Cloud Key Management Service roles and permissions
cloudkms.autokeyConfigs.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Autokey Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.autokeyConfigs.update
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Autokey Admin (roles/)
cloudkms.cryptoKeyVersions.create
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
cloudkms.cryptoKeyVersions.destroy
Owner (roles/)
Cloud KMS Admin (roles/)
cloudkms.cryptoKeyVersions.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Viewer (roles/)
Kubernetes Engine KMS Crypto Key User (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.cryptoKeyVersions.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.cryptoKeyVersions.manageRawAesCbcKeys
Owner (roles/)
Cloud KMS Expert Raw AES-CBC Key Manager (roles/)
cloudkms.cryptoKeyVersions.manageRawAesCtrKeys
Owner (roles/)
Cloud KMS Expert Raw AES-CTR Key Manager (roles/)
cloudkms.cryptoKeyVersions.manageRawPKCS1Keys
Owner (roles/)
Cloud KMS Expert Raw PKCS#1 Key Manager (roles/)
cloudkms.cryptoKeyVersions.restore
Owner (roles/)
Cloud KMS Admin (roles/)
cloudkms.cryptoKeyVersions.update
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
cloudkms.cryptoKeyVersions.useToDecapsulate
Owner (roles/)
Cloud KMS Crypto Operator (roles/)
Cloud KMS CryptoKey Decapsulator (roles/)
cloudkms.cryptoKeyVersions.useToDecrypt
Owner (roles/)
Cloud KMS CryptoKey Decrypter (roles/)
Cloud KMS CryptoKey Encrypter/Decrypter (roles/)
Cloud KMS Crypto Operator (roles/)
Data Scientist (roles/)
Dev Ops (roles/)
Service agent roles
-
DLP API Service Agent (
roles/)dlp.serviceAgent -
Cloud KMS KACLS Service Agent (
roles/)cloudkmskacls.serviceAgent
cloudkms.cryptoKeyVersions.useToDecryptViaDelegation
Owner (roles/)
Cloud KMS Admin (roles/)
Cloud KMS CryptoKey Decrypter Via Delegation (roles/)
Cloud KMS CryptoKey Encrypter/Decrypter Via Delegation (roles/)
cloudkms.cryptoKeyVersions.useToEncrypt
Owner (roles/)
Cloud KMS CryptoKey Encrypter (roles/)
Cloud KMS CryptoKey Encrypter/Decrypter (roles/)
Cloud KMS Crypto Operator (roles/)
Data Scientist (roles/)
Dev Ops (roles/)
Service agent roles
-
Cloud KMS KACLS Service Agent (
roles/)cloudkmskacls.serviceAgent
cloudkms.cryptoKeyVersions.useToEncryptViaDelegation
Owner (roles/)
Cloud KMS Admin (roles/)
Cloud KMS CryptoKey Encrypter/Decrypter Via Delegation (roles/)
Cloud KMS CryptoKey Encrypter Via Delegation (roles/)
cloudkms.cryptoKeyVersions.useToSign
Owner (roles/)
Cloud KMS Crypto Operator (roles/)
Cloud KMS CryptoKey Signer (roles/)
Cloud KMS CryptoKey Signer/Verifier (roles/)
Kubernetes Engine KMS Crypto Key User (roles/)
cloudkms.cryptoKeyVersions.useToVerify
Owner (roles/)
Cloud KMS Crypto Operator (roles/)
Cloud KMS CryptoKey Signer/Verifier (roles/)
Cloud KMS CryptoKey Verifier (roles/)
Kubernetes Engine KMS Crypto Key User (roles/)
cloudkms.cryptoKeyVersions.viewPublicKey
Owner (roles/)
Cloud KMS Crypto Operator (roles/)
Cloud KMS CryptoKey Decapsulator (roles/)
Cloud KMS CryptoKey Public Key Viewer (roles/)
Cloud KMS CryptoKey Signer/Verifier (roles/)
Cloud KMS CryptoKey Verifier (roles/)
Kubernetes Engine KMS Crypto Key User (roles/)
cloudkms.cryptoKeys.create
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Service agent roles
-
Cloud KMS Service Agent (
roles/)cloudkms.serviceAgent -
Assured Workloads Service Agent (
roles/)assuredworkloads.serviceAgent
cloudkms.cryptoKeys.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Viewer (roles/)
Kubernetes Engine KMS Crypto Key User (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
SLZ BQDW Blueprint Project Level Remediator (roles/)
Service agent roles
-
Cloud KMS KACLS Service Agent (
roles/)cloudkmskacls.serviceAgent -
Cloud Security Compliance Service Agent (
roles/)cloudsecuritycompliance.serviceAgent -
Audit Manager Auditing Service Agent (
roles/)auditmanager.serviceAgent
cloudkms.cryptoKeys.getIamPolicy
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Support User (roles/)
SLZ BQDW Blueprint Project Level Remediator (roles/)
Service agent roles
-
Cloud KMS Service Agent (
roles/)cloudkms.serviceAgent
cloudkms.cryptoKeys.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
SLZ BQDW Blueprint Project Level Remediator (roles/)
Service agent roles
-
Cloud Security Compliance Service Agent (
roles/)cloudsecuritycompliance.serviceAgent -
Audit Manager Auditing Service Agent (
roles/)auditmanager.serviceAgent
cloudkms.cryptoKeys.setIamPolicy
Owner (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
SLZ BQDW Blueprint Project Level Remediator (roles/)
Service agent roles
-
Cloud KMS Service Agent (
roles/)cloudkms.serviceAgent
cloudkms.cryptoKeys.update
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
SLZ BQDW Blueprint Project Level Remediator (roles/)
cloudkms.ekmConfigs.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS EkmConnections Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.ekmConfigs.getIamPolicy
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Support User (roles/)
cloudkms.ekmConfigs.setIamPolicy
Owner (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
cloudkms.ekmConfigs.update
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS EkmConnections Admin (roles/)
cloudkms.ekmConnections.create
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS EkmConnections Admin (roles/)
cloudkms.ekmConnections.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS EkmConnections Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Service agent roles
-
Cloud Controls Partner EKM Service Agent (
roles/)cloudcontrolspartner.ekmServiceAgent
cloudkms.ekmConnections.getIamPolicy
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Support User (roles/)
Service agent roles
-
Cloud Controls Partner EKM Service Agent (
roles/)cloudcontrolspartner.ekmServiceAgent
cloudkms.ekmConnections.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS EkmConnections Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Service agent roles
-
Cloud Controls Partner EKM Service Agent (
roles/)cloudcontrolspartner.ekmServiceAgent
cloudkms.ekmConnections.setIamPolicy
Owner (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
cloudkms.ekmConnections.update
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS EkmConnections Admin (roles/)
cloudkms.ekmConnections.use
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
cloudkms.ekmConnections.verifyConnectivity
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS EkmConnections Admin (roles/)
Support User (roles/)
Service agent roles
-
Cloud Controls Partner EKM Service Agent (
roles/)cloudcontrolspartner.ekmServiceAgent
cloudkms.importJobs.create
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Importer (roles/)
cloudkms.importJobs.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Importer (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.importJobs.getIamPolicy
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Support User (roles/)
cloudkms.importJobs.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Importer (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.importJobs.setIamPolicy
Owner (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
cloudkms.importJobs.useToImport
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Importer (roles/)
cloudkms.kajPolicyConfigs.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Key Access Justifications Policy Config Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.kajPolicyConfigs.update
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Key Access Justifications Policy Config Admin (roles/)
cloudkms.keyHandles.create
Owner (roles/)
Editor (roles/)
AlloyDB Admin (roles/)
Artifact Registry Administrator (roles/)
BigQuery Admin (roles/)
BigQuery Data Editor (roles/)
BigQuery Data Owner (roles/)
BigQuery Studio Admin (roles/)
BigQuery Studio User (roles/)
BigQuery User (roles/)
Bigtable Administrator (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Autokey User (roles/)
Cloud SQL Admin (roles/)
Composer Administrator (roles/)
Environment and Storage Object Administrator (roles/)
Composer Worker (roles/)
Compute Admin (roles/)
Compute Instance Admin (beta) (roles/)
Compute Instance Admin (v1) (roles/)
Compute Storage Admin (roles/)
Dataflow Admin (roles/)
Dataflow Developer (roles/)
Dataproc Administrator (roles/)
Dataproc Editor (roles/)
Dataproc Serverless Editor (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Firebase Admin (roles/)
Firebase Develop Admin (roles/)
Data Scientist (roles/)
Databases Admin (roles/)
Dev Ops (roles/)
Infrastructure Administrator (roles/)
ML Engineer (roles/)
Network Administrator (roles/)
Site Reliability Engineer (roles/)
Notebooks Legacy Admin (roles/)
Pub/Sub Admin (roles/)
Pub/Sub Editor (roles/)
Cloud Memorystore Redis Admin (roles/)
Cloud Run Source Developer (roles/)
Secret Manager Admin (roles/)
Secure Source Manager Admin (roles/)
Secure Source Manager Instance Owner (roles/)
Cloud Spanner Admin (roles/)
Cloud Spanner Database Admin (roles/)
Storage Admin (roles/)
cloudkms.keyHandles.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
AlloyDB Admin (roles/)
Artifact Registry Administrator (roles/)
BigQuery Admin (roles/)
BigQuery Data Editor (roles/)
BigQuery Data Owner (roles/)
BigQuery Studio Admin (roles/)
BigQuery Studio User (roles/)
BigQuery User (roles/)
Bigtable Administrator (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Autokey User (roles/)
Cloud KMS Viewer (roles/)
Cloud SQL Admin (roles/)
Composer Administrator (roles/)
Environment and Storage Object Administrator (roles/)
Composer Worker (roles/)
Compute Admin (roles/)
Compute Instance Admin (beta) (roles/)
Compute Instance Admin (v1) (roles/)
Compute Storage Admin (roles/)
Dataflow Admin (roles/)
Dataflow Developer (roles/)
Dataproc Administrator (roles/)
Dataproc Editor (roles/)
Dataproc Serverless Editor (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Firebase Admin (roles/)
Firebase Develop Admin (roles/)
Data Scientist (roles/)
Databases Admin (roles/)
Dev Ops (roles/)
Infrastructure Administrator (roles/)
ML Engineer (roles/)
Network Administrator (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Notebooks Legacy Admin (roles/)
Pub/Sub Admin (roles/)
Pub/Sub Editor (roles/)
Cloud Memorystore Redis Admin (roles/)
Cloud Run Source Developer (roles/)
Secret Manager Admin (roles/)
Secure Source Manager Admin (roles/)
Secure Source Manager Instance Owner (roles/)
Cloud Spanner Admin (roles/)
Cloud Spanner Database Admin (roles/)
Storage Admin (roles/)
cloudkms.keyHandles.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
AlloyDB Admin (roles/)
Artifact Registry Administrator (roles/)
BigQuery Admin (roles/)
BigQuery Data Editor (roles/)
BigQuery Data Owner (roles/)
BigQuery Studio Admin (roles/)
BigQuery Studio User (roles/)
BigQuery User (roles/)
Bigtable Administrator (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Autokey User (roles/)
Cloud KMS Viewer (roles/)
Cloud SQL Admin (roles/)
Composer Administrator (roles/)
Environment and Storage Object Administrator (roles/)
Composer Worker (roles/)
Compute Admin (roles/)
Compute Instance Admin (beta) (roles/)
Compute Instance Admin (v1) (roles/)
Compute Storage Admin (roles/)
Dataflow Admin (roles/)
Dataflow Developer (roles/)
Dataproc Administrator (roles/)
Dataproc Editor (roles/)
Dataproc Serverless Editor (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Firebase Admin (roles/)
Firebase Develop Admin (roles/)
Data Scientist (roles/)
Databases Admin (roles/)
Dev Ops (roles/)
Infrastructure Administrator (roles/)
ML Engineer (roles/)
Network Administrator (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Notebooks Legacy Admin (roles/)
Pub/Sub Admin (roles/)
Pub/Sub Editor (roles/)
Cloud Memorystore Redis Admin (roles/)
Cloud Run Source Developer (roles/)
Secret Manager Admin (roles/)
Secure Source Manager Admin (roles/)
Secure Source Manager Instance Owner (roles/)
Cloud Spanner Admin (roles/)
Cloud Spanner Database Admin (roles/)
Storage Admin (roles/)
cloudkms.keyRings.create
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Service agent roles
-
Cloud KMS Service Agent (
roles/)cloudkms.serviceAgent -
Assured Workloads Service Agent (
roles/)assuredworkloads.serviceAgent
cloudkms.keyRings.createTagBinding
Owner (roles/)
Cloud KMS Admin (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Tag User (roles/)
cloudkms.keyRings.deleteTagBinding
Owner (roles/)
Cloud KMS Admin (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Tag User (roles/)
cloudkms.keyRings.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Service agent roles
-
Cloud KMS Service Agent (
roles/)cloudkms.serviceAgent
cloudkms.keyRings.getIamPolicy
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Support User (roles/)
SLZ BQDW Blueprint Project Level Remediator (roles/)
cloudkms.keyRings.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Service agent roles
-
Cloud Security Compliance Service Agent (
roles/)cloudsecuritycompliance.serviceAgent -
Audit Manager Auditing Service Agent (
roles/)auditmanager.serviceAgent
cloudkms.keyRings.listEffectiveTags
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Security Auditor (roles/)
Support User (roles/)
Tag User (roles/)
Tag Viewer (roles/)
cloudkms.keyRings.listTagBindings
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Security Auditor (roles/)
Support User (roles/)
Tag User (roles/)
Tag Viewer (roles/)
cloudkms.keyRings.setIamPolicy
Owner (roles/)
Cloud KMS Admin (roles/)
Security Admin (roles/)
SLZ BQDW Blueprint Project Level Remediator (roles/)
cloudkms.locations.generateRandomBytes
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Crypto Operator (roles/)
Support User (roles/)
cloudkms.locations.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS CryptoKey Decrypter (roles/)
Cloud KMS CryptoKey Decrypter Via Delegation (roles/)
Cloud KMS CryptoKey Encrypter (roles/)
Cloud KMS CryptoKey Encrypter/Decrypter (roles/)
Cloud KMS CryptoKey Encrypter/Decrypter Via Delegation (roles/)
Cloud KMS CryptoKey Encrypter Via Delegation (roles/)
Cloud KMS Crypto Operator (roles/)
Cloud KMS CryptoKey Decapsulator (roles/)
Cloud KMS Expert Raw AES-CBC Key Manager (roles/)
Cloud KMS Expert Raw AES-CTR Key Manager (roles/)
Cloud KMS Expert Raw PKCS#1 Key Manager (roles/)
Cloud KMS Importer (roles/)
Cloud KMS CryptoKey Public Key Viewer (roles/)
Cloud KMS CryptoKey Signer (roles/)
Cloud KMS CryptoKey Signer/Verifier (roles/)
Cloud KMS CryptoKey Verifier (roles/)
Cloud KMS Viewer (roles/)
Kubernetes Engine KMS Crypto Key User (roles/)
Data Scientist (roles/)
Databases Admin (roles/)
Dev Ops (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Service agent roles
-
DLP API Service Agent (
roles/)dlp.serviceAgent
cloudkms.locations.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS CryptoKey Decrypter (roles/)
Cloud KMS CryptoKey Decrypter Via Delegation (roles/)
Cloud KMS CryptoKey Encrypter (roles/)
Cloud KMS CryptoKey Encrypter/Decrypter (roles/)
Cloud KMS CryptoKey Encrypter/Decrypter Via Delegation (roles/)
Cloud KMS CryptoKey Encrypter Via Delegation (roles/)
Cloud KMS Crypto Operator (roles/)
Cloud KMS CryptoKey Decapsulator (roles/)
Cloud KMS Expert Raw AES-CBC Key Manager (roles/)
Cloud KMS Expert Raw AES-CTR Key Manager (roles/)
Cloud KMS Expert Raw PKCS#1 Key Manager (roles/)
Cloud KMS Importer (roles/)
Cloud KMS CryptoKey Public Key Viewer (roles/)
Cloud KMS CryptoKey Signer (roles/)
Cloud KMS CryptoKey Signer/Verifier (roles/)
Cloud KMS CryptoKey Verifier (roles/)
Cloud KMS Viewer (roles/)
Kubernetes Engine KMS Crypto Key User (roles/)
Data Scientist (roles/)
Databases Admin (roles/)
Dev Ops (roles/)
ML Engineer (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Service agent roles
-
DLP API Service Agent (
roles/)dlp.serviceAgent
cloudkms.locations.optOutKeyDeletionMsa
Owner (roles/)
Cloud KMS Admin (roles/)
cloudkms.operations.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
AlloyDB Admin (roles/)
Artifact Registry Administrator (roles/)
BigQuery Admin (roles/)
BigQuery Data Editor (roles/)
BigQuery Data Owner (roles/)
BigQuery Studio Admin (roles/)
BigQuery Studio User (roles/)
BigQuery User (roles/)
Bigtable Administrator (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Autokey User (roles/)
Cloud KMS single-tenant HSM Executor (roles/)
Cloud KMS single-tenant HSM Proposer (roles/)
Cloud KMS single-tenant HSM Quorum Member (roles/)
Cloud KMS Viewer (roles/)
Cloud SQL Admin (roles/)
Composer Administrator (roles/)
Environment and Storage Object Administrator (roles/)
Composer Worker (roles/)
Compute Admin (roles/)
Compute Instance Admin (beta) (roles/)
Compute Instance Admin (v1) (roles/)
Compute Storage Admin (roles/)
Dataflow Admin (roles/)
Dataflow Developer (roles/)
Dataproc Administrator (roles/)
Dataproc Editor (roles/)
Dataproc Serverless Editor (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Firebase Admin (roles/)
Firebase Develop Admin (roles/)
Data Scientist (roles/)
Databases Admin (roles/)
Dev Ops (roles/)
Infrastructure Administrator (roles/)
ML Engineer (roles/)
Network Administrator (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Notebooks Legacy Admin (roles/)
Pub/Sub Admin (roles/)
Pub/Sub Editor (roles/)
Cloud Memorystore Redis Admin (roles/)
Cloud Run Source Developer (roles/)
Secret Manager Admin (roles/)
Secure Source Manager Admin (roles/)
Secure Source Manager Instance Owner (roles/)
Cloud Spanner Admin (roles/)
Cloud Spanner Database Admin (roles/)
Storage Admin (roles/)
cloudkms.projects.showEffectiveAutokeyConfig
Owner (roles/)
Editor (roles/)
Viewer (roles/)
AlloyDB Admin (roles/)
Artifact Registry Administrator (roles/)
BigQuery Admin (roles/)
BigQuery Data Editor (roles/)
BigQuery Data Owner (roles/)
BigQuery Studio Admin (roles/)
BigQuery Studio User (roles/)
BigQuery User (roles/)
Bigtable Administrator (roles/)
Cloud KMS Admin (roles/)
Cloud KMS Autokey Admin (roles/)
Cloud KMS Autokey User (roles/)
Cloud SQL Admin (roles/)
Composer Administrator (roles/)
Environment and Storage Object Administrator (roles/)
Composer Worker (roles/)
Compute Admin (roles/)
Compute Instance Admin (beta) (roles/)
Compute Instance Admin (v1) (roles/)
Compute Storage Admin (roles/)
Dataflow Admin (roles/)
Dataflow Developer (roles/)
Dataproc Administrator (roles/)
Dataproc Editor (roles/)
Dataproc Serverless Editor (roles/)
DLP Organization Data Profiles Driver (roles/)
DLP Project Data Profiles Driver (roles/)
Firebase Admin (roles/)
Firebase Develop Admin (roles/)
Data Scientist (roles/)
Databases Admin (roles/)
Dev Ops (roles/)
Infrastructure Administrator (roles/)
ML Engineer (roles/)
Network Administrator (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
Notebooks Legacy Admin (roles/)
Pub/Sub Admin (roles/)
Pub/Sub Editor (roles/)
Cloud Memorystore Redis Admin (roles/)
Cloud Run Source Developer (roles/)
Secret Manager Admin (roles/)
Secure Source Manager Admin (roles/)
Secure Source Manager Instance Owner (roles/)
Cloud Spanner Admin (roles/)
Cloud Spanner Database Admin (roles/)
Storage Admin (roles/)
cloudkms.projects.showEffectiveKajEnrollmentConfig
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Key Access Justifications Enrollment Viewer (roles/)
Support User (roles/)
cloudkms.projects.showEffectiveKajPolicyConfig
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Key Access Justifications Policy Config Admin (roles/)
Support User (roles/)
cloudkms.protectedResources.search
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Protected Resources Viewer (roles/)
Support User (roles/)
cloudkms.singleTenantHsmInstanceProposals.approve
Owner (roles/)
Editor (roles/)
Cloud KMS single-tenant HSM Quorum Member (roles/)
cloudkms.singleTenantHsmInstanceProposals.create
Owner (roles/)
Editor (roles/)
Cloud KMS single-tenant HSM Proposer (roles/)
cloudkms.singleTenantHsmInstanceProposals.delete
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS single-tenant HSM Proposer (roles/)
cloudkms.singleTenantHsmInstanceProposals.execute
Owner (roles/)
Editor (roles/)
Cloud KMS single-tenant HSM Executor (roles/)
cloudkms.singleTenantHsmInstanceProposals.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS single-tenant HSM Executor (roles/)
Cloud KMS single-tenant HSM Proposer (roles/)
Cloud KMS single-tenant HSM Quorum Member (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.singleTenantHsmInstanceProposals.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS single-tenant HSM Executor (roles/)
Cloud KMS single-tenant HSM Proposer (roles/)
Cloud KMS single-tenant HSM Quorum Member (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.singleTenantHsmInstances.create
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS single-tenant HSM Proposer (roles/)
cloudkms.singleTenantHsmInstances.get
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS single-tenant HSM Executor (roles/)
Cloud KMS single-tenant HSM Key Creator (roles/)
Cloud KMS single-tenant HSM Proposer (roles/)
Cloud KMS single-tenant HSM Quorum Member (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Auditor (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.singleTenantHsmInstances.list
Owner (roles/)
Editor (roles/)
Viewer (roles/)
Cloud KMS Admin (roles/)
Cloud KMS single-tenant HSM Executor (roles/)
Cloud KMS single-tenant HSM Key Creator (roles/)
Cloud KMS single-tenant HSM Proposer (roles/)
Cloud KMS single-tenant HSM Quorum Member (roles/)
Cloud KMS Viewer (roles/)
Databases Admin (roles/)
ML Engineer (roles/)
Security Admin (roles/)
Security Auditor (roles/)
Security Reviewer (roles/)
Site Reliability Engineer (roles/)
Support User (roles/)
cloudkms.singleTenantHsmInstances.use
Owner (roles/)
Editor (roles/)
Cloud KMS Admin (roles/)
Cloud KMS single-tenant HSM Key Creator (roles/)