Papéis e permissões

Nesta página, listamos os papéis e as permissões do IAM para o Agent Registry.

Conceda os papéis apropriados do IAM do Agent Registry a usuários ou grupos que vão gerenciar ou visualizar agentes no registro. Para conceder papéis, use a página do IAM no console do Google Cloud ou a Google Cloud CLI. Para instruções detalhadas, consulte Gerenciar o acesso a projetos, pastas e organizações.

Funções do Agent Registry

A tabela a seguir descreve os papéis do IAM do Agent Registry e as responsabilidades típicas deles:

Papel

Descrição

Purpose

Administrador da API Agent Registry

Realize todas as ações, incluindo o registro manual de agentes e a atualização de metadados.

  • Registre e gerencie agentes e servidores MCP.
  • Atualize as definições e os endpoints de ferramentas.

Editor da API Agent Registry

Acesso de edição aos recursos do Agent Registry.

  • Registre e gerencie agentes e servidores MCP.
  • Atualize as definições e os endpoints de ferramentas.

Leitor da API Agent Registry

Ver agentes, ferramentas e atributos.

  • Descubra agentes e servidores MCP disponíveis.
  • Confira habilidades A2A, habilidades independentes e endpoints para integração.

Usuário do Agent Registry

Criar, atualizar e excluir habilidades e revisões de habilidades.

  • Gerenciar habilidades independentes para agentes no Agent Registry.
  • Mantenha o controle de versões para revisões de habilidades e gerencie centralmente os estados ativos das habilidades.

Permissões do Agent Registry

A tabela a seguir lista as permissões de cada papel do IAM do Agent Registry:

(roles/agentregistry.admin)

Acesso total aos recursos da API Agent Registry.

agentregistry.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search
  • agentregistry.bindings.create
  • agentregistry.bindings.delete
  • agentregistry.bindings.fetchAvailable
  • agentregistry.bindings.get
  • agentregistry.bindings.list
  • agentregistry.bindings.update
  • agentregistry.endpoints.get
  • agentregistry.endpoints.list
  • agentregistry.locations.get
  • agentregistry.locations.list
  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search
  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list
  • agentregistry.publishers.get
  • agentregistry.publishers.list
  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update
  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list
  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

(roles/agentregistry.editor)

Acesso de edição aos recursos da API Agent Registry.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.*

  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.*

  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

agentregistry.skillRevisions.*

  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list

agentregistry.skills.*

  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

(roles/agentregistry.viewer)

Acesso somente leitura aos recursos da API Agent Registry.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.get

agentregistry.services.list

agentregistry.skillRevisions.get

agentregistry.skillRevisions.list

agentregistry.skills.get

agentregistry.skills.list

agentregistry.skills.search

(roles/agentregistry.user)

Criar, atualizar e excluir habilidades e revisões de habilidades.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.get

agentregistry.services.list

agentregistry.skillRevisions.*

  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list

agentregistry.skills.*

  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

Para mais informações sobre as permissões do IAM, consulte Encontrar os papéis predefinidos certos e Índice de papéis e permissões do IAM.