角色和權限

本頁面列出 Agent Registry 的 IAM 角色和權限。

將適當的 Agent Registry IAM 角色授予使用者或群組,讓他們管理或查看登錄檔中的代理程式。如要授予角色,可以使用 Google Cloud 控制台中的「IAM」頁面,也可以使用 Google Cloud CLI。如需詳細操作說明,請參閱「管理專案、資料夾和機構的存取權」。

Agent Registry 角色

下表說明 Agent Registry IAM 角色及其典型職責:

角色

說明

Purpose

Agent Registry API 管理員

執行所有動作,包括手動註冊代理程式和更新中繼資料。

  • 註冊及管理代理和 MCP 伺服器。
  • 更新工具定義和端點。

Agent Registry API 編輯者

具備 Agent Registry 資源的編輯權限。

  • 註冊及管理代理和 MCP 伺服器。
  • 更新工具定義和端點。

Agent Registry API 檢視者

查看代理程式、工具及其屬性。

  • 探索可用的代理和 MCP 伺服器。
  • 查看 A2A 技能、獨立技能和整合端點。

Agent Registry 使用者

可建立、更新及刪除技能和技能修訂版本。

  • 在 Agent Registry 管理代理程式的獨立技能。
  • 保留技能修訂版本的版本管控,並集中管理技能的啟用狀態。

Agent Registry 權限

下表列出各 Agent Registry IAM 角色具備的權限:

(roles/agentregistry.admin)

具備 Agent Registry API 資源的完整存取權。

agentregistry.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search
  • agentregistry.bindings.create
  • agentregistry.bindings.delete
  • agentregistry.bindings.fetchAvailable
  • agentregistry.bindings.get
  • agentregistry.bindings.list
  • agentregistry.bindings.update
  • agentregistry.endpoints.get
  • agentregistry.endpoints.list
  • agentregistry.locations.get
  • agentregistry.locations.list
  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search
  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list
  • agentregistry.publishers.get
  • agentregistry.publishers.list
  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update
  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list
  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

(roles/agentregistry.editor)

具備 Agent Registry API 資源的編輯權限。

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.*

  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.*

  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

agentregistry.skillRevisions.*

  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list

agentregistry.skills.*

  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

(roles/agentregistry.viewer)

具備 Agent Registry API 資源的唯讀存取權。

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.get

agentregistry.services.list

agentregistry.skillRevisions.get

agentregistry.skillRevisions.list

agentregistry.skills.get

agentregistry.skills.list

agentregistry.skills.search

(roles/agentregistry.user)

可建立、更新及刪除技能和技能修訂版本。

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.get

agentregistry.services.list

agentregistry.skillRevisions.*

  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list

agentregistry.skills.*

  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

如要進一步瞭解 IAM 權限,請參閱「尋找合適的預先定義角色」和「IAM 角色和權限索引」。

已註冊資源的存取控管

Agent Registry 角色可控管哪些使用者能管理及探索登錄中的資源。如要控管哪些代理可透過 Agent Gateway 與已註冊的服務、端點和 MCP 伺服器通訊,請使用 Identity-Aware Proxy 輸出政策:

如需設定 IAP 輸出政策的詳細操作說明,請參閱「設定 IAM 代理程式政策」。