Security Command Center roles and permissions
Security Center Admin
(roles/)
Admin(super user) access to security center
Lowest-level resources where you can grant this role:
- Project
aiplatform.artifacts.get
aiplatform.artifacts.list
aiplatform.
aiplatform.
aiplatform.customJobs.get
aiplatform.customJobs.list
aiplatform.datasets.get
aiplatform.datasets.list
aiplatform.endpoints.get
aiplatform.endpoints.list
aiplatform.executions.get
aiplatform.executions.list
aiplatform.models.get
aiplatform.models.list
aiplatform.tuningJobs.get
aiplatform.tuningJobs.list
appengine.applications.get
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.dockerimages. get artifactregistry.dockerimages. list
artifactregistry.
artifactregistry.files.get
artifactregistry.files.list
artifactregistry.locations.*
artifactregistry.locations.getartifactregistry.locations. list
artifactregistry.
artifactregistry.mavenartifacts. get artifactregistry.mavenartifacts. list
artifactregistry.npmpackages.*
artifactregistry.npmpackages. get artifactregistry.npmpackages. list
artifactregistry.packages.get
artifactregistry.packages.list
artifactregistry.
artifactregistry.
artifactregistry.pythonpackages. get artifactregistry.pythonpackages. list
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.rules.get
artifactregistry.rules.list
artifactregistry.tags.get
artifactregistry.tags.list
artifactregistry.versions.get
artifactregistry.versions.list
assuredoss.*
assuredoss.config.getassuredoss.customers.createassuredoss.locations.getassuredoss.locations.listassuredoss.metadata.getassuredoss.metadata.listassuredoss.operations.cancelassuredoss.operations.deleteassuredoss.operations.getassuredoss.operations.list
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudnotifications.
cloudsecuritycompliance.*
cloudsecuritycompliance.auditReports. generate cloudsecuritycompliance.auditReports. get cloudsecuritycompliance.auditReports. list cloudsecuritycompliance.auditScopeReports. generate cloudsecuritycompliance.billingSettings. get cloudsecuritycompliance.cloudControlDeployments. create cloudsecuritycompliance.cloudControlDeployments. delete cloudsecuritycompliance.cloudControlDeployments. get cloudsecuritycompliance.cloudControlDeployments. list cloudsecuritycompliance.cloudControlDeployments. update cloudsecuritycompliance.cloudControlPredictions. create cloudsecuritycompliance.cloudControlPredictions. get cloudsecuritycompliance.cloudControlPredictions. list cloudsecuritycompliance.cloudControls. create cloudsecuritycompliance.cloudControls. delete cloudsecuritycompliance.cloudControls. get cloudsecuritycompliance.cloudControls. list cloudsecuritycompliance.cloudControls. update cloudsecuritycompliance.cmEnrollments. get cloudsecuritycompliance.cmEnrollments. update cloudsecuritycompliance.controlComplianceSummaries. list cloudsecuritycompliance.controlReports. get cloudsecuritycompliance.controls. get cloudsecuritycompliance.controls. list cloudsecuritycompliance.findingSummaries. list cloudsecuritycompliance.findings. list cloudsecuritycompliance.frameworkAudits. create cloudsecuritycompliance.frameworkAudits. get cloudsecuritycompliance.frameworkAudits. list cloudsecuritycompliance.frameworkComplianceReports. aggregate cloudsecuritycompliance.frameworkComplianceReports. get cloudsecuritycompliance.frameworkComplianceSummaries. list cloudsecuritycompliance.frameworkDeployments. create cloudsecuritycompliance.frameworkDeployments. delete cloudsecuritycompliance.frameworkDeployments. get cloudsecuritycompliance.frameworkDeployments. list cloudsecuritycompliance.frameworkDeployments. update cloudsecuritycompliance.frameworks. create cloudsecuritycompliance.frameworks. delete cloudsecuritycompliance.frameworks. get cloudsecuritycompliance.frameworks. list cloudsecuritycompliance.frameworks. update cloudsecuritycompliance.locations. enrollResource cloudsecuritycompliance.locations. get cloudsecuritycompliance.locations. list cloudsecuritycompliance.operations. cancel cloudsecuritycompliance.operations. delete cloudsecuritycompliance.operations. get cloudsecuritycompliance.operations. list cloudsecuritycompliance.resourceEnrollmentStatuses. get cloudsecuritycompliance.resourceEnrollmentStatuses. list
cloudsecurityscanner.*
cloudsecurityscanner.crawledurls. list cloudsecurityscanner.results. get cloudsecurityscanner.results. list cloudsecurityscanner.scanruns. get cloudsecurityscanner.scanruns. getSummary cloudsecurityscanner.scanruns. list cloudsecurityscanner.scanruns. stop cloudsecurityscanner.scans. create cloudsecurityscanner.scans. delete cloudsecurityscanner.scans.getcloudsecurityscanner.scans. list cloudsecurityscanner.scans.runcloudsecurityscanner.scans. update
compute.addresses.list
dlp.*
dlp.analyzeRiskTemplates. create dlp.analyzeRiskTemplates. delete dlp.analyzeRiskTemplates.getdlp.analyzeRiskTemplates.listdlp.analyzeRiskTemplates. update dlp.charts.getdlp.columnDataProfiles.getdlp.columnDataProfiles.listdlp.connections.createdlp.connections.deletedlp.connections.getdlp.connections.listdlp.connections.searchdlp.connections.updatedlp.deidentifyTemplates.createdlp.deidentifyTemplates.deletedlp.deidentifyTemplates.getdlp.deidentifyTemplates.listdlp.deidentifyTemplates.updatedlp.estimates.canceldlp.estimates.createdlp.estimates.deletedlp.estimates.getdlp.estimates.listdlp.fileStoreProfiles.deletedlp.fileStoreProfiles.getdlp.fileStoreProfiles.listdlp.inspectFindings.listdlp.inspectTemplates.createdlp.inspectTemplates.deletedlp.inspectTemplates.getdlp.inspectTemplates.listdlp.inspectTemplates.updatedlp.jobTriggers.createdlp.jobTriggers.deletedlp.jobTriggers.getdlp.jobTriggers.hybridInspectdlp.jobTriggers.listdlp.jobTriggers.updatedlp.jobs.canceldlp.jobs.createdlp.jobs.deletedlp.jobs.getdlp.jobs.hybridInspectdlp.jobs.listdlp.kms.encryptdlp.locations.getdlp.locations.listdlp.projectDataProfiles.getdlp.projectDataProfiles.listdlp.storedInfoTypes.createdlp.storedInfoTypes.deletedlp.storedInfoTypes.getdlp.storedInfoTypes.listdlp.storedInfoTypes.updatedlp.subscriptions.canceldlp.subscriptions.createdlp.subscriptions.getdlp.subscriptions.listdlp.subscriptions.updatedlp.tableDataProfiles.deletedlp.tableDataProfiles.getdlp.tableDataProfiles.list
dspm.*
dspm.locations. computeAggregation dspm.locations. fetchDataGovernanceAnalytics dspm.locations. fetchDspmGovernedProjects dspm.locations. fetchGovernedResourceMetrics dspm.locations. fetchLineageConnections dspm.locations.getdspm.locations.listdspm.operations.canceldspm.operations.deletedspm.operations.getdspm.operations.list
iam.serviceAccountKeys.create
iam.serviceAccounts.create
iam.serviceAccounts.get
modelarmor.floorSettings.*
modelarmor.floorSettings.getmodelarmor.floorSettings. update
modelarmor.locations.*
modelarmor.locations.getmodelarmor.locations.list
modelarmor.templates.*
modelarmor.templates.createmodelarmor.templates.deletemodelarmor.templates.getmodelarmor.templates.listmodelarmor.templates.updatemodelarmor.templates. useToSanitizeModelResponse modelarmor.templates. useToSanitizeUserPrompt
monitoring.alertPolicies.get
monitoring.alertPolicies.list
monitoring.
monitoring.
monitoring.alerts.*
monitoring.alerts.getmonitoring.alerts.list
monitoring.dashboards.get
monitoring.dashboards.list
monitoring.
monitoring.
monitoring.groups.get
monitoring.groups.list
monitoring.
monitoring.
monitoring.
monitoring.monitoredResourceDescriptors. get monitoring.monitoredResourceDescriptors. list
monitoring.
monitoring.notificationChannelDescriptors. get monitoring.notificationChannelDescriptors. list
monitoring.
monitoring.
monitoring.services.get
monitoring.services.list
monitoring.slos.get
monitoring.slos.list
monitoring.snoozes.get
monitoring.snoozes.list
monitoring.timeSeries.list
monitoring.
monitoring.
opsconfigmonitoring.
pubsub.
pubsub.schemas.get
pubsub.schemas.list
pubsub.schemas.listRevisions
pubsub.schemas.validate
pubsub.snapshots.get
pubsub.snapshots.list
pubsub.
pubsub.
pubsub.subscriptions.create
pubsub.subscriptions.get
pubsub.subscriptions.list
pubsub.
pubsub.
pubsub.subscriptions.update
pubsub.topics.get
pubsub.topics.list
pubsub.
pubsub.topics.listTagBindings
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
resourcemanager.tagValues.get
securitycenter.*
securitycenter.assets.groupsecuritycenter.assets.listsecuritycenter.assets. listAssetPropertyNames securitycenter.assets. runDiscovery securitycenter.assetsecuritymarks. update securitycenter.attackpaths. list securitycenter.bigQueryExports. create securitycenter.bigQueryExports. delete securitycenter.bigQueryExports. get securitycenter.bigQueryExports. list securitycenter.bigQueryExports. update securitycenter.billingtier. update securitycenter.complianceReports. aggregate securitycenter.compliancesnapshots. list securitycenter.containerthreatdetectionsettings. calculate securitycenter.containerthreatdetectionsettings. get securitycenter.containerthreatdetectionsettings. update securitycenter.effectivesecurityhealthanalyticscustommodules. get securitycenter.effectivesecurityhealthanalyticscustommodules. list securitycenter.eventthreatdetectionsettings. calculate securitycenter.eventthreatdetectionsettings. get securitycenter.eventthreatdetectionsettings. update securitycenter.exposurepathexplan. get securitycenter.findingexplanations. get securitycenter.findingexternalsystems. update securitycenter.findings. bulkMuteUpdate securitycenter.findings.exportsecuritycenter.findings.groupsecuritycenter.findings.listsecuritycenter.findings. listFindingPropertyNames securitycenter.findings. setMute securitycenter.findings. setState securitycenter.findings. setWorkflowState securitycenter.findings.updatesecuritycenter.findingsecuritymarks. update securitycenter.graphs.getsecuritycenter.graphs.querysecuritycenter.integratedvulnerabilityscannersettings. calculate securitycenter.integratedvulnerabilityscannersettings. get securitycenter.integratedvulnerabilityscannersettings. update securitycenter.issues.getsecuritycenter.issues.groupsecuritycenter.issues.listsecuritycenter.issues. listFilterValues securitycenter.issues.mutesecuritycenter.muteconfigs. create securitycenter.muteconfigs. delete securitycenter.muteconfigs.getsecuritycenter.muteconfigs. list securitycenter.muteconfigs. update securitycenter.notificationconfig. create securitycenter.notificationconfig. delete securitycenter.notificationconfig. get securitycenter.notificationconfig. list securitycenter.notificationconfig. update securitycenter.organizationsettings. get securitycenter.organizationsettings. update securitycenter.rapidvulnerabilitydetectionsettings. calculate securitycenter.rapidvulnerabilitydetectionsettings. get securitycenter.rapidvulnerabilitydetectionsettings. update securitycenter.resourcevalueconfigs. create securitycenter.resourcevalueconfigs. delete securitycenter.resourcevalueconfigs. get securitycenter.resourcevalueconfigs. list securitycenter.resourcevalueconfigs. update securitycenter.riskreports.getsecuritycenter.riskreports. list securitycenter.securitycentersettings. get securitycenter.securitycentersettings. update securitycenter.securityhealthanalyticscustommodules. create securitycenter.securityhealthanalyticscustommodules. delete securitycenter.securityhealthanalyticscustommodules. get securitycenter.securityhealthanalyticscustommodules. list securitycenter.securityhealthanalyticscustommodules. simulate securitycenter.securityhealthanalyticscustommodules. test securitycenter.securityhealthanalyticscustommodules. update securitycenter.securityhealthanalyticssettings. calculate securitycenter.securityhealthanalyticssettings. get securitycenter.securityhealthanalyticssettings. update securitycenter.simulations.getsecuritycenter.sources.getsecuritycenter.sources. getIamPolicy securitycenter.sources.listsecuritycenter.sources. setIamPolicy securitycenter.sources.updatesecuritycenter.subscription. get securitycenter.userinterfacemetadata. get securitycenter.valuedresources. list securitycenter.virtualmachinethreatdetectionsettings. calculate securitycenter.virtualmachinethreatdetectionsettings. get securitycenter.virtualmachinethreatdetectionsettings. update securitycenter.vulnerabilitysnapshots. list securitycenter.websecurityscannersettings. calculate securitycenter.websecurityscannersettings. get securitycenter.websecurityscannersettings. update
securitycentermanagement.*
securitycentermanagement.billingMetadata. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. list securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list securitycentermanagement.eventThreatDetectionCustomModules. create securitycentermanagement.eventThreatDetectionCustomModules. delete securitycentermanagement.eventThreatDetectionCustomModules. get securitycentermanagement.eventThreatDetectionCustomModules. list securitycentermanagement.eventThreatDetectionCustomModules. update securitycentermanagement.eventThreatDetectionCustomModules. validate securitycentermanagement.locations. get securitycentermanagement.locations. list securitycentermanagement.securityCenterServices. get securitycentermanagement.securityCenterServices. list securitycentermanagement.securityCenterServices. update securitycentermanagement.securityCommandCenter. activate securitycentermanagement.securityCommandCenter. checkActivationOperation securitycentermanagement.securityCommandCenter. checkEligibility securitycentermanagement.securityCommandCenter. checkOnboardingStatus securitycentermanagement.securityCommandCenter. generateServiceAccounts securitycentermanagement.securityCommandCenter. get securitycentermanagement.securityCommandCenter. update securitycentermanagement.securityHealthAnalyticsCustomModules. create securitycentermanagement.securityHealthAnalyticsCustomModules. delete securitycentermanagement.securityHealthAnalyticsCustomModules. get securitycentermanagement.securityHealthAnalyticsCustomModules. list securitycentermanagement.securityHealthAnalyticsCustomModules. simulate securitycentermanagement.securityHealthAnalyticsCustomModules. test securitycentermanagement.securityHealthAnalyticsCustomModules. update
securityposture.operations.get
securityposture.
securityposture.
securityposture.
securityposture.postureTemplates. get securityposture.postureTemplates. list
securityposture.postures.get
securityposture.postures.list
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
serviceusage.groups.listserviceusage.groups. listExpandedMembers serviceusage.groups. listMembers
serviceusage.quotas.get
serviceusage.services.enable
serviceusage.services.get
serviceusage.services.list
serviceusage.services.use
serviceusage.values.test
stackdriver.projects.get
stackdriver.
Security Center Admin Editor
(roles/)
Admin Read-write access to security center
Lowest-level resources where you can grant this role:
- Project
aiplatform.artifacts.get
aiplatform.artifacts.list
aiplatform.
aiplatform.
aiplatform.customJobs.get
aiplatform.customJobs.list
aiplatform.datasets.get
aiplatform.datasets.list
aiplatform.endpoints.get
aiplatform.endpoints.list
aiplatform.executions.get
aiplatform.executions.list
aiplatform.models.get
aiplatform.models.list
aiplatform.tuningJobs.get
aiplatform.tuningJobs.list
appengine.applications.get
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.dockerimages. get artifactregistry.dockerimages. list
artifactregistry.
artifactregistry.files.get
artifactregistry.files.list
artifactregistry.locations.*
artifactregistry.locations.getartifactregistry.locations. list
artifactregistry.
artifactregistry.mavenartifacts. get artifactregistry.mavenartifacts. list
artifactregistry.npmpackages.*
artifactregistry.npmpackages. get artifactregistry.npmpackages. list
artifactregistry.packages.get
artifactregistry.packages.list
artifactregistry.
artifactregistry.
artifactregistry.pythonpackages. get artifactregistry.pythonpackages. list
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.rules.get
artifactregistry.rules.list
artifactregistry.tags.get
artifactregistry.tags.list
artifactregistry.versions.get
artifactregistry.versions.list
assuredoss.config.get
assuredoss.locations.*
assuredoss.locations.getassuredoss.locations.list
assuredoss.metadata.*
assuredoss.metadata.getassuredoss.metadata.list
assuredoss.operations.get
assuredoss.operations.list
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudnotifications.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.controls. get cloudsecuritycompliance.controls. list
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.frameworkComplianceReports. aggregate cloudsecuritycompliance.frameworkComplianceReports. get
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.resourceEnrollmentStatuses. get cloudsecuritycompliance.resourceEnrollmentStatuses. list
cloudsecurityscanner.*
cloudsecurityscanner.crawledurls. list cloudsecurityscanner.results. get cloudsecurityscanner.results. list cloudsecurityscanner.scanruns. get cloudsecurityscanner.scanruns. getSummary cloudsecurityscanner.scanruns. list cloudsecurityscanner.scanruns. stop cloudsecurityscanner.scans. create cloudsecurityscanner.scans. delete cloudsecurityscanner.scans.getcloudsecurityscanner.scans. list cloudsecurityscanner.scans.runcloudsecurityscanner.scans. update
compute.addresses.list
dlp.charts.get
dlp.columnDataProfiles.*
dlp.columnDataProfiles.getdlp.columnDataProfiles.list
dlp.fileStoreProfiles.get
dlp.fileStoreProfiles.list
dlp.projectDataProfiles.*
dlp.projectDataProfiles.getdlp.projectDataProfiles.list
dlp.tableDataProfiles.get
dlp.tableDataProfiles.list
dspm.locations.*
dspm.locations. computeAggregation dspm.locations. fetchDataGovernanceAnalytics dspm.locations. fetchDspmGovernedProjects dspm.locations. fetchGovernedResourceMetrics dspm.locations. fetchLineageConnections dspm.locations.getdspm.locations.list
dspm.operations.get
dspm.operations.list
monitoring.alertPolicies.get
monitoring.alertPolicies.list
monitoring.
monitoring.
monitoring.alerts.*
monitoring.alerts.getmonitoring.alerts.list
monitoring.dashboards.get
monitoring.dashboards.list
monitoring.
monitoring.
monitoring.groups.get
monitoring.groups.list
monitoring.
monitoring.
monitoring.
monitoring.monitoredResourceDescriptors. get monitoring.monitoredResourceDescriptors. list
monitoring.
monitoring.notificationChannelDescriptors. get monitoring.notificationChannelDescriptors. list
monitoring.
monitoring.
monitoring.services.get
monitoring.services.list
monitoring.slos.get
monitoring.slos.list
monitoring.snoozes.get
monitoring.snoozes.list
monitoring.timeSeries.list
monitoring.
monitoring.
opsconfigmonitoring.
pubsub.
pubsub.schemas.get
pubsub.schemas.list
pubsub.schemas.listRevisions
pubsub.schemas.validate
pubsub.snapshots.get
pubsub.snapshots.list
pubsub.
pubsub.
pubsub.subscriptions.get
pubsub.subscriptions.list
pubsub.
pubsub.
pubsub.topics.get
pubsub.topics.list
pubsub.
pubsub.topics.listTagBindings
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
resourcemanager.tagValues.get
securitycenter.assets.*
securitycenter.assets.groupsecuritycenter.assets.listsecuritycenter.assets. listAssetPropertyNames securitycenter.assets. runDiscovery
securitycenter.
securitycenter.
securitycenter.
securitycenter.bigQueryExports. create securitycenter.bigQueryExports. delete securitycenter.bigQueryExports. get securitycenter.bigQueryExports. list securitycenter.bigQueryExports. update
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.effectivesecurityhealthanalyticscustommodules. get securitycenter.effectivesecurityhealthanalyticscustommodules. list
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.findings.*
securitycenter.findings. bulkMuteUpdate securitycenter.findings.exportsecuritycenter.findings.groupsecuritycenter.findings.listsecuritycenter.findings. listFindingPropertyNames securitycenter.findings. setMute securitycenter.findings. setState securitycenter.findings. setWorkflowState securitycenter.findings.update
securitycenter.
securitycenter.graphs.*
securitycenter.graphs.getsecuritycenter.graphs.query
securitycenter.
securitycenter.
securitycenter.issues.*
securitycenter.issues.getsecuritycenter.issues.groupsecuritycenter.issues.listsecuritycenter.issues. listFilterValues securitycenter.issues.mute
securitycenter.muteconfigs.*
securitycenter.muteconfigs. create securitycenter.muteconfigs. delete securitycenter.muteconfigs.getsecuritycenter.muteconfigs. list securitycenter.muteconfigs. update
securitycenter.
securitycenter.notificationconfig. create securitycenter.notificationconfig. delete securitycenter.notificationconfig. get securitycenter.notificationconfig. list securitycenter.notificationconfig. update
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.resourcevalueconfigs. create securitycenter.resourcevalueconfigs. delete securitycenter.resourcevalueconfigs. get securitycenter.resourcevalueconfigs. list securitycenter.resourcevalueconfigs. update
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.simulations.get
securitycenter.sources.get
securitycenter.sources.list
securitycenter.sources.update
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.effectiveEventThreatDetectionCustomModules. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. list
securitycentermanagement.
securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.locations. get securitycentermanagement.locations. list
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securityposture.operations.get
securityposture.
securityposture.
securityposture.
securityposture.postureTemplates. get securityposture.postureTemplates. list
securityposture.postures.get
securityposture.postures.list
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
serviceusage.groups.listserviceusage.groups. listExpandedMembers serviceusage.groups. listMembers
serviceusage.quotas.get
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
stackdriver.projects.get
stackdriver.
Security Center Admin Viewer
(roles/)
Admin Read access to security center
Lowest-level resources where you can grant this role:
- Project
aiplatform.artifacts.get
aiplatform.artifacts.list
aiplatform.
aiplatform.
aiplatform.customJobs.get
aiplatform.customJobs.list
aiplatform.datasets.get
aiplatform.datasets.list
aiplatform.endpoints.get
aiplatform.endpoints.list
aiplatform.executions.get
aiplatform.executions.list
aiplatform.models.get
aiplatform.models.list
aiplatform.tuningJobs.get
aiplatform.tuningJobs.list
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.dockerimages. get artifactregistry.dockerimages. list
artifactregistry.
artifactregistry.files.get
artifactregistry.files.list
artifactregistry.locations.*
artifactregistry.locations.getartifactregistry.locations. list
artifactregistry.
artifactregistry.mavenartifacts. get artifactregistry.mavenartifacts. list
artifactregistry.npmpackages.*
artifactregistry.npmpackages. get artifactregistry.npmpackages. list
artifactregistry.packages.get
artifactregistry.packages.list
artifactregistry.
artifactregistry.
artifactregistry.pythonpackages. get artifactregistry.pythonpackages. list
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.rules.get
artifactregistry.rules.list
artifactregistry.tags.get
artifactregistry.tags.list
artifactregistry.versions.get
artifactregistry.versions.list
assuredoss.config.get
assuredoss.locations.*
assuredoss.locations.getassuredoss.locations.list
assuredoss.metadata.*
assuredoss.metadata.getassuredoss.metadata.list
assuredoss.operations.get
assuredoss.operations.list
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudnotifications.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.controls. get cloudsecuritycompliance.controls. list
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.frameworkComplianceReports. aggregate cloudsecuritycompliance.frameworkComplianceReports. get
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.
cloudsecuritycompliance.resourceEnrollmentStatuses. get cloudsecuritycompliance.resourceEnrollmentStatuses. list
cloudsecurityscanner.
cloudsecurityscanner.results.*
cloudsecurityscanner.results. get cloudsecurityscanner.results. list
cloudsecurityscanner.
cloudsecurityscanner.
cloudsecurityscanner.
cloudsecurityscanner.scans.get
cloudsecurityscanner.
dlp.charts.get
dlp.columnDataProfiles.*
dlp.columnDataProfiles.getdlp.columnDataProfiles.list
dlp.fileStoreProfiles.get
dlp.fileStoreProfiles.list
dlp.projectDataProfiles.*
dlp.projectDataProfiles.getdlp.projectDataProfiles.list
dlp.tableDataProfiles.get
dlp.tableDataProfiles.list
dspm.locations.*
dspm.locations. computeAggregation dspm.locations. fetchDataGovernanceAnalytics dspm.locations. fetchDspmGovernedProjects dspm.locations. fetchGovernedResourceMetrics dspm.locations. fetchLineageConnections dspm.locations.getdspm.locations.list
dspm.operations.get
dspm.operations.list
monitoring.alertPolicies.get
monitoring.alertPolicies.list
monitoring.
monitoring.
monitoring.alerts.*
monitoring.alerts.getmonitoring.alerts.list
monitoring.dashboards.get
monitoring.dashboards.list
monitoring.
monitoring.
monitoring.groups.get
monitoring.groups.list
monitoring.
monitoring.
monitoring.
monitoring.monitoredResourceDescriptors. get monitoring.monitoredResourceDescriptors. list
monitoring.
monitoring.notificationChannelDescriptors. get monitoring.notificationChannelDescriptors. list
monitoring.
monitoring.
monitoring.services.get
monitoring.services.list
monitoring.slos.get
monitoring.slos.list
monitoring.snoozes.get
monitoring.snoozes.list
monitoring.timeSeries.list
monitoring.
monitoring.
opsconfigmonitoring.
pubsub.
pubsub.schemas.get
pubsub.schemas.list
pubsub.schemas.listRevisions
pubsub.schemas.validate
pubsub.snapshots.get
pubsub.snapshots.list
pubsub.
pubsub.
pubsub.subscriptions.get
pubsub.subscriptions.list
pubsub.
pubsub.
pubsub.topics.get
pubsub.topics.list
pubsub.
pubsub.topics.listTagBindings
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
resourcemanager.tagValues.get
securitycenter.assets.group
securitycenter.assets.list
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.effectivesecurityhealthanalyticscustommodules. get securitycenter.effectivesecurityhealthanalyticscustommodules. list
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.findings.group
securitycenter.findings.list
securitycenter.
securitycenter.graphs.*
securitycenter.graphs.getsecuritycenter.graphs.query
securitycenter.
securitycenter.
securitycenter.issues.get
securitycenter.issues.group
securitycenter.issues.list
securitycenter.
securitycenter.muteconfigs.get
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.simulations.get
securitycenter.sources.get
securitycenter.sources.list
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.effectiveEventThreatDetectionCustomModules. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. list
securitycentermanagement.
securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.locations. get securitycentermanagement.locations. list
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securityposture.operations.get
securityposture.
securityposture.
securityposture.
securityposture.postureTemplates. get securityposture.postureTemplates. list
securityposture.postures.get
securityposture.postures.list
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
serviceusage.groups.listserviceusage.groups. listExpandedMembers serviceusage.groups. listMembers
serviceusage.quotas.get
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
stackdriver.projects.get
stackdriver.
Security Center Asset Security Marks Writer
(roles/)
Write access to asset security marks
Lowest-level resources where you can grant this role:
- Project
securitycenter.
securitycenter.
Security Center Assets Discovery Runner
(roles/)
Run asset discovery access to assets
Lowest-level resources where you can grant this role:
- Organization
securitycenter.
securitycenter.
Security Center Assets Viewer
(roles/)
Read access to assets
Lowest-level resources where you can grant this role:
- Project
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
resourcemanager.folders.get
resourcemanager.
resourcemanager.projects.get
securitycenter.assets.group
securitycenter.assets.list
securitycenter.
securitycenter.
Security Center Attack Paths Reader
(roles/)
Read access to security center attack paths
securitycenter.
securitycenter.
Attack Surface Management Scanner Service Agent
(roles/)
Gives Mandiant Attack Surface Management the ability to scan Cloud Platform resources.
apigateway.apiconfigs.get
cloudasset.assets.listResource
dns.managedZones.list
dns.resourceRecordSets.list
resourcemanager.projects.get
Security Center Automation Service Agent
(roles/)
Security Center automation service agent can configure GCP resources to enable security scanning.
cloudasset.feeds.*
cloudasset.feeds.createcloudasset.feeds.deletecloudasset.feeds.getcloudasset.feeds.listcloudasset.feeds.update
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.
resourcemanager.projects.list
serviceusage.consumerpolicy.*
serviceusage.consumerpolicy. analyze serviceusage.consumerpolicy. get serviceusage.consumerpolicy. update
serviceusage.
serviceusage.groups.*
serviceusage.groups.listserviceusage.groups. listExpandedMembers serviceusage.groups. listMembers
serviceusage.services.enable
serviceusage.services.get
serviceusage.values.test
Security Center BigQuery Exports Editor
(roles/)
Read-Write access to security center BigQuery Exports
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
securitycenter.
securitycenter.bigQueryExports. create securitycenter.bigQueryExports. delete securitycenter.bigQueryExports. get securitycenter.bigQueryExports. list securitycenter.bigQueryExports. update
securitycenter.findings.export
Security Center BigQuery Exports Viewer
(roles/)
Read access to security center BigQuery Exports
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
securitycenter.
securitycenter.
Security Center Compliance Reports Viewer Beta
(roles/)
Read access to security center compliance reports
securitycenter.
Security Center Compliance Snapshots Viewer Beta
(roles/)
Read access to security center compliance snapshots
securitycenter.
securitycenter.
Security Center Control Service Agent
(roles/)
Security Center Control service agent can monitor and configure GCP resources and import security findings.
accesscontextmanager.
accesscontextmanager.
aiplatform.dataItems.list
aiplatform.datasets.list
aiplatform.models.list
bigquery.datasets.get
binaryauthorization.policy.get
cloudasset.
cloudasset.assets.analyzeMove
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.exportIapWeb
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listIamRoles
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listIapWeb
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listResource
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listTpuNodes
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.feeds.*
cloudasset.feeds.createcloudasset.feeds.deletecloudasset.feeds.getcloudasset.feeds.listcloudasset.feeds.update
cloudasset.
cloudasset.
cloudasset.
cloudsql.instances.connect
cloudsql.users.list
compute.disks.useReadOnly
compute.globalOperations.get
compute.instances.get
compute.instances.list
compute.
compute.projects.get
compute.regionOperations.get
compute.zoneOperations.get
container.clusters.get
iam.denypolicies.get
iam.denypolicies.list
iam.googleapis.
iam.googleapis.
logging.logEntries.list
monitoring.alertPolicies.list
monitoring.timeSeries.list
orgpolicy.policies.list
orgpolicy.policy.get
recommender.
recommender.
recommender.locations.*
recommender.locations.getrecommender.locations.list
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.
resourcemanager.projects.list
resourcemanager.tagValues.get
securitycenter.assets.list
securitycenter.
securitycenter.findings.list
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.simulations.get
securitycenter.sources.list
securitycenter.
securitycentermanagement.
securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
serviceusage.consumerpolicy.*
serviceusage.consumerpolicy. analyze serviceusage.consumerpolicy. get serviceusage.consumerpolicy. update
serviceusage.
serviceusage.groups.*
serviceusage.groups.listserviceusage.groups. listExpandedMembers serviceusage.groups. listMembers
serviceusage.operations.get
serviceusage.quotas.get
serviceusage.services.disable
serviceusage.services.enable
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
stackdriver.projects.get
storage.buckets.get
storage.buckets.getIamPolicy
storage.buckets.list
Security Center External Systems Editor
(roles/)
Write access to security center external systems
securitycenter.
Security Center Finding Security Marks Writer
(roles/)
Write access to finding security marks
Lowest-level resources where you can grant this role:
- Project
securitycenter.
securitycenter.
Security Center Findings Bulk Mute Editor
(roles/)
Ability to mute findings in bulk
securitycenter.
Security Center Findings Editor
(roles/)
Read-write access to findings
Lowest-level resources where you can grant this role:
- Project
resourcemanager.folders.get
resourcemanager.
resourcemanager.projects.get
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.findings.group
securitycenter.findings.list
securitycenter.
securitycenter.
securitycenter.
securitycenter.findings.update
securitycenter.graphs.*
securitycenter.graphs.getsecuritycenter.graphs.query
securitycenter.issues.*
securitycenter.issues.getsecuritycenter.issues.groupsecuritycenter.issues.listsecuritycenter.issues. listFilterValues securitycenter.issues.mute
securitycenter.sources.get
securitycenter.sources.list
securitycenter.
securitycenter.
Security Center Findings Mute Setter
(roles/)
Set mute access to findings
securitycenter.
Security Center Findings State Setter
(roles/)
Set state access to findings
Lowest-level resources where you can grant this role:
- Project
securitycenter.
securitycenter.
Security Center Findings Viewer
(roles/)
Read access to findings
Lowest-level resources where you can grant this role:
- Project
resourcemanager.folders.get
resourcemanager.
resourcemanager.projects.get
securitycenter.
securitycenter.
securitycenter.
securitycenter.findings.group
securitycenter.findings.list
securitycenter.
securitycenter.graphs.*
securitycenter.graphs.getsecuritycenter.graphs.query
securitycenter.issues.get
securitycenter.issues.group
securitycenter.issues.list
securitycenter.
securitycenter.sources.get
securitycenter.sources.list
securitycenter.
securitycenter.
Security Center Findings Workflow State Setter Beta
(roles/)
Set workflow state access to findings
Lowest-level resources where you can grant this role:
- Project
securitycenter.
securitycenter.
Security Center Integration Executor Service Agent
(roles/)
Gives Security Center access to execute Integrations.
integrations.
integrations.
integrations.
Security Center Issues Editor
(roles/)
Write access to security center issues
securitycenter.graphs.*
securitycenter.graphs.getsecuritycenter.graphs.query
securitycenter.issues.*
securitycenter.issues.getsecuritycenter.issues.groupsecuritycenter.issues.listsecuritycenter.issues. listFilterValues securitycenter.issues.mute
Security Center Issues Viewer
(roles/)
Read access to security center issues
securitycenter.graphs.*
securitycenter.graphs.getsecuritycenter.graphs.query
securitycenter.issues.get
securitycenter.issues.group
securitycenter.issues.list
securitycenter.
Security Center Mute Configurations Editor
(roles/)
Read-Write access to security center mute configurations
securitycenter.muteconfigs.*
securitycenter.muteconfigs. create securitycenter.muteconfigs. delete securitycenter.muteconfigs.getsecuritycenter.muteconfigs. list securitycenter.muteconfigs. update
Security Center Mute Configurations Viewer
(roles/)
Read access to security center mute configurations
securitycenter.muteconfigs.get
securitycenter.
Security Center Notification Configurations Editor
(roles/)
Write access to notification configurations
Lowest-level resources where you can grant this role:
- Organization
securitycenter.
securitycenter.notificationconfig. create securitycenter.notificationconfig. delete securitycenter.notificationconfig. get securitycenter.notificationconfig. list securitycenter.notificationconfig. update
securitycenter.
Security Center Notification Configurations Viewer
(roles/)
Read access to notification configurations
Lowest-level resources where you can grant this role:
- Organization
securitycenter.
securitycenter.
securitycenter.
Security Center Notification Service Agent
(roles/)
Security Center service agent can publish notifications to Pub/Sub topics.
pubsub.topics.publish
Security Center Resource Value Configurations Editor
(roles/)
Read-Write access to security center resource value configurations
resourcemanager.tagValues.get
securitycenter.
securitycenter.resourcevalueconfigs. create securitycenter.resourcevalueconfigs. delete securitycenter.resourcevalueconfigs. get securitycenter.resourcevalueconfigs. list securitycenter.resourcevalueconfigs. update
Security Center Resource Value Configurations Viewer
(roles/)
Read access to security center resource value configurations
resourcemanager.tagValues.get
securitycenter.
securitycenter.
Security Center Risk Reports Viewer
(roles/)
Read access to security center risk reports
securitycenter.riskreports.*
securitycenter.riskreports.getsecuritycenter.riskreports. list
securitycenter.
Security Health Analytics Custom Modules Tester
(roles/)
Test access to Security Health Analytics Custom Modules
securitycenter.
securitycenter.
securitycentermanagement.
securitycentermanagement.
Security Health Analytics Service Agent
(roles/)
Security Health Analytics service agent can scan GCP resource metadata to find security vulnerabilities.
bigquery.datasets.get
binaryauthorization.policy.get
cloudasset.
cloudasset.assets.analyzeMove
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.exportIapWeb
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listIamRoles
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listIapWeb
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listResource
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listTpuNodes
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.feeds.*
cloudasset.feeds.createcloudasset.feeds.deletecloudasset.feeds.getcloudasset.feeds.listcloudasset.feeds.update
cloudasset.
cloudasset.
cloudasset.
cloudsql.instances.connect
cloudsql.users.list
compute.globalOperations.get
compute.instances.get
compute.instances.list
compute.
compute.projects.get
container.clusters.get
monitoring.alertPolicies.list
orgpolicy.policy.get
recommender.
recommender.
recommender.locations.*
recommender.locations.getrecommender.locations.list
resourcemanager.projects.get
resourcemanager.projects.list
securitycenter.
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
serviceusage.groups.listserviceusage.groups. listExpandedMembers serviceusage.groups. listMembers
serviceusage.quotas.get
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
stackdriver.projects.get
Google Cloud Security Response Service Agent
(roles/)
Gives Playbook Runner permissions to execute all Google authored Playbooks. This role will keep evolving as we add more playbooks
compute.globalOperations.get
compute.
compute.instances.get
compute.instances.setMetadata
compute.regionOperations.get
compute.zoneOperations.get
iam.serviceAccounts.actAs
pubsub.topics.publish
securitycenter.findings.list
storage.buckets.get
storage.buckets.update
Security Center Service Agent
(roles/)
Security Center service agent can scan GCP resources and import security scans.
accesscontextmanager.
accesscontextmanager.
aiplatform.dataItems.list
aiplatform.datasets.list
aiplatform.models.list
bigquery.datasets.get
binaryauthorization.policy.get
cloudasset.
cloudasset.assets.analyzeMove
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.exportIapWeb
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listIamRoles
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listIapWeb
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listResource
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.assets.listTpuNodes
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.
cloudasset.feeds.*
cloudasset.feeds.createcloudasset.feeds.deletecloudasset.feeds.getcloudasset.feeds.listcloudasset.feeds.update
cloudasset.
cloudasset.
cloudasset.
cloudsql.instances.connect
cloudsql.users.list
compute.disks.useReadOnly
compute.globalOperations.get
compute.instances.get
compute.instances.list
compute.
compute.projects.get
compute.regionOperations.get
compute.zoneOperations.get
container.clusters.get
iam.denypolicies.get
iam.denypolicies.list
iam.googleapis.
iam.googleapis.
logging.logEntries.list
monitoring.alertPolicies.list
monitoring.timeSeries.list
orgpolicy.policies.list
orgpolicy.policy.get
recommender.
recommender.
recommender.locations.*
recommender.locations.getrecommender.locations.list
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.
resourcemanager.projects.list
resourcemanager.tagValues.get
securitycenter.assets.list
securitycenter.
securitycenter.findings.list
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.simulations.get
securitycenter.sources.list
securitycenter.
securitycentermanagement.
securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
serviceusage.consumerpolicy.*
serviceusage.consumerpolicy. analyze serviceusage.consumerpolicy. get serviceusage.consumerpolicy. update
serviceusage.
serviceusage.groups.*
serviceusage.groups.listserviceusage.groups. listExpandedMembers serviceusage.groups. listMembers
serviceusage.operations.get
serviceusage.quotas.get
serviceusage.services.disable
serviceusage.services.enable
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
stackdriver.projects.get
storage.buckets.get
storage.buckets.getIamPolicy
storage.buckets.list
Security Center Settings Admin
(roles/)
Admin(super user) access to security center settings
Lowest-level resources where you can grant this role:
- Project
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
securitycenter.
securitycenter.bigQueryExports. create securitycenter.bigQueryExports. delete securitycenter.bigQueryExports. get securitycenter.bigQueryExports. list securitycenter.bigQueryExports. update
securitycenter.
securitycenter.
securitycenter.containerthreatdetectionsettings. calculate securitycenter.containerthreatdetectionsettings. get securitycenter.containerthreatdetectionsettings. update
securitycenter.
securitycenter.effectivesecurityhealthanalyticscustommodules. get securitycenter.effectivesecurityhealthanalyticscustommodules. list
securitycenter.
securitycenter.eventthreatdetectionsettings. calculate securitycenter.eventthreatdetectionsettings. get securitycenter.eventthreatdetectionsettings. update
securitycenter.findings.export
securitycenter.
securitycenter.integratedvulnerabilityscannersettings. calculate securitycenter.integratedvulnerabilityscannersettings. get securitycenter.integratedvulnerabilityscannersettings. update
securitycenter.muteconfigs.*
securitycenter.muteconfigs. create securitycenter.muteconfigs. delete securitycenter.muteconfigs.getsecuritycenter.muteconfigs. list securitycenter.muteconfigs. update
securitycenter.
securitycenter.notificationconfig. create securitycenter.notificationconfig. delete securitycenter.notificationconfig. get securitycenter.notificationconfig. list securitycenter.notificationconfig. update
securitycenter.
securitycenter.organizationsettings. get securitycenter.organizationsettings. update
securitycenter.
securitycenter.rapidvulnerabilitydetectionsettings. calculate securitycenter.rapidvulnerabilitydetectionsettings. get securitycenter.rapidvulnerabilitydetectionsettings. update
securitycenter.
securitycenter.securitycentersettings. get securitycenter.securitycentersettings. update
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.securityhealthanalyticssettings. calculate securitycenter.securityhealthanalyticssettings. get securitycenter.securityhealthanalyticssettings. update
securitycenter.
securitycenter.
securitycenter.
securitycenter.virtualmachinethreatdetectionsettings. calculate securitycenter.virtualmachinethreatdetectionsettings. get securitycenter.virtualmachinethreatdetectionsettings. update
securitycenter.
securitycenter.websecurityscannersettings. calculate securitycenter.websecurityscannersettings. get securitycenter.websecurityscannersettings. update
securitycentermanagement.*
securitycentermanagement.billingMetadata. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. list securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list securitycentermanagement.eventThreatDetectionCustomModules. create securitycentermanagement.eventThreatDetectionCustomModules. delete securitycentermanagement.eventThreatDetectionCustomModules. get securitycentermanagement.eventThreatDetectionCustomModules. list securitycentermanagement.eventThreatDetectionCustomModules. update securitycentermanagement.eventThreatDetectionCustomModules. validate securitycentermanagement.locations. get securitycentermanagement.locations. list securitycentermanagement.securityCenterServices. get securitycentermanagement.securityCenterServices. list securitycentermanagement.securityCenterServices. update securitycentermanagement.securityCommandCenter. activate securitycentermanagement.securityCommandCenter. checkActivationOperation securitycentermanagement.securityCommandCenter. checkEligibility securitycentermanagement.securityCommandCenter. checkOnboardingStatus securitycentermanagement.securityCommandCenter. generateServiceAccounts securitycentermanagement.securityCommandCenter. get securitycentermanagement.securityCommandCenter. update securitycentermanagement.securityHealthAnalyticsCustomModules. create securitycentermanagement.securityHealthAnalyticsCustomModules. delete securitycentermanagement.securityHealthAnalyticsCustomModules. get securitycentermanagement.securityHealthAnalyticsCustomModules. list securitycentermanagement.securityHealthAnalyticsCustomModules. simulate securitycentermanagement.securityHealthAnalyticsCustomModules. test securitycentermanagement.securityHealthAnalyticsCustomModules. update
Security Center Settings Editor
(roles/)
Read-Write access to security center settings
Lowest-level resources where you can grant this role:
- Project
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
securitycenter.
securitycenter.bigQueryExports. create securitycenter.bigQueryExports. delete securitycenter.bigQueryExports. get securitycenter.bigQueryExports. list securitycenter.bigQueryExports. update
securitycenter.
securitycenter.
securitycenter.containerthreatdetectionsettings. calculate securitycenter.containerthreatdetectionsettings. get securitycenter.containerthreatdetectionsettings. update
securitycenter.
securitycenter.effectivesecurityhealthanalyticscustommodules. get securitycenter.effectivesecurityhealthanalyticscustommodules. list
securitycenter.
securitycenter.eventthreatdetectionsettings. calculate securitycenter.eventthreatdetectionsettings. get securitycenter.eventthreatdetectionsettings. update
securitycenter.findings.export
securitycenter.
securitycenter.integratedvulnerabilityscannersettings. calculate securitycenter.integratedvulnerabilityscannersettings. get securitycenter.integratedvulnerabilityscannersettings. update
securitycenter.muteconfigs.*
securitycenter.muteconfigs. create securitycenter.muteconfigs. delete securitycenter.muteconfigs.getsecuritycenter.muteconfigs. list securitycenter.muteconfigs. update
securitycenter.
securitycenter.notificationconfig. create securitycenter.notificationconfig. delete securitycenter.notificationconfig. get securitycenter.notificationconfig. list securitycenter.notificationconfig. update
securitycenter.
securitycenter.organizationsettings. get securitycenter.organizationsettings. update
securitycenter.
securitycenter.rapidvulnerabilitydetectionsettings. calculate securitycenter.rapidvulnerabilitydetectionsettings. get securitycenter.rapidvulnerabilitydetectionsettings. update
securitycenter.
securitycenter.securitycentersettings. get securitycenter.securitycentersettings. update
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.securityhealthanalyticssettings. calculate securitycenter.securityhealthanalyticssettings. get securitycenter.securityhealthanalyticssettings. update
securitycenter.
securitycenter.
securitycenter.
securitycenter.virtualmachinethreatdetectionsettings. calculate securitycenter.virtualmachinethreatdetectionsettings. get securitycenter.virtualmachinethreatdetectionsettings. update
securitycenter.
securitycenter.websecurityscannersettings. calculate securitycenter.websecurityscannersettings. get securitycenter.websecurityscannersettings. update
securitycentermanagement.*
securitycentermanagement.billingMetadata. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. list securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list securitycentermanagement.eventThreatDetectionCustomModules. create securitycentermanagement.eventThreatDetectionCustomModules. delete securitycentermanagement.eventThreatDetectionCustomModules. get securitycentermanagement.eventThreatDetectionCustomModules. list securitycentermanagement.eventThreatDetectionCustomModules. update securitycentermanagement.eventThreatDetectionCustomModules. validate securitycentermanagement.locations. get securitycentermanagement.locations. list securitycentermanagement.securityCenterServices. get securitycentermanagement.securityCenterServices. list securitycentermanagement.securityCenterServices. update securitycentermanagement.securityCommandCenter. activate securitycentermanagement.securityCommandCenter. checkActivationOperation securitycentermanagement.securityCommandCenter. checkEligibility securitycentermanagement.securityCommandCenter. checkOnboardingStatus securitycentermanagement.securityCommandCenter. generateServiceAccounts securitycentermanagement.securityCommandCenter. get securitycentermanagement.securityCommandCenter. update securitycentermanagement.securityHealthAnalyticsCustomModules. create securitycentermanagement.securityHealthAnalyticsCustomModules. delete securitycentermanagement.securityHealthAnalyticsCustomModules. get securitycentermanagement.securityHealthAnalyticsCustomModules. list securitycentermanagement.securityHealthAnalyticsCustomModules. simulate securitycentermanagement.securityHealthAnalyticsCustomModules. test securitycentermanagement.securityHealthAnalyticsCustomModules. update
Security Center Settings Viewer
(roles/)
Read access to security center settings
Lowest-level resources where you can grant this role:
- Project
resourcemanager.folders.get
resourcemanager.folders.list
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.effectivesecurityhealthanalyticscustommodules. get securitycenter.effectivesecurityhealthanalyticscustommodules. list
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.muteconfigs.get
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycenter.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.effectiveEventThreatDetectionCustomModules. get securitycentermanagement.effectiveEventThreatDetectionCustomModules. list
securitycentermanagement.
securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. get securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules. list
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.locations. get securitycentermanagement.locations. list
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
securitycentermanagement.
Security Center Simulations Reader
(roles/)
Read access to security center simulations
securitycenter.simulations.get
Security Center Sources Admin
(roles/)
Admin access to sources
Lowest-level resources where you can grant this role:
- Organization
resourcemanager.
securitycenter.sources.*
securitycenter.sources.getsecuritycenter.sources. getIamPolicy securitycenter.sources.listsecuritycenter.sources. setIamPolicy securitycenter.sources.update
securitycenter.
Security Center Sources Editor
(roles/)
Read-write access to sources
Lowest-level resources where you can grant this role:
- Organization
resourcemanager.
securitycenter.sources.get
securitycenter.sources.list
securitycenter.sources.update
securitycenter.
Security Center Sources Viewer
(roles/)
Read access to sources
Lowest-level resources where you can grant this role:
- Project
resourcemanager.
securitycenter.sources.get
securitycenter.sources.list
securitycenter.
Security Center Valued Resources Reader
(roles/)
Read access to security center valued resources
securitycenter.