Papéis e permissões

Esta página lista os papéis e as permissões do IAM para o Agent Registry.

Conceda os papéis apropriados do IAM do Agent Registry a usuários ou grupos que vão gerenciar ou visualizar agentes no registro. Para conceder papéis, use a página "IAM" no Google Cloud console ou a Google Cloud CLI. Para instruções detalhadas, consulte Gerenciar o acesso a projetos, pastas e organizações.

Papéis do Agent Registry

A tabela a seguir descreve os papéis do IAM do Agent Registry e as responsabilidades típicas deles:

Papel

Descrição

Purpose

Administrador da API Agent Registry

Realizar todas as ações, incluindo o registro manual de agentes e a atualização de metadados.

  • Registrar e gerenciar agentes e servidores MCP.
  • Atualizar definições e endpoints de ferramentas.

Editor da API Agent Registry

Editar o acesso de edição aos recursos do Agent Registry.

  • Registrar e gerenciar agentes e servidores MCP.
  • Atualizar definições e endpoints de ferramentas.

Leitor da API Agent Registry

Visualizar agentes, ferramentas e atributos.

  • Descobrir agentes e servidores MCP disponíveis.
  • Visualizar habilidades A2A, habilidades independentes e endpoints para integração.

Usuário do Agent Registry

Criar, atualizar e excluir habilidades e revisões de habilidades.

  • Gerenciar habilidades independentes para agentes no Agent Registry.
  • Manter o controle de versões para revisões de habilidades e gerenciar centralmente os estados ativos das habilidades.

Permissões do Agent Registry

A tabela a seguir lista as permissões que cada papel do IAM do Agent Registry tem:

(roles/agentregistry.admin)

Acesso total aos recursos da API Agent Registry.

agentregistry.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search
  • agentregistry.bindings.create
  • agentregistry.bindings.delete
  • agentregistry.bindings.fetchAvailable
  • agentregistry.bindings.get
  • agentregistry.bindings.list
  • agentregistry.bindings.update
  • agentregistry.endpoints.get
  • agentregistry.endpoints.list
  • agentregistry.locations.get
  • agentregistry.locations.list
  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search
  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list
  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

(roles/agentregistry.editor)

Editar o acesso de edição aos recursos da API Agent Registry.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.*

  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list

agentregistry.services.*

  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

(roles/agentregistry.viewer)

Acesso somente leitura aos recursos da API Agent Registry.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.services.get

agentregistry.services.list

Para mais informações sobre as permissões do IAM, consulte Encontrar os papéis predefinidos certos e Índice de papéis e permissões do IAM.