Enable Augmented Administrative Access
This page describes how to enable Augmented Administrative Access for your Google Cloud organization, folder, or project. Enabling this feature provides more granular details in both Access Approval requests and Access Transparency logs for supported services and fields.
Before you begin
- Ensure that your organization has been added to the allowlist for this feature.
- Enable Access Transparency.
- Enable Access Approval.
Required roles
To get the permission that
you need to modifyAccess Approval settings,
ask your administrator to grant you the
Access Approval Config Editor (roles/accessapproval.configEditor)
IAM role on your organization.
For more information about granting roles, see Manage access to projects, folders, and organizations.
This predefined role contains the
accessapproval.settings.get
permission,
which is required to
modifyAccess Approval settings.
You might also be able to get this permission with custom roles or other predefined roles.
Enable Augmented Administrative Access using the Google Cloud console
You can enable Augmented Administrative Access at the organization, folder, or project level in the Google Cloud console:
In the Google Cloud console, go to the Access Approval page.
Select the organization, folder, or project that you want to enable the feature on.
Click Manage Settings.
Locate the section for Augmented Administrative Access.
To turn on the setting, click the Augmented Administrative Access toggle.
Click Save.
What's next
- Learn about Augmented Administrative Access.