Cloud Infrastructure Entitlement Management (CIEM) roles and permissions
Stay organized with collections
Save and categorize content based on your preferences.
This page lists the IAM roles and permissions for Cloud Infrastructure Entitlement Management (CIEM). To
search through all roles and permissions, see the role and
permission index.
Cloud Infrastructure Entitlement Management (CIEM) offers the following service agent roles.
Service agent roles should only be granted to service agents.
Role
Permissions
CIEM Service Agent
(roles/ciem.serviceAgent)
Gives CIEM Service Account permission to access GCP resources
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-04-10 UTC."],[],[]]