.  
 spanner.  
 spanner.  
 storage.  
 storage.  
 storage.buckets.get 
 storage.buckets.getIamPolicy 
 storage.  
 storage.  
 storage.folders.get 
 storage.folders.list 
 storage.managedFolders.get 
 storage.managedFolders.list 
 storage.objects.get 
 storage.objects.getIamPolicy 
 storage.objects.list 
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 workflows.  
 workflows.  
 workflows.  
 workflows.  
 workstations.  
 workstations.  
 workstations.  
 workstations.  
DLP Project Data Profiles Reader
( roles/  
)
Read DLP project profiles.
  dlp.projectDataProfiles.* 
 
-  dlp.projectDataProfiles.get
-  dlp.projectDataProfiles.list
DLP Project Data Profiles Driver
( roles/  
)
Permissions needed by the DLP service account to generate data profiles within a project.
 aiplatform.agentExamples.get 
 aiplatform.agentExamples.list 
 aiplatform.agents.get 
 aiplatform.agents.list 
 aiplatform.annotationSpecs.get 
 aiplatform.  
 aiplatform.annotations.get 
 aiplatform.annotations.list 
 aiplatform.apps.get 
 aiplatform.apps.list 
 aiplatform.artifacts.get 
 aiplatform.artifacts.list 
 aiplatform.  
 aiplatform.  
 aiplatform.cacheConfigs.get 
 aiplatform.cachedContents.get 
 aiplatform.cachedContents.list 
 aiplatform.consents.get 
 aiplatform.contexts.get 
 aiplatform.contexts.list 
 aiplatform.  
 aiplatform.customJobs.get 
 aiplatform.customJobs.list 
 aiplatform.dataItems.get 
 aiplatform.dataItems.list 
 aiplatform.  
 aiplatform.  
 aiplatform.datasetVersions.get 
 aiplatform.  
 aiplatform.datasets.get 
 aiplatform.datasets.list 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.edgeDevices.get 
 aiplatform.edgeDevices.list 
 aiplatform.endpoints.get 
 aiplatform.endpoints.list 
 aiplatform.entityTypes.get 
 aiplatform.entityTypes.list 
 aiplatform.exampleStores.get 
 aiplatform.exampleStores.list 
 aiplatform.  
 aiplatform.executions.get 
 aiplatform.executions.list 
 aiplatform.  
 aiplatform.extensions.get 
 aiplatform.extensions.list 
 aiplatform.featureGroups.get 
 aiplatform.featureGroups.list 
 aiplatform.  
 aiplatform.  
 aiplatform.featureMonitors.get 
 aiplatform.  
 aiplatform.  
 aiplatform.  
  aiplatform.featureViewSyncs.* 
 
-  aiplatform.featureViewSyncs. get 
-  aiplatform.featureViewSyncs. list 
 aiplatform.  
 aiplatform.featureViews.get 
 aiplatform.featureViews.list 
 aiplatform.  
 aiplatform.features.get 
 aiplatform.features.list 
 aiplatform.featurestores.get 
 aiplatform.featurestores.list 
 aiplatform.humanInTheLoops.get 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.indexEndpoints.get 
 aiplatform.indexEndpoints.list 
 aiplatform.  
 aiplatform.indexes.get 
 aiplatform.indexes.list 
 aiplatform.locations.get 
 aiplatform.locations.list 
 aiplatform.memories.get 
 aiplatform.memories.list 
 aiplatform.metadataSchemas.get 
 aiplatform.  
 aiplatform.metadataStores.get 
 aiplatform.metadataStores.list 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.modelMonitors.get 
 aiplatform.modelMonitors.list 
 aiplatform.  
 aiplatform.  
 aiplatform.models.get 
 aiplatform.models.list 
 aiplatform.nasJobs.get 
 aiplatform.nasJobs.list 
  aiplatform.nasTrialDetails.* 
 
-  aiplatform.nasTrialDetails.get
-  aiplatform.nasTrialDetails. list 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.operations.list 
 aiplatform.  
 aiplatform.  
 aiplatform.pipelineJobs.get 
 aiplatform.pipelineJobs.list 
  aiplatform.  
 
-  aiplatform.provisionedThroughputRevisions. get 
-  aiplatform.provisionedThroughputRevisions. list 
 aiplatform.  
 aiplatform.  
 aiplatform.ragCorpora.get 
 aiplatform.ragCorpora.list 
 aiplatform.ragCorpora.query 
 aiplatform.  
 aiplatform.ragFiles.get 
 aiplatform.ragFiles.list 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.schedules.get 
 aiplatform.schedules.list 
 aiplatform.sessionEvents.list 
 aiplatform.sessions.get 
 aiplatform.sessions.list 
 aiplatform.specialistPools.get 
 aiplatform.  
 aiplatform.  
 aiplatform.studies.get 
 aiplatform.studies.list 
 aiplatform.  
 aiplatform.  
 aiplatform.tensorboardRuns.get 
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.  
 aiplatform.tensorboards.get 
 aiplatform.tensorboards.list 
 aiplatform.  
 aiplatform.  
 aiplatform.trials.get 
 aiplatform.trials.list 
 aiplatform.tuningJobs.get 
 aiplatform.tuningJobs.list 
 alloydb.  
 alloydb.  
 alloydb.backups.get 
 alloydb.backups.list 
 alloydb.  
 alloydb.  
 alloydb.  
 alloydb.  
 alloydb.clusters.export 
 alloydb.  
 alloydb.clusters.get 
 alloydb.clusters.list 
 alloydb.  
 alloydb.  
 alloydb.databases.get 
 alloydb.databases.list 
 alloydb.instances.connect 
 alloydb.instances.executeSql 
 alloydb.instances.get 
 alloydb.instances.list 
  alloydb.locations.* 
 
-  alloydb.locations.get
-  alloydb.locations.list
 alloydb.operations.get 
 alloydb.operations.list 
  alloydb.  
 
-  alloydb.supportedDatabaseFlags. get 
-  alloydb.supportedDatabaseFlags. list 
 alloydb.users.get 
 alloydb.users.list 
 alloydb.users.login 
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apigateway.  
 apihub.apis.createTagBinding 
 apihub.apis.deleteTagBinding 
 apihub.apis.listEffectiveTags 
 apihub.apis.listTagBindings 
 apihub.  
 apihub.  
 apihub.  
 apihub.  
 artifactregistry.  
 artifactregistry.  
 artifactregistry.  
 artifactregistry.  
 bigquery.bireservations.get 
 bigquery.  
 bigquery.  
 bigquery.config.get 
 bigquery.connections.updateTag 
 bigquery.datasets.create 
 bigquery.  
 bigquery.  
 bigquery.datasets.get 
 bigquery.datasets.getIamPolicy 
 bigquery.  
 bigquery.  
 bigquery.datasets.updateTag 
 bigquery.jobs.create 
 bigquery.jobs.get 
 bigquery.jobs.list 
 bigquery.jobs.listAll 
 bigquery.  
  bigquery.models.* 
 
-  bigquery.models.create
-  bigquery.models.delete
-  bigquery.models.export
-  bigquery.models.getData
-  bigquery.models.getMetadata
-  bigquery.models.list
-  bigquery.models.updateData
-  bigquery.models.updateMetadata
-  bigquery.models.updateTag
  bigquery.readsessions.* 
 
-  bigquery.readsessions.create
-  bigquery.readsessions.getData
-  bigquery.readsessions.update
 bigquery.  
 bigquery.  
 bigquery.reservationGroups.get 
 bigquery.  
 bigquery.reservations.get 
 bigquery.reservations.list 
 bigquery.  
 bigquery.reservations.use 
  bigquery.routines.* 
 
-  bigquery.routines.create
-  bigquery.routines.delete
-  bigquery.routines.get
-  bigquery.routines.list
-  bigquery.routines.update
-  bigquery.routines.updateTag
 bigquery.savedqueries.get 
 bigquery.savedqueries.list 
 bigquery.tables.create 
 bigquery.tables.createIndex 
 bigquery.tables.createSnapshot 
 bigquery.  
 bigquery.tables.delete 
 bigquery.tables.deleteIndex 
 bigquery.  
 bigquery.tables.export 
 bigquery.tables.get 
 bigquery.tables.getData 
 bigquery.tables.getIamPolicy 
 bigquery.tables.list 
 bigquery.  
 bigquery.  
 bigquery.tables.replicateData 
 bigquery.  
 bigquery.tables.update 
 bigquery.tables.updateData 
 bigquery.tables.updateIndex 
 bigquery.tables.updateTag 
 bigquery.transfers.get 
 bigquerymigration.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 bigtable.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 certificatemanager.  
 cloudaicompanion.  
 cloudasset.  
 cloudasset.assets.analyzeMove 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.exportIapWeb 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listIamRoles 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listIapWeb 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listResource 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.assets.listTpuNodes 
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudasset.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
 clouddeploy.  
  cloudkms.keyHandles.* 
 
-  cloudkms.keyHandles.create
-  cloudkms.keyHandles.get
-  cloudkms.keyHandles.list
 cloudkms.  
 cloudkms.  
 cloudkms.  
 cloudkms.  
 cloudkms.operations.get 
 cloudkms.  
 cloudsql.instances.connect 
 cloudsql.  
 cloudsql.  
 cloudsql.instances.executeSql 
 cloudsql.instances.get 
 cloudsql.  
 cloudsql.  
 cloudsql.instances.login 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.disks.createTagBinding 
 compute.disks.deleteTagBinding 
 compute.  
 compute.disks.listTagBindings 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.images.listTagBindings 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.routes.listTagBindings 
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 container.  
 container.  
 container.  
 container.  
  databasesconsole.locations.* 
 
-  databasesconsole.locations.get
-  databasesconsole.locations. list 
 databasesconsole.  
 datacatalog.  
 datacatalog.entries.updateTag 
 datacatalog.  
 datacatalog.  
 datacatalog.  
 datacatalog.tagTemplates.get 
 datacatalog.  
 datacatalog.tagTemplates.use 
  dataform.locations.* 
 
-  dataform.locations.get
-  dataform.locations.list
 dataform.repositories.create 
 dataform.repositories.list 
 datafusion.  
 datafusion.  
 datafusion.  
 datafusion.  
 dataplex.aspectTypes.create 
 dataplex.aspectTypes.get 
 dataplex.aspectTypes.list 
 dataplex.aspectTypes.use 
 dataplex.datascans.create 
 dataplex.datascans.delete 
 dataplex.datascans.get 
 dataplex.datascans.getData 
 dataplex.  
 dataplex.datascans.list 
 dataplex.datascans.run 
 dataplex.datascans.update 
 dataplex.entries.get 
 dataplex.entries.update 
 dataplex.operations.get 
 dataplex.operations.list 
 dataplex.projects.search 
 datastore.  
 datastore.  
 datastore.  
 datastore.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
 datastream.  
  dlp.* 
 
-  dlp.analyzeRiskTemplates. create 
-  dlp.analyzeRiskTemplates. delete 
-  dlp.analyzeRiskTemplates.get
-  dlp.analyzeRiskTemplates.list
-  dlp.analyzeRiskTemplates. update 
-  dlp.charts.get
-  dlp.columnDataProfiles.get
-  dlp.columnDataProfiles.list
-  dlp.connections.create
-  dlp.connections.delete
-  dlp.connections.get
-  dlp.connections.list
-  dlp.connections.search
-  dlp.connections.update
-  dlp.deidentifyTemplates.create
-  dlp.deidentifyTemplates.delete
-  dlp.deidentifyTemplates.get
-  dlp.deidentifyTemplates.list
-  dlp.deidentifyTemplates.update
-  dlp.estimates.cancel
-  dlp.estimates.create
-  dlp.estimates.delete
-  dlp.estimates.get
-  dlp.estimates.list
-  dlp.fileStoreProfiles.delete
-  dlp.fileStoreProfiles.get
-  dlp.fileStoreProfiles.list
-  dlp.inspectFindings.list
-  dlp.inspectTemplates.create
-  dlp.inspectTemplates.delete
-  dlp.inspectTemplates.get
-  dlp.inspectTemplates.list
-  dlp.inspectTemplates.update
-  dlp.jobTriggers.create
-  dlp.jobTriggers.delete
-  dlp.jobTriggers.get
-  dlp.jobTriggers.hybridInspect
-  dlp.jobTriggers.list
-  dlp.jobTriggers.update
-  dlp.jobs.cancel
-  dlp.jobs.create
-  dlp.jobs.delete
-  dlp.jobs.get
-  dlp.jobs.hybridInspect
-  dlp.jobs.list
-  dlp.kms.encrypt
-  dlp.locations.get
-  dlp.locations.list
-  dlp.projectDataProfiles.get
-  dlp.projectDataProfiles.list
-  dlp.storedInfoTypes.create
-  dlp.storedInfoTypes.delete
-  dlp.storedInfoTypes.get
-  dlp.storedInfoTypes.list
-  dlp.storedInfoTypes.update
-  dlp.subscriptions.cancel
-  dlp.subscriptions.create
-  dlp.subscriptions.get
-  dlp.subscriptions.list
-  dlp.subscriptions.update
-  dlp.tableDataProfiles.delete
-  dlp.tableDataProfiles.get
-  dlp.tableDataProfiles.list
 domains.  
 domains.  
 domains.  
 domains.  
 file.backups.createTagBinding 
 file.backups.deleteTagBinding 
 file.backups.listEffectiveTags 
 file.backups.listTagBindings 
 file.  
 file.  
 file.  
 file.instances.listTagBindings 
  file.snapshots.* 
 
-  file.snapshots. createTagBinding 
-  file.snapshots. deleteTagBinding 
-  file.snapshots. listEffectiveTags 
-  file.snapshots.listTagBindings
 gkemulticloud.  
 gkemulticloud.  
 gkemulticloud.  
 gkemulticloud.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 iam.  
 iam.  
 iam.  
 iam.  
 logging.  
 logging.  
 logging.  
 logging.  
 managedidentities.  
 managedidentities.  
 managedidentities.  
 managedidentities.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 metastore.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.  
 monitoring.timeSeries.create 
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 privateca.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.  
 pubsub.topics.createTagBinding 
 pubsub.topics.deleteTagBinding 
 pubsub.  
 pubsub.topics.listTagBindings 
 pubsub.topics.updateTag 
 recaptchaenterprise.  
 recaptchaenterprise.  
 recaptchaenterprise.  
 recaptchaenterprise.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 recommender.  
  recommender.locations.* 
 
-  recommender.locations.get
-  recommender.locations.list
 redis.  
 redis.  
 redis.  
 redis.  
  resourcemanager.  
 
-  resourcemanager.hierarchyNodes. createTagBinding 
-  resourcemanager.hierarchyNodes. deleteTagBinding 
-  resourcemanager.hierarchyNodes. listEffectiveTags 
-  resourcemanager.hierarchyNodes. listTagBindings 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 resourcemanager.tagKeys.get 
 resourcemanager.tagKeys.list 
  resourcemanager.  
 
-  resourcemanager.tagValueBindings. create 
-  resourcemanager.tagValueBindings. delete 
 resourcemanager.tagValues.get 
 resourcemanager.tagValues.list 
 run.jobs.createTagBinding 
 run.jobs.deleteTagBinding 
 run.jobs.listEffectiveTags 
 run.jobs.listTagBindings 
 run.services.createTagBinding 
 run.services.deleteTagBinding 
 run.services.listEffectiveTags 
 run.services.listTagBindings 
 secretmanager.  
 secretmanager.  
 secretmanager.  
 secretmanager.  
 serviceusage.services.use 
 spanner.  
 spanner.  
 spanner.  
 spanner.  
 storage.  
 storage.  
 storage.buckets.get 
 storage.buckets.getIamPolicy 
 storage.  
 storage.  
 storage.folders.get 
 storage.folders.list 
 storage.managedFolders.get 
 storage.managedFolders.list 
 storage.objects.get 
 storage.objects.getIamPolicy 
 storage.objects.list 
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 transcoder.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 vmwareengine.  
 workflows.  
 workflows.  
 workflows.  
 workflows.  
 workstations.  
 workstations.  
 workstations.  
 workstations.  
DLP Reader
( roles/  
)
Read DLP entities, such as jobs and templates.
 dlp.analyzeRiskTemplates.get 
 dlp.analyzeRiskTemplates.list 
 dlp.deidentifyTemplates.get 
 dlp.deidentifyTemplates.list 
 dlp.inspectFindings.list 
 dlp.inspectTemplates.get 
 dlp.inspectTemplates.list 
 dlp.jobTriggers.get 
 dlp.jobTriggers.list 
 dlp.jobs.get 
 dlp.jobs.list 
  dlp.locations.* 
 
-  dlp.locations.get
-  dlp.locations.list
 dlp.storedInfoTypes.get 
 dlp.storedInfoTypes.list 
DLP API Service Agent
( roles/  
)
Gives the Cloud DLP API service agent permissions for BigQuery, Cloud Storage, Datastore, Pub/Sub, and Cloud KMS.
 appengine.applications.get 
 bigquery.config.get 
 bigquery.dataPolicies.create 
 bigquery.dataPolicies.delete 
 bigquery.dataPolicies.get 
 bigquery.  
 bigquery.dataPolicies.list 
 bigquery.  
 bigquery.dataPolicies.update 
  bigquery.datasets.* 
 
-  bigquery.datasets.create
-  bigquery.datasets. createTagBinding 
-  bigquery.datasets.delete
-  bigquery.datasets. deleteTagBinding 
-  bigquery.datasets.get
-  bigquery.datasets.getIamPolicy
-  bigquery.datasets.link
-  bigquery.datasets. listEffectiveTags 
-  bigquery.datasets. listSharedDatasetUsage 
-  bigquery.datasets. listTagBindings 
-  bigquery.datasets.setIamPolicy
-  bigquery.datasets.update
-  bigquery.datasets.updateTag
 bigquery.jobs.create 
 bigquery.jobs.get 
 bigquery.jobs.update 
  bigquery.models.* 
 
-  bigquery.models.create
-  bigquery.models.delete
-  bigquery.models.export
-  bigquery.models.getData
-  bigquery.models.getMetadata
-  bigquery.models.list
-  bigquery.models.updateData
-  bigquery.models.updateMetadata
-  bigquery.models.updateTag
  bigquery.readsessions.* 
 
-  bigquery.readsessions.create
-  bigquery.readsessions.getData
-  bigquery.readsessions.update
  bigquery.routines.* 
 
-  bigquery.routines.create
-  bigquery.routines.delete
-  bigquery.routines.get
-  bigquery.routines.list
-  bigquery.routines.update
-  bigquery.routines.updateTag
 bigquery.  
 bigquery.  
 bigquery.rowAccessPolicies.get 
 bigquery.  
 bigquery.  
 bigquery.  
 bigquery.  
  bigquery.tables.* 
 
-  bigquery.tables.create
-  bigquery.tables.createIndex
-  bigquery.tables.createSnapshot
-  bigquery.tables. createTagBinding 
-  bigquery.tables.delete
-  bigquery.tables.deleteIndex
-  bigquery.tables.deleteSnapshot
-  bigquery.tables. deleteTagBinding 
-  bigquery.tables.export
-  bigquery.tables.get
-  bigquery.tables.getData
-  bigquery.tables.getIamPolicy
-  bigquery.tables.list
-  bigquery.tables. listEffectiveTags 
-  bigquery.tables. listTagBindings 
-  bigquery.tables.replicateData
-  bigquery.tables. restoreSnapshot 
-  bigquery.tables.setCategory
-  bigquery.tables. setColumnDataPolicy 
-  bigquery.tables.setIamPolicy
-  bigquery.tables.update
-  bigquery.tables.updateData
-  bigquery.tables.updateIndex
-  bigquery.tables.updateTag
 cloudasset.  
 cloudasset.  
 cloudasset.  
 cloudkms.  
 cloudkms.locations.get 
 cloudkms.locations.list 
  databasesconsole.locations.* 
 
-  databasesconsole.locations.get
-  databasesconsole.locations. list 
 databasesconsole.  
 databasesconsole.  
 databasesconsole.  
 databasesconsole.  
 datacatalog.  
 datacatalog.  
  datacatalog.tagTemplates.* 
 
-  datacatalog.tagTemplates. create 
-  datacatalog.tagTemplates. delete 
-  datacatalog.tagTemplates.get
-  datacatalog.tagTemplates. getIamPolicy 
-  datacatalog.tagTemplates. getTag 
-  datacatalog.tagTemplates. setIamPolicy 
-  datacatalog.tagTemplates. update 
-  datacatalog.tagTemplates.use
  dataform.locations.* 
 
-  dataform.locations.get
-  dataform.locations.list
 dataform.repositories.create 
 dataform.repositories.list 
  dataplex.aspectTypes.* 
 
-  dataplex.aspectTypes.create
-  dataplex.aspectTypes.delete
-  dataplex.aspectTypes.get
-  dataplex.aspectTypes. getIamPolicy 
-  dataplex.aspectTypes.list
-  dataplex.aspectTypes. setIamPolicy 
-  dataplex.aspectTypes.update
-  dataplex.aspectTypes.use
  dataplex.datascans.* 
 
-  dataplex.datascans.create
-  dataplex.datascans.delete
-  dataplex.datascans.get
-  dataplex.datascans.getData
-  dataplex.datascans. getIamPolicy 
-  dataplex.datascans.list
-  dataplex.datascans.run
-  dataplex.datascans. setIamPolicy 
-  dataplex.datascans.update
 dataplex.entries.get 
 dataplex.operations.get 
 dataplex.operations.list 
 dataplex.projects.search 
 datastore.databases.get 
 datastore.  
 datastore.databases.list 
  datastore.entities.* 
 
-  datastore.entities.allocateIds
-  datastore.entities.create
-  datastore.entities.delete
-  datastore.entities.get
-  datastore.entities.list
-  datastore.entities.update
 datastore.indexes.list 
  datastore.namespaces.* 
 
-  datastore.namespaces.get
-  datastore.namespaces.list
  datastore.statistics.* 
 
-  datastore.statistics.get
-  datastore.statistics.list
 dlp.analyzeRiskTemplates.get 
 dlp.analyzeRiskTemplates.list 
 dlp.deidentifyTemplates.get 
 dlp.deidentifyTemplates.list 
 dlp.inspectTemplates.get 
 dlp.inspectTemplates.list 
  dlp.jobs.* 
 
-  dlp.jobs.cancel
-  dlp.jobs.create
-  dlp.jobs.delete
-  dlp.jobs.get
-  dlp.jobs.hybridInspect
-  dlp.jobs.list
 dlp.kms.encrypt 
 firebase.projects.get 
 monitoring.timeSeries.create 
 orgpolicy.policy.get 
  pubsub.* 
 
-  pubsub.messageTransforms. validate 
-  pubsub.schemas.attach
-  pubsub.schemas.commit
-  pubsub.schemas.create
-  pubsub.schemas.delete
-  pubsub.schemas.get
-  pubsub.schemas.getIamPolicy
-  pubsub.schemas.list
-  pubsub.schemas.listRevisions
-  pubsub.schemas.rollback
-  pubsub.schemas.setIamPolicy
-  pubsub.schemas.validate
-  pubsub.snapshots.create
-  pubsub.snapshots. createTagBinding 
-  pubsub.snapshots.delete
-  pubsub.snapshots. deleteTagBinding 
-  pubsub.snapshots.get
-  pubsub.snapshots.getIamPolicy
-  pubsub.snapshots.list
-  pubsub.snapshots. listEffectiveTags 
-  pubsub.snapshots. listTagBindings 
-  pubsub.snapshots.seek
-  pubsub.snapshots.setIamPolicy
-  pubsub.snapshots.update
-  pubsub.subscriptions.consume
-  pubsub.subscriptions.create
-  pubsub.subscriptions. createTagBinding 
-  pubsub.subscriptions.delete
-  pubsub.subscriptions. deleteTagBinding 
-  pubsub.subscriptions.get
-  pubsub.subscriptions. getIamPolicy 
-  pubsub.subscriptions.list
-  pubsub.subscriptions. listEffectiveTags 
-  pubsub.subscriptions. listTagBindings 
-  pubsub.subscriptions. setIamPolicy 
-  pubsub.subscriptions.update
-  pubsub.topics. attachSubscription 
-  pubsub.topics.create
-  pubsub.topics.createTagBinding
-  pubsub.topics.delete
-  pubsub.topics.deleteTagBinding
-  pubsub.topics. detachSubscription 
-  pubsub.topics.get
-  pubsub.topics.getIamPolicy
-  pubsub.topics.list
-  pubsub.topics. listEffectiveTags 
-  pubsub.topics.listTagBindings
-  pubsub.topics.publish
-  pubsub.topics.setIamPolicy
-  pubsub.topics.update
-  pubsub.topics.updateTag
  recommender.  
 
-  recommender.iamPolicyInsights. get 
-  recommender.iamPolicyInsights. list 
-  recommender.iamPolicyInsights. update 
  recommender.  
 
-  recommender.iamPolicyRecommendations. get 
-  recommender.iamPolicyRecommendations. list 
-  recommender.iamPolicyRecommendations. update 
  recommender.  
 
-  recommender.storageBucketSoftDeleteInsights. get 
-  recommender.storageBucketSoftDeleteInsights. list 
-  recommender.storageBucketSoftDeleteInsights. update 
  recommender.  
 
-  recommender.storageBucketSoftDeleteRecommendations. get 
-  recommender.storageBucketSoftDeleteRecommendations. list 
-  recommender.storageBucketSoftDeleteRecommendations. update 
 resourcemanager.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 serviceusage.quotas.get 
 serviceusage.services.get 
 serviceusage.services.list 
 serviceusage.services.use 
  storage.anywhereCaches.* 
 
-  storage.anywhereCaches.create
-  storage.anywhereCaches.disable
-  storage.anywhereCaches.get
-  storage.anywhereCaches.list
-  storage.anywhereCaches.pause
-  storage.anywhereCaches.resume
-  storage.anywhereCaches.update
  storage.bucketOperations.* 
 
-  storage.bucketOperations. cancel 
-  storage.bucketOperations.get
-  storage.bucketOperations.list
  storage.buckets.* 
 
-  storage.buckets.create
-  storage.buckets. createTagBinding 
-  storage.buckets.delete
-  storage.buckets. deleteTagBinding 
-  storage.buckets. enableObjectRetention 
-  storage.buckets.get
-  storage.buckets.getIamPolicy
-  storage.buckets.getIpFilter
-  storage.buckets. getObjectInsights 
-  storage.buckets.list
-  storage.buckets. listEffectiveTags 
-  storage.buckets. listTagBindings 
-  storage.buckets.relocate
-  storage.buckets.restore
-  storage.buckets.setIamPolicy
-  storage.buckets.setIpFilter
-  storage.buckets.update
  storage.folders.* 
 
-  storage.folders.create
-  storage.folders.delete
-  storage.folders.get
-  storage.folders.list
-  storage.folders.rename
  storage.intelligenceConfigs.* 
 
-  storage.intelligenceConfigs. get 
-  storage.intelligenceConfigs. update 
  storage.managedFolders.* 
 
-  storage.managedFolders.create
-  storage.managedFolders.delete
-  storage.managedFolders.get
-  storage.managedFolders. getIamPolicy 
-  storage.managedFolders.list
-  storage.managedFolders. setIamPolicy 
  storage.multipartUploads.* 
 
-  storage.multipartUploads.abort
-  storage.multipartUploads. create 
-  storage.multipartUploads.list
-  storage.multipartUploads. listParts 
  storage.objects.* 
 
-  storage.objects.create
-  storage.objects.delete
-  storage.objects.get
-  storage.objects.getIamPolicy
-  storage.objects.list
-  storage.objects.move
-  storage.objects. overrideUnlockedRetention 
-  storage.objects.restore
-  storage.objects.setIamPolicy
-  storage.objects.setRetention
-  storage.objects.update
DLP Stored InfoTypes Editor
( roles/  
)
Edit DLP stored info types.
  dlp.storedInfoTypes.* 
 
-  dlp.storedInfoTypes.create
-  dlp.storedInfoTypes.delete
-  dlp.storedInfoTypes.get
-  dlp.storedInfoTypes.list
-  dlp.storedInfoTypes.update
DLP Stored InfoTypes Reader
( roles/  
)
Read DLP stored info types.
 dlp.storedInfoTypes.get 
 dlp.storedInfoTypes.list 
DLP Subscription Admin
( roles/  
)
Manage DLP subscriptions.
  dlp.subscriptions.* 
 
-  dlp.subscriptions.cancel
-  dlp.subscriptions.create
-  dlp.subscriptions.get
-  dlp.subscriptions.list
-  dlp.subscriptions.update
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DLP Subscription Viewer
( roles/  
)
View DLP subscriptions.
 dlp.subscriptions.get 
 dlp.subscriptions.list 
DLP Table Data Profiles Admin
( roles/  
)
Manage DLP table profiles.
  dlp.tableDataProfiles.* 
 
-  dlp.tableDataProfiles.delete
-  dlp.tableDataProfiles.get
-  dlp.tableDataProfiles.list
DLP Table Data Profiles Reader
( roles/  
)
Read DLP table profiles.
 dlp.tableDataProfiles.get 
 dlp.tableDataProfiles.list 
DLP User
( roles/  
)
Inspect, Redact, and De-identify Content
 dlp.kms.encrypt 
  dlp.locations.* 
 
-  dlp.locations.get
-  dlp.locations.list
 serviceusage.services.use 
Custom roles
If you want to define your own roles to contain bundles of permissions that you specify, use custom roles .

