여러 팀 구성원이 공동작업으로 에이전트를 빌드하고, 에이전트에 액세스할 서비스를 위해 협력하는 것은 일반적입니다. 역할을 사용하면 주 구성원에게 부여된 액세스와 권한을 제어할 수 있습니다.
Identity and Access Management (IAM)와 함께 Google Cloud 콘솔을 사용하여 액세스를 구성할 수 있습니다. Google Cloud 콘솔은 주 구성원에게 IAM 역할을 부여하는 데 사용됩니다. 권한의 추가, 편집, 제거에 대한 자세한 지침은 IAM 빠른 시작을 참고하세요.
설정에 액세스하려면 Google Cloud 콘솔에서 IAM 페이지를 엽니다.
프로젝트에 사용자 또는 서비스 계정 추가
사용자 또는 서비스 계정에 Google Cloud 프로젝트에 대한 역할을 부여하여 권한을 제공할 수 있습니다. 사용자는 이메일 주소를 제공하여 추가됩니다. 서비스 계정도 연결된 이메일 주소를 제공하여 추가됩니다. 여러 프로젝트에서 서비스 계정 하나를 사용하려면 서비스 계정을 추가해야 합니다. 서비스 계정과 연결된 이메일 주소를 찾으려면 Google Cloud 콘솔에서 IAM 서비스 계정 페이지를 참고하세요.
주 구성원 추가
주 구성원을 추가하려면 다음 단계를 따르세요.
- 페이지 상단에서 를 클릭합니다.
- 주 구성원의 이메일 주소를 입력합니다.
- 역할을 선택합니다.
- 저장을 클릭합니다.
권한 변경
권한을 변경하려면 다음 단계를 따르세요.
- 주 구성원의 아이콘을 클릭합니다.
- 다른 역할을 선택합니다.
- 저장을 클릭합니다.
주 구성원 삭제
주 구성원을 삭제하려면 주 구성원의 를 클릭합니다.
IAM 역할
CX Agent Studio에 액세스할 수 있는 역할은 다음과 같습니다.
Gemini Enterprise for Customer Experience 관리자 (ces.googleapis.com/admin)
이렇게 하면 리소스에 대한 전체 액세스 권한이 제공됩니다.
기본 역할:
ces.googleapis.com/viewerces.googleapis.com/clientcontactcenterinsights.googleapis.com/admin
추가 권한:
ces.googleapis.com/operations.deleteces.googleapis.com/operations.cancelces.googleapis.com/apps.createces.googleapis.com/apps.updateces.googleapis.com/apps.deleteces.googleapis.com/apps.importces.googleapis.com/apps.exportces.googleapis.com/apps.runEvaluationces.googleapis.com/agents.createces.googleapis.com/agents.updateces.googleapis.com/agents.updateCallbacksces.googleapis.com/agents.updateInstructionsces.googleapis.com/agents.updateToolsces.googleapis.com/agents.updateGeneralces.googleapis.com/agents.deleteces.googleapis.com/examples.createces.googleapis.com/examples.updateces.googleapis.com/examples.deleteces.googleapis.com/tools.createces.googleapis.com/tools.updateces.googleapis.com/tools.deleteces.googleapis.com/guardrails.createces.googleapis.com/guardrails.updateces.googleapis.com/guardrails.deleteces.googleapis.com/toolsets.createces.googleapis.com/toolsets.updateces.googleapis.com/toolsets.deleteces.googleapis.com/deployments.createces.googleapis.com/deployments.updateces.googleapis.com/deployments.deleteces.googleapis.com/conversations.deleteces.googleapis.com/evaluations.createces.googleapis.com/evaluations.updateces.googleapis.com/evaluations.deleteces.googleapis.com/evaluationResults.deleteces.googleapis.com/evaluationDatasets.createces.googleapis.com/evaluationDatasets.updateces.googleapis.com/evaluationDatasets.deleteces.googleapis.com/evaluationRuns.deleteces.googleapis.com/scheduledEvaluationRuns.createces.googleapis.com/scheduledEvaluationRuns.updateces.googleapis.com/scheduledEvaluationRuns.deleteces.googleapis.com/appVersions.createces.googleapis.com/appVersions.deleteces.googleapis.com/appVersions.restoreces.googleapis.com/omnichannels.createces.googleapis.com/omnichannels.updateces.googleapis.com/omnichannels.deleteces.googleapis.com/apps.createTagBindingces.googleapis.com/apps.deleteTagBindingces.googleapis.com/apps.listTagBindingsces.googleapis.com/apps.listEffectiveTagsces.googleapis.com/assistantSessions.createces.googleapis.com/routes.createces.googleapis.com/routes.updateces.googleapis.com/routes.deleteces.googleapis.com/endpointConfigs.createces.googleapis.com/endpointConfigs.updateces.googleapis.com/endpointConfigs.deleteces.googleapis.com/sipDomains.createces.googleapis.com/sipDomains.updateces.googleapis.com/sipDomains.deleteces.googleapis.com/securitySettings.update
Gemini Enterprise for Customer Experience 뷰어 (ces.googleapis.com/viewer)
이렇게 하면 리소스에 대한 읽기 전용 액세스 권한이 제공됩니다.
기본 역할:
contactcenterinsights.googleapis.com/viewer
추가 권한:
cloudresourcemanager.googleapis.com/projects.getcloudresourcemanager.googleapis.com/projects.listces.googleapis.com/operations.listces.googleapis.com/operations.getces.googleapis.com/locations.listces.googleapis.com/locations.getces.googleapis.com/apps.listces.googleapis.com/apps.getces.googleapis.com/agents.listces.googleapis.com/agents.getces.googleapis.com/examples.listces.googleapis.com/examples.getces.googleapis.com/tools.listces.googleapis.com/tools.getces.googleapis.com/guardrails.listces.googleapis.com/guardrails.getces.googleapis.com/toolsets.listces.googleapis.com/toolsets.getces.googleapis.com/deployments.listces.googleapis.com/deployments.getces.googleapis.com/conversations.listces.googleapis.com/conversations.getces.googleapis.com/appVersions.listces.googleapis.com/appVersions.getces.googleapis.com/evaluations.listces.googleapis.com/evaluations.getces.googleapis.com/evaluationResults.listces.googleapis.com/evaluationResults.getces.googleapis.com/evaluationDatasets.listces.googleapis.com/evaluationDatasets.getces.googleapis.com/evaluationRuns.listces.googleapis.com/evaluationRuns.getces.googleapis.com/scheduledEvaluationRuns.listces.googleapis.com/scheduledEvaluationRuns.getces.googleapis.com/changelogs.listces.googleapis.com/changelogs.getces.googleapis.com/omnichannels.getces.googleapis.com/omnichannels.listces.googleapis.com/apps.listTagBindingsces.googleapis.com/apps.listEffectiveTagsces.googleapis.com/assistantSessions.listces.googleapis.com/assistantSessions.getces.googleapis.com/routes.listces.googleapis.com/routes.getces.googleapis.com/endpointConfigs.listces.googleapis.com/endpointConfigs.getces.googleapis.com/sipDomains.listces.googleapis.com/sipDomains.getces.googleapis.com/securitySettings.get
Gemini Enterprise for Customer Experience 클라이언트 (ces.googleapis.com/client)
이를 통해 에이전트에 대한 쿼리 액세스가 제공됩니다.
권한:
ces.googleapis.com/sessions.runSessionces.googleapis.com/sessions.bidiRunSessionces.googleapis.com/tools.execute
Gemini Enterprise for Customer Experience 앱 편집자 (ces.googleapis.com/appEditor)
앱 수준 설정에 대한 전체 제어 권한입니다. 전역 로깅, 오디오/음성 구성, 스토리지 버킷, 앱 버전을 관리합니다.
기본 역할:
ces.googleapis.com/viewer
추가 권한:
ces.googleapis.com/apps.createces.googleapis.com/apps.updateces.googleapis.com/apps.deleteces.googleapis.com/apps.importces.googleapis.com/apps.exportces.googleapis.com/apps.runEvaluationces.googleapis.com/apps.createTagBindingces.googleapis.com/apps.deleteTagBindingces.googleapis.com/appVersions.createces.googleapis.com/appVersions.deleteces.googleapis.com/appVersions.restore
Gemini Enterprise for Customer Experience 에이전트 편집자 (ces.googleapis.com/agentEditor)
에이전트 노드 구조, 흐름, 요청 사항, 콜백에 대한 전체 제어 권한입니다. 에이전트에서 도구를 추가/삭제할 수 있습니다 (새 도구는 만들 수 없음).
기본 역할:
ces.googleapis.com/viewerces.googleapis.com/client
추가 권한:
ces.googleapis.com/agents.createces.googleapis.com/agents.updateces.googleapis.com/agents.updateCallbacksces.googleapis.com/agents.updateInstructionsces.googleapis.com/agents.updateToolsces.googleapis.com/agents.updateGeneralces.googleapis.com/agents.deleteces.googleapis.com/examples.createces.googleapis.com/examples.updateces.googleapis.com/examples.delete
Gemini Enterprise for Customer Experience 도구 편집자 (ces.googleapis.com/toolsEditor)
도구, 도구 세트, 통합에 대한 전체 제어 권한입니다.
기본 역할:
ces.googleapis.com/viewerces.googleapis.com/client
추가 권한:
ces.googleapis.com/tools.createces.googleapis.com/tools.updateces.googleapis.com/tools.deleteces.googleapis.com/toolsets.createces.googleapis.com/toolsets.updateces.googleapis.com/toolsets.delete
Gemini Enterprise for Customer Experience 가드레일 편집자 (ces.googleapis.com/guardrailsEditor)
안전 설정 및 가드레일에 대한 전체 제어 권한입니다.
기본 역할:
- ces.googleapis.com/viewer
- ces.googleapis.com/client
추가 권한:
- ces.googleapis.com/guardrails.create
- ces.googleapis.com/guardrails.update
- ces.googleapis.com/guardrails.delete
Gemini Enterprise for Customer Experience 평가 편집자 (ces.googleapis.com/evalsEditor)
평가 데이터 세트, 실행, 결과에 대한 전체 제어 권한입니다.
기본 역할:
ces.googleapis.com/viewerces.googleapis.com/client
추가 권한:
ces.googleapis.com/evaluations.createces.googleapis.com/evaluations.updateces.googleapis.com/evaluations.deleteces.googleapis.com/evaluationResults.deleteces.googleapis.com/evaluationDatasets.createces.googleapis.com/evaluationDatasets.updateces.googleapis.com/evaluationDatasets.deleteces.googleapis.com/evaluationRuns.deleteces.googleapis.com/scheduledEvaluationRuns.createces.googleapis.com/scheduledEvaluationRuns.updateces.googleapis.com/scheduledEvaluationRuns.delete
Gemini Enterprise for Customer Experience 보안 설정 편집자 (ces.googleapis.com/securitySettingsEditor)
프로젝트 전체 보안 설정을 완전히 제어할 수 있습니다.
기본 역할:
ces.googleapis.com/viewer
추가 권한:
ces.googleapis.com/securitySettings.update
Gemini Enterprise for Customer Experience 배포 편집자 (ces.googleapis.com/deploymentEditor)
환경을 관리하고 특정 앱 버전을 환경에 배포할 수 있습니다.
기본 역할:
ces.googleapis.com/viewer
추가 권한:
ces.googleapis.com/deployments.createces.googleapis.com/deployments.updateces.googleapis.com/deployments.delete
고객 경험 인사이트
CX Agent Studio는 CX Insights와 통합되며 CX Agent Studio에 액세스하는 주 구성원에게 다음 CX Insights 권한을 제공해야 합니다.
contactcenterinsights.googleapis.com/conversations.getcontactcenterinsights.googleapis.com/conversations.list
이러한 권한은 ces.googleapis.com/admin 및 ces.googleapis.com/viewer의 하위 역할에 의해 자동으로 포함됩니다.
하지만 커스텀 역할을 정의하는 경우 커스텀 역할 정의에 이러한 권한을 포함해야 합니다.
또는 관련 주 구성원에게 다음 CX 통계 역할 중 하나를 부여할 수 있습니다.
contactcenterinsights.googleapis.com/viewer: 대화에 대한 읽기 전용 액세스 권한을 제공합니다.contactcenterinsights.googleapis.com/admin: 대화에 대한 전체 액세스 권한을 부여합니다.
역할 외에도 디스커버리 엔진 설정 단계를 따라야 할 수도 있습니다.
Cloud Storage 액세스와 관련된 요청
일부 CX Agent Studio는 데이터 읽기 또는 쓰기를 위해 Cloud Storage의 객체에 액세스합니다. 이러한 요청 중 하나를 호출하면 CX Agent Studio가 호출자를 대신하여 Cloud Storage 데이터에 액세스합니다. 즉, 요청 인증에 CX Agent Studio 및 Cloud Storage 객체에 액세스할 수 있는 권한이 있어야 합니다.
Google 클라이언트 라이브러리 및 IAM 역할을 사용할 때 Cloud Storage 역할에 대해서는 Cloud Storage 액세스 제어 가이드에서 자세히 알아보세요.
자체 클라이언트를 구현하여 OAuth를 사용할 때는 다음 OAuth 범위를 사용해야 합니다.
https://www.googleapis.com/auth/cloud-platform(모든 프로젝트 리소스에 대한 액세스 권한)
하나의 에이전트 애플리케이션에 대한 액세스를 제한하는 조건 추가
주 구성원을 추가하거나 수정할 때 하나의 에이전트 애플리케이션에 대한 액세스를 제한하는 조건부 역할 바인딩을 만들 수 있습니다.
다음 조건은 특정 에이전트 애플리케이션과 에이전트 애플리케이션에 필요한 프로젝트 내 최상위 리소스에 대한 액세스 권한을 제공합니다.
resource.name == "projects/PROJECT_ID" ||
resource.name.startsWith("projects/PROJECT_ID/locations/LOCATION_ID/apps/APP_ID") ||
resource.name.startsWith("projects/PROJECT_ID/locations/LOCATION_ID/operations") ||
resource.name.startsWith("projects/PROJECT_ID/locations/LOCATION_ID/sipDomains") ||
resource.name.startsWith("projects/PROJECT_ID/locations/LOCATION_ID/omnichannels") ||
resource.name.startsWith("projects/PROJECT_ID/locations/LOCATION_ID/dataStores") ||
resource.name.startsWith("projects/PROJECT_ID/locations/LOCATION_ID/routes") ||
resource.name.startsWith("projects/PROJECT_ID/locations/LOCATION_ID/endpointConfigs")
고객 경험 통계에 액세스하려면 조건부 부여 외에도 고객 경험 통계 역할을 부여해야 합니다.