permissions
  • General
  • Dashboard
  • Reference Usage
  • Predefined Roles
  • Cloud Providers
  • AWS
  • Azure
  • Google Cloud
  • Reference

Type / to search...



  1. Reference

Permissions Reference for

IAM Actions defined by

You can specify the following permissions in an IAM custom role.

IAM Actions

-

API Methods

-

Name Used By Access Level Predefined Roles
API Methods defined by

You can use the following methods in the Google Cloud CLI, SDKs or API.

IAM Actions

-

API Methods

-

Method Description API Versions IAM Action
Download the permissions in JSON format.

Consume the above permissions with your own tooling.

  1. General
  2. Dashboard

Dashboard

IAM Actions

Number of known IAM actions within Google Cloud IAM.

API Methods

Number of known API methods within all of Google Cloud.

Predefined Roles

Number of predefined roles provided by Google Cloud.

  1. General
  2. Reference Usage

Reference Usage

About gcp.permissions.cloud

The gcp.permissions.cloud website uses a variety of information gathered within the IAM Dataset and exposes that information in a clean, easy-to-read format.

gcp.permissions.cloud was built in order to provide an alternate, community-driven source of truth for Google Cloud identity. If you would like to contribute to or suggest a feature for this website, please raise it in the gcp.permissions.cloud repo. If you have found a data issue with the IAM permissions or API methods, please raise it in the IAM Dataset repo.

The website can be navigated using the left sidebar or by quickly looking up a specific managed policy, IAM permission or API method in the top search bar.


Using the Dashboard

The dashboard has a small selection of statistics about the global state of IAM permissions and API methods.


Using Predefined Roles

The predefined roles section lists all known predefined roles with the ability to view individual roles in-depth. Additional analysis is presented about the effective IAM permissions the policy provides.

The following table represents the attributes available on either a managed policy or an effective IAM action within it:

Tag Description
credentials exposure A predefined role or predefined role action tag that indicates the presence of an action that could produce a response that contains credentials.
data access A predefined role or predefined role action tag that indicates the presence of an action that could return data within Google Cloud data stores.
possible privesc A predefined role or predefined role action tag that indicates the presence of an action that could potentially lead to a privilege escalation.
beta A predefined role tag indicating that the predefined role is in beta and is not recommended for production use.
undocumented actions A predefined role action tag that indicates the action is not documented in the official permissions reference.
malformed A predefined role tag that indicates the presence of a malformed statement within the policy.
deprecated A predefined role tag that indicates the policy is deprecated.

Using IAM Permissions

IAM Permissions are available on all service pages. Each IAM permission details its own name, access level, the predefined roles that contain the permission, as well as the API methods that are known to consume that permission.


Using API Methods

API Methods are available on all service pages. Each API Method details its own name, description, and the API versions of the method.

  1. General
  2. Predefined Roles

Predefined Roles

Google Cloud Predefined Roles

Below is a list of Google Cloud Predefined Roles.

Active Predefined Roles

-

Deprecated Predefined Roles

-

Name ID Description
  1. General
  2. Predefined Roles

Raw Policy

Below is the raw predefined role policy.

Effective Actions

Below is a breakdown of the effective actions for the predefined role.

Action Based On Access Level
API Request Location