2026 年 3 月 29 日の週に予定されている権限の変更

新しい機能と既存の機能に対する制御とアクセスをより標準化するため、次の表に示す事前定義ロールに新しい権限を追加します。これらの変更は 2026 年 3 月 29 日に適用されます。

サービス 詳細
Vertex AI

次の権限が Vertex AI 閲覧者ロール(roles/aiplatform.viewer)に追加されます。

aiplatform.endpoints.explain
aiplatform.endpoints.getIamPolicy
aiplatform.endpoints.predict
aiplatform.entityTypes.exportFeatureValues
aiplatform.entityTypes.getIamPolicy
aiplatform.entityTypes.readFeatureValues
aiplatform.entityTypes.streamingReadFeatureValues
aiplatform.featureGroups.getIamPolicy
aiplatform.featureOnlineStores.getIamPolicy
aiplatform.featureViews.getIamPolicy
aiplatform.featurestores.batchReadFeatureValues
aiplatform.featurestores.getIamPolicy
aiplatform.featurestores.readFeatures
aiplatform.humanInTheLoops.queryAnnotationStats
aiplatform.locations.evaluateInstances
aiplatform.memories.retrieve
aiplatform.migratableResources.search
aiplatform.notebookRuntimeTemplates.apply
aiplatform.notebookRuntimeTemplates.getIamPolicy

BigQuery Sharing

次の権限が Analytics Hub 管理者ロール(roles/analyticshub.admin)に追加されます。

analyticshub.dataExchanges.subscribe
analyticshub.listings.subscribe

BigQuery Sharing

次の権限が Analytics Hub 閲覧者のロール(roles/analyticshub.viewer)に追加されます。

analyticshub.subscriptions.get
analyticshub.subscriptions.list

Apigee Connect

次の権限が Apigee Connect 管理者ロール(roles/apigeeconnect.Admin)に追加されます。

apigeeconnect.endpoints.connect

App Hub

次の権限が App Hub 編集者のロール(roles/apphub.editor)に追加されます。

apphub.applications.getIamPolicy
apphub.serviceProjectAttachments.create
apphub.serviceProjectAttachments.delete
apphub.serviceProjectAttachments.get
apphub.serviceProjectAttachments.list

App Hub

次の権限が App Hub 閲覧者ロール(roles/apphub.viewer)に追加されます。

apphub.applications.getIamPolicy
apphub.serviceProjectAttachments.get
apphub.serviceProjectAttachments.list

Artifact Registry

次の権限が Artifact Registry 管理者ロール(roles/artifactregistry.admin)に追加されます。

artifactregistry.repositories.createOnPush

バックアップと障害復旧

次の権限が Backup and DR 管理者ロール(roles/backupdr.admin)に追加されます。

backupdr.resourceBackupConfigs.get
backupdr.resourceBackupConfigs.list

バックアップと障害復旧

次の権限がバックアップと DR の閲覧者ロール(roles/backupdr.viewer)に追加されます。

backupdr.resourceBackupConfigs.get
backupdr.resourceBackupConfigs.list

Bare Metal Solution

次の権限が Bare Metal Solution 管理者ロール(roles/baremetalsolution.admin)に追加されます。

baremetalsolution.procurements.create

Bare Metal Solution

次の権限が Bare Metal Solution 編集者のロール(roles/baremetalsolution.editor)に追加されます。

baremetalsolution.procurements.create

バッチ

次の権限が Batch 管理者ロール(roles/batch.admin)に追加されます。

batch.states.report

BigLake

次の権限が BigLake 編集者ロール(roles/biglake.editor)に追加されます。

biglake.databases.create
biglake.databases.delete
biglake.databases.get
biglake.databases.list
biglake.databases.update
biglake.locks.check
biglake.locks.create
biglake.locks.delete
biglake.locks.list
biglake.tables.lock

BigQuery Migration API

次の権限が MigrationWorkflow 編集者ロール(roles/bigquerymigration.editor)に追加されます。

bigquerymigration.translation.translate

Bigtable

次の権限が Bigtable 閲覧者ロール(roles/bigtable.viewer)に追加されます。

bigtable.authorizedViews.getIamPolicy
bigtable.authorizedViews.listEffectiveTags
bigtable.authorizedViews.listTagBindings
bigtable.authorizedViews.readRows
bigtable.authorizedViews.sampleRowKeys
bigtable.backups.getIamPolicy
bigtable.backups.read
bigtable.instances.executeQuery
bigtable.instances.getIamPolicy
bigtable.instances.ping
bigtable.keyvisualizer.get
bigtable.keyvisualizer.list
bigtable.logicalViews.getIamPolicy
bigtable.logicalViews.readRows
bigtable.materializedViews.getIamPolicy
bigtable.materializedViews.readRows
bigtable.materializedViews.sampleRowKeys
bigtable.schemaBundles.getIamPolicy
bigtable.tables.getIamPolicy
bigtable.tables.readRows
bigtable.tables.sampleRowKeys

Cloud Billing

次の権限が請求先アカウント管理者ロール(roles/billing.admin)に追加されます。

billing.costRecommendations.listScoped
billing.resourceCosts.get
billing.resourcebudgets.read
billing.resourcebudgets.write

Cloud Billing

次の権限が請求先アカウント閲覧者のロール(roles/billing.viewer)に追加されます。

billing.costRecommendations.listScoped
billing.resourceCosts.get
billing.resourcebudgets.read

Certificate Manager

次の権限が Certificate Manager 編集者ロール(roles/certificatemanager.editor)に追加されます。

certificatemanager.certissuanceconfigs.delete
certificatemanager.certmapentries.delete
certificatemanager.certmaps.delete
certificatemanager.certs.delete
certificatemanager.dnsauthorizations.delete
certificatemanager.operations.cancel
certificatemanager.operations.delete
certificatemanager.trustconfigs.delete

Google Security Operations

次の権限が Chronicle API 管理者ロール(roles/chronicle.admin)に追加されます。

chronicle.federationGroups.create
chronicle.federationGroups.delete
chronicle.federationGroups.get
chronicle.federationGroups.list
chronicle.federationGroups.update
chronicle.instances.delete
chronicle.instances.permitFederationAccess
chronicle.instances.soarThreatManager
chronicle.instances.soarVulnerabilityManager
chronicle.instances.undelete

Google Security Operations

次の権限が Chronicle API 編集者ロール(roles/chronicle.editor)に追加されます。

chronicle.calculatedFieldDefinitions.update
chronicle.collectors.create
chronicle.collectors.delete
chronicle.collectors.update
chronicle.connectors.delete
chronicle.connectors.get
chronicle.connectors.update
chronicle.customFields.update
chronicle.enrichmentControls.delete
chronicle.entitiesBlocklists.delete
chronicle.entitiesBlocklists.update
chronicle.errorNotificationConfigs.create
chronicle.errorNotificationConfigs.delete
chronicle.errorNotificationConfigs.update
chronicle.federationGroups.get
chronicle.federationGroups.list
chronicle.formDynamicParameters.update
chronicle.forwarders.create
chronicle.forwarders.delete
chronicle.forwarders.update
chronicle.instances.permitFederationAccess
chronicle.instances.verifyNonce
chronicle.integrationActions.delete
chronicle.integrations.delete
chronicle.jobs.delete
chronicle.legacyCaseFederationPlatforms.delete
chronicle.legacyCaseFederationPlatforms.get
chronicle.legacyCaseFederationPlatforms.update
chronicle.logProcessingPipelines.associateStreams
chronicle.logProcessingPipelines.create
chronicle.logProcessingPipelines.delete
chronicle.logProcessingPipelines.dissociateStreams
chronicle.logProcessingPipelines.update
chronicle.moduleSettingsProperties.get
chronicle.rules.delete
chronicle.shareConfigs.get
chronicle.shareConfigs.update
chronicle.systemNotifications.get
chronicle.systemNotifications.update
chronicle.tenants.create
chronicle.tenants.list
chronicle.tenants.update

Google Security Operations

次の権限が Chronicle API 閲覧者ロール(roles/chronicle.viewer)に追加されます。

chronicle.caseWallRecords.get
chronicle.connectorInstanceLogs.get
chronicle.connectorInstances.get
chronicle.connectorRevisions.get
chronicle.connectors.get
chronicle.contentPacks.export
chronicle.customLists.get
chronicle.emailTemplates.get
chronicle.entitiesBlocklists.get
chronicle.federationGroups.get
chronicle.federationGroups.list
chronicle.instances.permitFederationAccess
chronicle.instances.verifyNonce
chronicle.integrationActionRevisions.get
chronicle.integrationInstances.get
chronicle.integrationLogicalOperatorRevisions.get
chronicle.integrationLogicalOperators.get
chronicle.integrations.get
chronicle.jobInstanceLogs.get
chronicle.jobInstances.get
chronicle.jobRevisions.get
chronicle.jobs.get
chronicle.legacyCaseFederationPlatforms.get
chronicle.legacyPlaybooks.get
chronicle.managerRevisions.get
chronicle.managers.get
chronicle.moduleSettingsProperties.get
chronicle.notificationSettings.get
chronicle.remoteAgents.get
chronicle.shareConfigs.get
chronicle.systemNotifications.get
chronicle.tasks.get
chronicle.tenants.list
chronicle.transformerDefinitions.get
chronicle.transformerDefinitions.list
chronicle.transformerRevisions.get
chronicle.uniqueEntities.get
chronicle.userLocalizations.get
chronicle.userNotifications.get
chronicle.workdeskContacts.get
chronicle.workdeskLinks.get
chronicle.workdeskNotes.get

Cloud Asset Inventory

次の権限が Cloud Asset 閲覧者のロール(roles/cloudasset.viewer)に追加されます。

cloudasset.savedqueries.get
cloudasset.savedqueries.list

Cloud Run functions

次の権限が Cloud Functions 閲覧者ロール(roles/cloudfunctions.viewer)に追加されます。

cloudfunctions.functions.sourceCodeGet

Talent Solution

次の権限が Cloud Talent Solution 管理者ロール(roles/cloudjobdiscovery.admin)に追加されます。

cloudjobdiscovery.companies.create
cloudjobdiscovery.companies.delete
cloudjobdiscovery.companies.get
cloudjobdiscovery.companies.list
cloudjobdiscovery.companies.update
cloudjobdiscovery.events.create
cloudjobdiscovery.jobs.create
cloudjobdiscovery.jobs.delete
cloudjobdiscovery.jobs.get
cloudjobdiscovery.jobs.search
cloudjobdiscovery.jobs.update
cloudjobdiscovery.profiles.create
cloudjobdiscovery.profiles.delete
cloudjobdiscovery.profiles.get
cloudjobdiscovery.profiles.search
cloudjobdiscovery.profiles.update
cloudjobdiscovery.tenants.create
cloudjobdiscovery.tenants.delete
cloudjobdiscovery.tenants.get
cloudjobdiscovery.tenants.update

Cloud Key Management Service

次の権限が Cloud KMS 管理者ロール(roles/cloudkms.admin)に追加されます。

cloudkms.cryptoKeyVersions.manageRawAesCbcKeys
cloudkms.cryptoKeyVersions.manageRawAesCtrKeys
cloudkms.cryptoKeyVersions.manageRawPKCS1Keys
cloudkms.cryptoKeyVersions.useToDecapsulate
cloudkms.cryptoKeyVersions.useToDecrypt
cloudkms.cryptoKeyVersions.useToEncrypt
cloudkms.cryptoKeyVersions.useToSign
cloudkms.cryptoKeyVersions.useToVerify
cloudkms.cryptoKeyVersions.viewPublicKey
cloudkms.locations.generateRandomBytes
cloudkms.protectedResources.search
cloudkms.singleTenantHsmInstanceProposals.approve
cloudkms.singleTenantHsmInstanceProposals.create
cloudkms.singleTenantHsmInstanceProposals.execute

Cloud Key Management Service

次の権限が Cloud KMS 閲覧者のロール(roles/cloudkms.viewer)に追加されます。

cloudkms.cryptoKeys.getIamPolicy
cloudkms.ekmConfigs.getIamPolicy
cloudkms.ekmConnections.getIamPolicy
cloudkms.ekmConnections.verifyConnectivity
cloudkms.importJobs.getIamPolicy
cloudkms.keyRings.getIamPolicy
cloudkms.keyRings.listEffectiveTags
cloudkms.keyRings.listTagBindings
cloudkms.locations.generateRandomBytes
cloudkms.projects.showEffectiveAutokeyConfig
cloudkms.projects.showEffectiveKajEnrollmentConfig
cloudkms.projects.showEffectiveKajPolicyConfig
cloudkms.protectedResources.search

Cloud SQL

次の権限が Cloud SQL 編集者ロール(roles/cloudsql.editor)に追加されます。

cloudsql.backupRuns.delete
cloudsql.databases.delete
cloudsql.instances.clone
cloudsql.instances.create
cloudsql.instances.createBackupDrBackup
cloudsql.instances.delete
cloudsql.instances.demoteMaster
cloudsql.instances.executeSql
cloudsql.instances.import
cloudsql.instances.login
cloudsql.instances.promoteReplica
cloudsql.instances.resetSslConfig
cloudsql.instances.restoreBackup
cloudsql.instances.startReplica
cloudsql.instances.stopReplica
cloudsql.instances.updateBackupDrConfig
cloudsql.sslCerts.create
cloudsql.sslCerts.delete
cloudsql.users.create
cloudsql.users.delete
cloudsql.users.update

Cloud SQL

次の権限が Cloud SQL 閲覧者ロール(roles/cloudsql.viewer)に追加されます。

cloudsql.instances.createBackupDrBackup
cloudsql.schemas.view

Google Cloud サポート

次の権限がサポート アカウント管理者ロール(roles/cloudsupport.admin)に追加されます。

cloudsupport.techCases.create
cloudsupport.techCases.escalate
cloudsupport.techCases.get
cloudsupport.techCases.list
cloudsupport.techCases.update

Google Cloud サポート

次の権限がサポート アカウント閲覧者の役割(roles/cloudsupport.viewer)に追加されます。

cloudsupport.accounts.getIamPolicy
cloudsupport.operations.get
cloudsupport.techCases.get
cloudsupport.techCases.list

Translation

次の権限が Cloud Translation API 閲覧者ロール(roles/cloudtranslate.viewer)に追加されます。

cloudtranslate.adaptiveMtDatasets.predict
cloudtranslate.customModels.predict
cloudtranslate.datasets.export
cloudtranslate.generalModels.batchDocPredict
cloudtranslate.generalModels.batchPredict
cloudtranslate.generalModels.docPredict
cloudtranslate.generalModels.predict
cloudtranslate.glossaries.batchDocPredict
cloudtranslate.glossaries.batchPredict
cloudtranslate.glossaries.docPredict
cloudtranslate.glossaries.predict
cloudtranslate.languageDetectionModels.predict

Compute Engine

次の権限が Compute 閲覧者ロール(roles/compute.viewer)に追加されます。

compute.disks.createSnapshot
compute.disks.useReadOnly
compute.healthChecks.useReadOnly
compute.httpHealthChecks.useReadOnly
compute.httpsHealthChecks.useReadOnly
compute.images.useReadOnly
compute.instanceTemplates.useReadOnly
compute.instances.useReadOnly
compute.instantSnapshots.useReadOnly
compute.machineImages.useReadOnly
compute.regionHealthChecks.useReadOnly
compute.resourcePolicies.useReadOnly
compute.snapshots.useReadOnly

コネクタ

次の権限がコネクタ管理者ロール(roles/connectors.admin)に追加されます。

connectors.connections.listenEvent

コネクタ

次の権限がコネクタ閲覧者のロール(roles/connectors.viewer)に追加されます。

connectors.actions.list
connectors.entities.get
connectors.entities.list
connectors.entityTypes.list

Google Cloud Contact Center as a Service

次の権限が Contact Center AI Platform 管理者ロール(roles/contactcenteraiplatform.admin)に追加されます。

contactcenteraiplatform.locations.generateShifts

Google Cloud Contact Center as a Service

次の権限がコンタクト センター AI プラットフォーム閲覧者ロール(roles/contactcenteraiplatform.viewer)に追加されます。

contactcenteraiplatform.contactCenters.queryQuota

カスタマー エクスペリエンスのインサイト

次の権限が Contact Center AI Insights 編集者ロール(roles/contactcenterinsights.editor)に追加されます。

contactcenterinsights.authorizedViews.getIamPolicy

カスタマー エクスペリエンスのインサイト

次の権限が Contact Center AI Insights 閲覧者ロール(roles/contactcenterinsights.viewer)に追加されます。

contactcenterinsights.authorizedViews.getIamPolicy

Google Kubernetes Engine

次の権限が Kubernetes Engine クラスタ閲覧者ロール(roles/container.clusterViewer)に追加されます。

container.clusters.listEffectiveTags
container.clusters.listTagBindings
container.pods.getLogs
container.selfSubjectAccessReviews.create
container.selfSubjectRulesReviews.create
container.volumeSnapshots.getStatus

Content Warehouse

次の権限が Content Warehouse 管理者ロール(roles/contentwarehouse.admin)に追加されます。

contentwarehouse.links.create
contentwarehouse.links.delete
contentwarehouse.links.get
contentwarehouse.links.update

データベース分析情報

次の権限がデータベース分析情報閲覧者ロール(roles/databaseinsights.viewer)に追加されます。

databaseinsights.aggregatedEvents.query
databaseinsights.clusterEvents.query
databaseinsights.instanceEvents.query

Data Catalog

次の権限が Data Catalog 閲覧者ロール(roles/datacatalog.viewer)に追加されます。

datacatalog.categories.getIamPolicy
datacatalog.taxonomies.getIamPolicy

Dataflow

次の権限が Dataflow 管理者ロール(roles/dataflow.admin)に追加されます。

dataflow.shuffle.read
dataflow.shuffle.write
dataflow.streamingWorkItems.ImportState
dataflow.streamingWorkItems.commitWork
dataflow.streamingWorkItems.getData
dataflow.streamingWorkItems.getWork
dataflow.streamingWorkItems.getWorkerMetadata
dataflow.workItems.lease
dataflow.workItems.sendMessage
dataflow.workItems.update

Dataform

次の権限が Dataform 編集者ロール(roles/dataform.editor)に追加されます。

dataform.commentThreads.create
dataform.commentThreads.delete
dataform.commentThreads.update
dataform.comments.create
dataform.comments.delete
dataform.comments.update
dataform.config.update
dataform.folders.addContents
dataform.folders.create
dataform.folders.delete
dataform.folders.move
dataform.folders.update
dataform.operations.cancel
dataform.operations.delete
dataform.releaseConfigs.create
dataform.releaseConfigs.delete
dataform.releaseConfigs.update
dataform.repositories.commit
dataform.repositories.create
dataform.repositories.delete
dataform.repositories.move
dataform.repositories.scheduleRelease
dataform.repositories.scheduleWorkflow
dataform.repositories.update
dataform.teamFolders.create
dataform.teamFolders.delete
dataform.teamFolders.update
dataform.workflowConfigs.create
dataform.workflowConfigs.delete
dataform.workflowConfigs.update

Data Lineage API

次の権限がデータ リネージ編集者ロール(roles/datalineage.editor)に追加されます。

datalineage.configs.get
datalineage.configs.update
datalineage.processes.delete
datalineage.runs.delete

Data Lineage API

次の権限がデータリネージ閲覧者のロール(roles/datalineage.viewer)に追加されます。

datalineage.configs.get
datalineage.operations.get

Dataplex Universal Catalog

次の権限が Dataplex 管理者ロール(roles/dataplex.admin)に追加されます。

dataplex.aspectTypes.create
dataplex.aspectTypes.delete
dataplex.aspectTypes.get
dataplex.aspectTypes.getIamPolicy
dataplex.aspectTypes.list
dataplex.aspectTypes.setIamPolicy
dataplex.aspectTypes.update
dataplex.aspectTypes.use
dataplex.assets.ownData
dataplex.assets.readData
dataplex.assets.writeData
dataplex.encryptionConfig.create
dataplex.encryptionConfig.delete
dataplex.encryptionConfig.get
dataplex.encryptionConfig.list
dataplex.encryptionConfig.update
dataplex.entries.create
dataplex.entries.delete
dataplex.entries.get
dataplex.entries.getData
dataplex.entries.list
dataplex.entries.update
dataplex.entryGroups.create
dataplex.entryGroups.delete
dataplex.entryGroups.get
dataplex.entryGroups.getIamPolicy
dataplex.entryGroups.list
dataplex.entryGroups.setIamPolicy
dataplex.entryGroups.update
dataplex.entryGroups.useContactsAspect
dataplex.entryGroups.useDataProfileAspect
dataplex.entryGroups.useDataQualityScorecardAspect
dataplex.entryGroups.useDescriptionsAspect
dataplex.entryGroups.useGenericAspect
dataplex.entryGroups.useGenericEntry
dataplex.entryGroups.useOverviewAspect
dataplex.entryGroups.useQueriesAspect
dataplex.entryGroups.useRefreshCadenceAspect
dataplex.entryGroups.useSchemaAspect
dataplex.entryGroups.useStorageAspect
dataplex.entryTypes.create
dataplex.entryTypes.delete
dataplex.entryTypes.get
dataplex.entryTypes.getIamPolicy
dataplex.entryTypes.list
dataplex.entryTypes.setIamPolicy
dataplex.entryTypes.update
dataplex.entryTypes.use
dataplex.projects.search

Dataplex Universal Catalog

次の権限が Dataplex 編集者ロール(roles/dataplex.editor)に追加されます。

dataplex.aspectTypes.create
dataplex.aspectTypes.delete
dataplex.aspectTypes.get
dataplex.aspectTypes.getIamPolicy
dataplex.aspectTypes.list
dataplex.aspectTypes.update
dataplex.aspectTypes.use
dataplex.assets.readData
dataplex.assets.writeData
dataplex.content.create
dataplex.content.update
dataplex.datascans.getData
dataplex.encryptionConfig.create
dataplex.encryptionConfig.delete
dataplex.encryptionConfig.get
dataplex.encryptionConfig.list
dataplex.encryptionConfig.update
dataplex.entities.create
dataplex.entities.delete
dataplex.entities.get
dataplex.entities.list
dataplex.entities.update
dataplex.entries.create
dataplex.entries.delete
dataplex.entries.get
dataplex.entries.getData
dataplex.entries.link
dataplex.entries.list
dataplex.entries.update
dataplex.entryGroups.create
dataplex.entryGroups.delete
dataplex.entryGroups.export
dataplex.entryGroups.get
dataplex.entryGroups.getIamPolicy
dataplex.entryGroups.import
dataplex.entryGroups.list
dataplex.entryGroups.update
dataplex.entryGroups.useContactsAspect
dataplex.entryGroups.useDataProfileAspect
dataplex.entryGroups.useDataQualityScorecardAspect
dataplex.entryGroups.useDefinitionEntryLink
dataplex.entryGroups.useDescriptionsAspect
dataplex.entryGroups.useGenericAspect
dataplex.entryGroups.useGenericEntry
dataplex.entryGroups.useOverviewAspect
dataplex.entryGroups.useQueriesAspect
dataplex.entryGroups.useRefreshCadenceAspect
dataplex.entryGroups.useRelatedEntryLink
dataplex.entryGroups.useSchemaAspect
dataplex.entryGroups.useStorageAspect
dataplex.entryGroups.useSynonymEntryLink
dataplex.entryLinks.create
dataplex.entryLinks.delete
dataplex.entryLinks.get
dataplex.entryLinks.reference
dataplex.entryTypes.create
dataplex.entryTypes.delete
dataplex.entryTypes.get
dataplex.entryTypes.getIamPolicy
dataplex.entryTypes.list
dataplex.entryTypes.update
dataplex.entryTypes.use
dataplex.environments.execute
dataplex.glossaries.create
dataplex.glossaries.delete
dataplex.glossaries.get
dataplex.glossaries.getIamPolicy
dataplex.glossaries.import
dataplex.glossaries.list
dataplex.glossaries.update
dataplex.glossaryCategories.create
dataplex.glossaryCategories.delete
dataplex.glossaryCategories.get
dataplex.glossaryCategories.list
dataplex.glossaryCategories.update
dataplex.glossaryTerms.create
dataplex.glossaryTerms.delete
dataplex.glossaryTerms.get
dataplex.glossaryTerms.list
dataplex.glossaryTerms.update
dataplex.glossaryTerms.use
dataplex.locations.get
dataplex.locations.list
dataplex.metadataJobs.cancel
dataplex.metadataJobs.create
dataplex.metadataJobs.get
dataplex.metadataJobs.list
dataplex.partitions.create
dataplex.partitions.delete
dataplex.partitions.get
dataplex.partitions.list
dataplex.partitions.update
dataplex.projects.search

Dataplex Universal Catalog

次の権限が Dataplex 閲覧者のロール(roles/dataplex.viewer)に追加されます。

dataplex.aspectTypes.get
dataplex.aspectTypes.getIamPolicy
dataplex.aspectTypes.list
dataplex.assets.readData
dataplex.datascans.getData
dataplex.encryptionConfig.get
dataplex.encryptionConfig.list
dataplex.entities.get
dataplex.entities.list
dataplex.entries.get
dataplex.entries.getData
dataplex.entries.list
dataplex.entryGroups.export
dataplex.entryGroups.get
dataplex.entryGroups.getIamPolicy
dataplex.entryGroups.list
dataplex.entryLinks.get
dataplex.entryTypes.get
dataplex.entryTypes.getIamPolicy
dataplex.entryTypes.list
dataplex.glossaries.get
dataplex.glossaries.getIamPolicy
dataplex.glossaries.list
dataplex.glossaryCategories.get
dataplex.glossaryCategories.list
dataplex.glossaryTerms.get
dataplex.glossaryTerms.list
dataplex.locations.get
dataplex.locations.list
dataplex.metadataJobs.get
dataplex.metadataJobs.list
dataplex.partitions.get
dataplex.partitions.list
dataplex.projects.search

Dataproc

次の権限が Dataproc 管理者ロール(roles/dataproc.admin)に追加されます。

dataproc.agents.create
dataproc.agents.delete
dataproc.agents.get
dataproc.agents.list
dataproc.agents.update
dataproc.tasks.lease
dataproc.tasks.listInvalidatedLeases
dataproc.tasks.reportStatus

Dataproc

次の権限が Dataproc 編集者ロール(roles/dataproc.editor)に追加されます。

dataproc.agents.create
dataproc.agents.delete
dataproc.agents.get
dataproc.agents.list
dataproc.agents.update
dataproc.autoscalingPolicies.getIamPolicy
dataproc.clusters.getIamPolicy
dataproc.jobs.getIamPolicy
dataproc.operations.getIamPolicy
dataproc.tasks.lease
dataproc.tasks.listInvalidatedLeases
dataproc.tasks.reportStatus
dataproc.workflowTemplates.getIamPolicy

Dataproc

次の権限が Dataproc 閲覧者ロール(roles/dataproc.viewer)に追加されます。

dataproc.agents.get
dataproc.agents.list
dataproc.autoscalingPolicies.getIamPolicy
dataproc.autoscalingPolicies.use
dataproc.clusters.getIamPolicy
dataproc.jobs.getIamPolicy
dataproc.operations.getIamPolicy
dataproc.tasks.listInvalidatedLeases
dataproc.workflowTemplates.getIamPolicy

Firestore

次の権限が Cloud Datastore 閲覧者ロール(roles/datastore.viewer)に追加されます。

datastore.backupSchedules.get
datastore.backupSchedules.list
datastore.backups.get
datastore.backups.list
datastore.databases.listEffectiveTags
datastore.databases.listTagBindings
datastore.keyVisualizerScans.get
datastore.keyVisualizerScans.list
datastore.operations.get
datastore.operations.list
datastore.userCreds.get
datastore.userCreds.list

ディスカバリー エンジン

次の権限がディスカバリー エンジン管理者ロール(roles/discoveryengine.admin)に追加されます。

discoveryengine.accounts.create
discoveryengine.audioOverviews.create
discoveryengine.audioOverviews.delete
discoveryengine.audioOverviews.get
discoveryengine.audioOverviews.getIceConfig
discoveryengine.audioOverviews.sendSdpOffer
discoveryengine.notebooks.create
discoveryengine.notebooks.generateGuide
discoveryengine.notebooks.get
discoveryengine.notebooks.getAnalytics
discoveryengine.notebooks.getIamPolicy
discoveryengine.notebooks.interactSources
discoveryengine.notebooks.list
discoveryengine.notebooks.removeSelf
discoveryengine.notebooks.setIamPolicy
discoveryengine.notebooks.update
discoveryengine.notes.create
discoveryengine.notes.delete
discoveryengine.notes.get
discoveryengine.notes.update
discoveryengine.podcasts.create
discoveryengine.sources.checkFreshness
discoveryengine.sources.create
discoveryengine.sources.delete
discoveryengine.sources.generateDocumentGuide
discoveryengine.sources.get
discoveryengine.sources.refresh
discoveryengine.sources.update

ディスカバリー エンジン

次の権限がディスカバリー エンジン編集者ロール(roles/discoveryengine.editor)に追加されます。

discoveryengine.accounts.create
discoveryengine.aclConfigs.update
discoveryengine.alertPolicies.create
discoveryengine.alertPolicies.update
discoveryengine.assistants.create
discoveryengine.assistants.delete
discoveryengine.assistants.update
discoveryengine.audioOverviews.create
discoveryengine.audioOverviews.delete
discoveryengine.audioOverviews.get
discoveryengine.audioOverviews.getIceConfig
discoveryengine.audioOverviews.sendSdpOffer
discoveryengine.cmekConfigs.update
discoveryengine.collections.delete
discoveryengine.completionConfigs.update
discoveryengine.controls.create
discoveryengine.controls.delete
discoveryengine.controls.update
discoveryengine.dataConnectors.startConnectorRun
discoveryengine.dataConnectors.update
discoveryengine.dataStores.create
discoveryengine.dataStores.delete
discoveryengine.dataStores.enrollSolutions
discoveryengine.dataStores.update
discoveryengine.documentProcessingConfigs.update
discoveryengine.documents.purge
discoveryengine.engines.create
discoveryengine.engines.delete
discoveryengine.engines.getIamPolicy
discoveryengine.engines.update
discoveryengine.evaluations.create
discoveryengine.licenseConfigs.create
discoveryengine.licenseConfigs.update
discoveryengine.locations.estimateDataSize
discoveryengine.locations.exchangeAuthCredentials
discoveryengine.locations.getConnectorSource
discoveryengine.locations.listConnectorSources
discoveryengine.locations.setUpDataConnector
discoveryengine.notebooks.create
discoveryengine.notebooks.generateGuide
discoveryengine.notebooks.get
discoveryengine.notebooks.getAnalytics
discoveryengine.notebooks.getIamPolicy
discoveryengine.notebooks.interactSources
discoveryengine.notebooks.list
discoveryengine.notebooks.removeSelf
discoveryengine.notebooks.update
discoveryengine.notes.create
discoveryengine.notes.delete
discoveryengine.notes.get
discoveryengine.notes.update
discoveryengine.podcasts.create
discoveryengine.projects.provision
discoveryengine.projects.reportConsentChange
discoveryengine.schemas.create
discoveryengine.schemas.delete
discoveryengine.schemas.update
discoveryengine.servingConfigs.create
discoveryengine.servingConfigs.delete
discoveryengine.servingConfigs.update
discoveryengine.siteSearchEngines.batchVerifyTargetSites
discoveryengine.siteSearchEngines.disableAdvancedSiteSearch
discoveryengine.siteSearchEngines.enableAdvancedSiteSearch
discoveryengine.siteSearchEngines.fetchDomainVerificationStatus
discoveryengine.siteSearchEngines.recrawlUris
discoveryengine.sitemaps.create
discoveryengine.sitemaps.delete
discoveryengine.sitemaps.fetch
discoveryengine.sources.checkFreshness
discoveryengine.sources.create
discoveryengine.sources.delete
discoveryengine.sources.generateDocumentGuide
discoveryengine.sources.get
discoveryengine.sources.refresh
discoveryengine.sources.update
discoveryengine.suggestionDenyListEntries.import
discoveryengine.suggestionDenyListEntries.purge
discoveryengine.targetSites.batchCreate
discoveryengine.targetSites.create
discoveryengine.targetSites.delete
discoveryengine.targetSites.update
discoveryengine.userEvents.purge
discoveryengine.userStores.batchUpdateUserLicenses
discoveryengine.userStores.listUserLicenses

ディスカバリー エンジン

次の権限が Discovery Engine 閲覧者ロール(roles/discoveryengine.viewer)に追加されます。

discoveryengine.audioOverviews.get
discoveryengine.audioOverviews.getIceConfig
discoveryengine.audioOverviews.sendSdpOffer
discoveryengine.engines.getIamPolicy
discoveryengine.licenseConfigs.get
discoveryengine.licenseConfigs.list
discoveryengine.locations.estimateDataSize
discoveryengine.locations.exchangeAuthCredentials
discoveryengine.locations.getConnectorSource
discoveryengine.locations.listConnectorSources
discoveryengine.notebooks.generateGuide
discoveryengine.notebooks.get
discoveryengine.notebooks.getAnalytics
discoveryengine.notebooks.getIamPolicy
discoveryengine.notebooks.interactSources
discoveryengine.notebooks.list
discoveryengine.notes.get
discoveryengine.sessions.search
discoveryengine.siteSearchEngines.fetchDomainVerificationStatus
discoveryengine.sitemaps.fetch
discoveryengine.sources.checkFreshness
discoveryengine.sources.generateDocumentGuide
discoveryengine.sources.get
discoveryengine.userStores.listUserLicenses

Cloud DNS

次の権限が DNS 管理者のロール(roles/dns.admin)に追加されます。

dns.managedZones.setIamPolicy

Firebase セキュリティ ルール

次の権限が Firebase ルール閲覧者ロール(roles/firebaserules.viewer)に追加されます。

firebaserules.releases.getExecutable
firebaserules.rulesets.test

GKE Hub

次の権限がフリート管理者(旧 GKE Hub 管理者)ロール(roles/gkehub.admin)に追加されます。

gkehub.endpoints.connect
gkehub.gateway.delete
gkehub.gateway.generateCredentials
gkehub.gateway.get
gkehub.gateway.patch
gkehub.gateway.post
gkehub.gateway.put
gkehub.gateway.stream

GKE Hub

次の権限がフリート編集者(旧 GKE Hub 編集者)ロール(roles/gkehub.editor)に追加されます。

gkehub.gateway.delete
gkehub.gateway.generateCredentials
gkehub.gateway.get
gkehub.gateway.patch
gkehub.gateway.post
gkehub.gateway.put
gkehub.gateway.stream

GKE Hub

次の権限がフリート閲覧者(旧 GKE Hub 閲覧者)ロール(roles/gkehub.viewer)に追加されます。

gkehub.gateway.generateCredentials
gkehub.gateway.get
gkehub.scopes.getIamPolicy

Identity-Aware Proxy

次の権限が IAP ポリシー管理者ロール(roles/iap.admin)に追加されます。

iap.projects.getSettings
iap.projects.updateSettings
iap.tunnelDestGroups.accessViaIAP
iap.tunnelDestGroups.create
iap.tunnelDestGroups.delete
iap.tunnelDestGroups.get
iap.tunnelDestGroups.list
iap.tunnelDestGroups.remediate
iap.tunnelDestGroups.update
iap.tunnelInstances.accessViaIAP
iap.tunnelinstances.remediate
iap.web.getSettings
iap.web.updateSettings
iap.webServiceVersions.getSettings
iap.webServiceVersions.remediate
iap.webServiceVersions.updateSettings
iap.webServices.getSettings
iap.webServices.updateSettings
iap.webTypes.getSettings
iap.webTypes.updateSettings

Cloud License Manager

次の権限が Cloud License Manager 閲覧者ロール(roles/licensemanager.viewer)に追加されます。

licensemanager.configurations.aggregateUsage
licensemanager.configurations.queryLicenseUsage

Cloud Logging

次の権限がログ閲覧者ロール(roles/logging.viewer)に追加されます。

logging.buckets.copyLogEntries
logging.buckets.listEffectiveTags
logging.buckets.listTagBindings
logging.logEntries.download
logging.notificationRules.get
logging.notificationRules.list
logging.settings.get
logging.views.getIamPolicy
logging.views.listLogs
logging.views.listResourceKeys
logging.views.listResourceValues

Managed Service for Microsoft Active Directory

次の権限が Google Cloud Managed Identities 閲覧者ロール(roles/managedidentities.viewer)に追加されます。

managedidentities.domains.checkMigrationPermission
managedidentities.domains.validateTrust

Memorystore for Memcached

次の権限が Cloud Memorystore Memcached 編集者ロール(roles/memcache.editor)に追加されます。

memcache.instances.applySoftwareUpdate
memcache.instances.create
memcache.instances.delete
memcache.instances.rescheduleMaintenance
memcache.instances.upgrade

Memorystore for Memcached

次の権限が Cloud Memorystore Memcached 閲覧者ロール(roles/memcache.viewer)に追加されます。

memcache.instances.listEffectiveTags
memcache.instances.listTagBindings

Dataproc Metastore

次の権限が Dataproc Metastore 管理者ロール(roles/metastore.admin)に追加されます。

metastore.databases.create
metastore.databases.delete
metastore.databases.get
metastore.databases.getIamPolicy
metastore.databases.list
metastore.databases.setIamPolicy
metastore.databases.update
metastore.services.mutateMetadata
metastore.services.queryMetadata
metastore.services.use
metastore.tables.create
metastore.tables.delete
metastore.tables.get
metastore.tables.getIamPolicy
metastore.tables.list
metastore.tables.setIamPolicy
metastore.tables.update

Dataproc Metastore

次の権限が Dataproc Metastore 編集者ロール(roles/metastore.editor)に追加されます。

metastore.backups.getIamPolicy
metastore.databases.create
metastore.databases.delete
metastore.databases.get
metastore.databases.getIamPolicy
metastore.databases.list
metastore.databases.update
metastore.federations.getIamPolicy
metastore.federations.use
metastore.services.use
metastore.tables.create
metastore.tables.delete
metastore.tables.get
metastore.tables.getIamPolicy
metastore.tables.list
metastore.tables.update

AI Platform

次の権限が AI Platform 閲覧者ロール(roles/ml.viewer)に追加されます。

ml.jobs.getIamPolicy
ml.models.getIamPolicy
ml.models.predict
ml.versions.predict

Model Armor

次の権限が Model Armor 管理者ロール(roles/modelarmor.admin)に追加されます。

modelarmor.callouts.invoke
modelarmor.floorSettings.get
modelarmor.floorSettings.update

Model Armor

次の権限が Model Armor 閲覧者のロール(roles/modelarmor.viewer)に追加されます。

modelarmor.floorSettings.get

Oracle Database@Google Cloud

次の権限が Oracle Database@Google Cloud 閲覧者ロール(roles/oracledatabase.viewer)に追加されます。

oracledatabase.dbSystemInitialStorageSizes.list
oracledatabase.dbVersions.list
oracledatabase.systemVersions.list

Pub/Sub

次の権限が Pub/Sub 編集者ロール(roles/pubsub.editor)に追加されます。

pubsub.schemas.getIamPolicy

Pub/Sub

次の権限が Pub/Sub 閲覧者ロール(roles/pubsub.viewer)に追加されます。

pubsub.schemas.attach
pubsub.schemas.getIamPolicy
pubsub.snapshots.seek

Pub/Sub Lite

次の権限が Pub/Sub Lite 閲覧者ロール(roles/pubsublite.viewer)に追加されます。

pubsublite.locations.openKafkaStream
pubsublite.subscriptions.subscribe
pubsublite.topics.computeHeadCursor
pubsublite.topics.computeMessageStats
pubsublite.topics.computeTimeCursor
pubsublite.topics.subscribe

reCAPTCHA

次の権限が reCAPTCHA Enterprise 管理者ロール(roles/recaptchaenterprise.admin)に追加されます。

recaptchaenterprise.assessments.annotate
recaptchaenterprise.assessments.create
recaptchaenterprise.relatedaccountgroupmemberships.list
recaptchaenterprise.relatedaccountgroups.list

reCAPTCHA

次の権限が reCAPTCHA Enterprise 閲覧者ロール(roles/recaptchaenterprise.viewer)に追加されます。

recaptchaenterprise.relatedaccountgroupmemberships.list
recaptchaenterprise.relatedaccountgroups.list

Recommender

次の権限が Recommender 閲覧者ロール(roles/recommender.viewer)に追加されます。

recommender.costRecommendations.listAll
recommender.costRecommendations.summarizeAll

Memorystore for Redis

次の権限が Cloud Memorystore Redis 編集者のロール(roles/redis.editor)に追加されます。

redis.backupCollections.create
redis.backupCollections.delete
redis.backups.create
redis.backups.delete
redis.backups.export
redis.clusters.connect
redis.clusters.create
redis.clusters.delete
redis.clusters.rescheduleMaintenance
redis.instances.create
redis.instances.delete
redis.instances.export
redis.instances.getAuthString
redis.instances.import
redis.instances.listEffectiveTags
redis.instances.listTagBindings
redis.instances.rescheduleMaintenance
redis.instances.updateAuth
redis.instances.upgrade

Memorystore for Redis

次の権限が Cloud Memorystore Redis 閲覧者ロール(roles/redis.viewer)に追加されます。

redis.backups.export

Retail API

次の権限が小売業編集者のロール(roles/retail.editor)に追加されます。

retail.attributesConfigs.batchRemoveCatalogAttributes
retail.attributesConfigs.removeCatalogAttribute
retail.products.purge
retail.products.setSponsorship
retail.userEvents.purge
retail.userEvents.rejoin

Retail API

次の権限が Retail 閲覧者ロール(roles/retail.viewer)に追加されます。

retail.merchantControls.creatorGet
retail.merchantControls.creatorList
retail.models.pause
retail.models.resume
retail.models.tune

ルートの最適化

次の権限がルート最適化閲覧者のロール(roles/routeoptimization.viewer)に追加されます。

routeoptimization.locations.use

Security Center Management API

次の権限がセキュリティ センター管理閲覧者ロール(roles/securitycentermanagement.viewer)に追加されます。

securitycentermanagement.securityCommandCenter.checkEligibility

Security Posture API

次の権限がセキュリティ対策閲覧者のロール(roles/securityposture.viewer)に追加されます。

securityposture.locations.get
securityposture.locations.list
securityposture.operations.list
securityposture.reports.get
securityposture.reports.list

Spanner

次の権限が Cloud Spanner 閲覧者ロール(roles/spanner.viewer)に追加されます。

spanner.backupOperations.get
spanner.backupOperations.list
spanner.backupSchedules.get
spanner.backupSchedules.getIamPolicy
spanner.backupSchedules.list
spanner.backups.get
spanner.backups.getIamPolicy
spanner.backups.list
spanner.databaseOperations.get
spanner.databaseOperations.list
spanner.databaseRoles.list
spanner.databases.beginReadOnlyTransaction
spanner.databases.getDdl
spanner.databases.getIamPolicy
spanner.databases.partitionQuery
spanner.databases.partitionRead
spanner.databases.read
spanner.databases.select
spanner.databases.useDataBoost
spanner.instanceConfigOperations.get
spanner.instanceConfigOperations.list
spanner.instanceOperations.get
spanner.instanceOperations.list
spanner.instancePartitionOperations.get
spanner.instancePartitionOperations.list
spanner.instances.getIamPolicy
spanner.sessions.create
spanner.sessions.delete
spanner.sessions.get
spanner.sessions.list

Speaker ID

次の権限が話者 ID 編集者ロール(roles/speakerid.editor)に追加されます。

speakerid.settings.get

Speaker ID

次の権限が Speaker ID 閲覧者のロール(roles/speakerid.viewer)に追加されます。

speakerid.settings.get

Speech-to-Text

次の権限が Cloud Speech 編集者のロール(roles/speech.editor)に追加されます。

speech.config.get

Cloud Storage

次の権限がストレージ管理者ロール(roles/storage.admin)に追加されます。

storage.hmacKeys.create
storage.hmacKeys.delete
storage.hmacKeys.get
storage.hmacKeys.list
storage.hmacKeys.update

Visual Inspection AI

次の権限が Visual Inspection AI ソリューション編集者ロール(roles/visualinspection.editor)に追加されます。

visualinspection.locations.reportUsageMetrics

サーバーレス VPC アクセス

次の権限がサーバーレス VPC アクセス閲覧者ロール(roles/vpcaccess.viewer)に追加されます。

vpcaccess.connectors.use