Enable cross-organizational access with trusted orgs

This page is intended for Google Cloud organization administrators and Data Studio Pro administrators who need to enable cross-organizational user access on a self-service subscription.

To add users from external Google Cloud organizations to your Data Studio Pro subscription, contact Cloud Customer Care to enable the trusted orgs feature. Afterwards, you can assign licenses directly to individual user email addresses from those allowed domains right inside your subscription.

Before you begin

Before you allow external users on your subscription, ensure that you meet the following requirements:

  • Self-service subscription: Your subscription must be self-service. Trusted organizations aren't available for organization-wide Monthly Active User (MAU) subscriptions.
  • Support contract: You must have an active support contract with Cloud Customer Care.
  • Domain Restricted Sharing policy (constraints/iam.allowedPolicyMemberDomains): If your organization enforces this policy, an organization administrator must navigate to IAM & Admin > Organization Policies in the Google Cloud console, edit constraints/iam.allowedPolicyMemberDomains, and add the numeric Google Workspace customer ID of each external organization to Allowed values. Otherwise, IAM blocks granting project or data permissions to external users or administrators.
  • Project and data permissions: Individual Data Studio Pro users don't need specific IAM (IAM) permissions on the project just to use Pro features or consume a license. Assigning IAM roles (such as Looker Studio Pro Manager) is required only for administrators or service accounts that manage the subscription itself. However, if external users query restricted Google Cloud data sources by using their own credentials, an administrator must grant them the appropriate data-level IAM permissions (such as BigQuery Data Viewer).

For complete role requirements, see Data Studio Pro roles and permissions.

Request trusted org enablement

To enable trusted organizations across your subscription, complete the following steps:

  1. Obtain the primary domain name (for example, example.com) and numeric Google Cloud organization ID for each organization that you want to trust.
    • Tip: An administrator of the external organization can find this numeric ID inside the Google Cloud console under IAM & Admin > Settings. Provide the numeric Google Cloud organization ID rather than the alphanumeric Google Workspace ID.
  2. Submit a support case to Cloud Customer Care requesting to enable the Trusted Orgs feature on your Data Studio Pro subscription. Include the domain name and numeric organization ID for each trusted domain in your request.

Important considerations

  • Individual user assignment: After Cloud Customer Care enables the feature, you can assign licenses to individual user email addresses from the trusted domain. You can't add Google Groups from an external organization to your subscription.
  • Permanence: You can't disable the trusted organizations feature after enabling it on your subscription.