תפקידים והרשאות

בדף הזה מפורטים התפקידים וההרשאות של IAM עבור Agent Registry.

נותנים למשתמשים או לקבוצות שינהלו או יצפו בסוכנים במאגר את התפקידים המתאימים ב-IAM של מאגר הסוכנים. כדי להקצות תפקידים, אפשר להשתמש בדף IAM במסוף Google Cloud או ב-Google Cloud CLI. הוראות מפורטות מופיעות במאמר ניהול הגישה לפרויקטים, לתיקיות ולארגונים.

תפקידים ב-Agent Registry

בטבלה הבאה מתוארים תפקידי ה-IAM של Agent Registry והאחריות האופיינית שלהם:

תפקיד

תיאור

מטרה

Agent Registry API Admin

ביצוע כל הפעולות, כולל רישום סוכנים באופן ידני ועדכון מטא-נתונים.

  • רישום וניהול של סוכנים ושרתי MCP.
  • עדכון ההגדרות של כלי ונקודות קצה.

עריכת Agent Registry API

עריכת הגישה למשאבים של Agent Registry.

  • רישום וניהול של סוכנים ושרתי MCP.
  • עדכון ההגדרות של כלי ונקודות קצה.

Agent Registry API Viewer

צפייה בסוכנים, בכלים ובמאפיינים שלהם.

  • לגלות נציגים ושרתי MCP זמינים.
  • צפייה במיומנויות ובנקודות הקצה לשילוב.

הרשאות ב-Agent Registry

בטבלה הבאה מפורטות ההרשאות של כל תפקיד IAM במאגר הסוכנים:

(roles/agentregistry.admin)

גישה מלאה למשאבים של Agent Registry API.

agentregistry.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search
  • agentregistry.bindings.create
  • agentregistry.bindings.delete
  • agentregistry.bindings.fetchAvailable
  • agentregistry.bindings.get
  • agentregistry.bindings.list
  • agentregistry.bindings.update
  • agentregistry.endpoints.get
  • agentregistry.endpoints.list
  • agentregistry.locations.get
  • agentregistry.locations.list
  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search
  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list
  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

(roles/agentregistry.editor)

עריכת הגישה למשאבי Agent Registry API.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.*

  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list

agentregistry.services.*

  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

(roles/agentregistry.viewer)

גישת קריאה בלבד למשאבים של Agent Registry API.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.services.get

agentregistry.services.list

מידע נוסף על הרשאות IAM זמין במאמרים איך מוצאים את התפקידים המוגדרים מראש שמתאימים לכם ואינדקס של תפקידים והרשאות ב-IAM.