Cloud Controls Partner API roles and permissions

This page lists the IAM roles and permissions for Cloud Controls Partner API. To search through all roles and permissions, see the role and permission index.

Cloud Controls Partner API roles

Role Permissions

(roles/cloudcontrolspartner.admin)

Full access to Cloud Controls Partner resources.

cloudcontrolspartner.accessapprovalrequests.list

cloudcontrolspartner.customers.*

  • cloudcontrolspartner.customers.create
  • cloudcontrolspartner.customers.delete
  • cloudcontrolspartner.customers.get
  • cloudcontrolspartner.customers.list

cloudcontrolspartner.ekmconnections.get

cloudcontrolspartner.inspectabilityevents.get

cloudcontrolspartner.partnerpermissions.get

cloudcontrolspartner.partners.get

cloudcontrolspartner.platformcontrols.get

cloudcontrolspartner.violations.list

cloudcontrolspartner.workloads.list

(roles/cloudcontrolspartner.editor)

Editor access to Cloud Controls Partner resources.

cloudcontrolspartner.*

  • cloudcontrolspartner.accessapprovalrequests.list
  • cloudcontrolspartner.customers.create
  • cloudcontrolspartner.customers.delete
  • cloudcontrolspartner.customers.get
  • cloudcontrolspartner.customers.list
  • cloudcontrolspartner.ekmconnections.get
  • cloudcontrolspartner.inspectabilityevents.get
  • cloudcontrolspartner.partnerpermissions.get
  • cloudcontrolspartner.partners.get
  • cloudcontrolspartner.platformcontrols.get
  • cloudcontrolspartner.violations.get
  • cloudcontrolspartner.violations.list
  • cloudcontrolspartner.workloads.get
  • cloudcontrolspartner.workloads.list

(roles/cloudcontrolspartner.viewer)

Viewer role for cloudcontrolspartner

cloudcontrolspartner.accessapprovalrequests.list

cloudcontrolspartner.customers.get

cloudcontrolspartner.customers.list

cloudcontrolspartner.ekmconnections.get

cloudcontrolspartner.inspectabilityevents.get

cloudcontrolspartner.partnerpermissions.get

cloudcontrolspartner.partners.get

cloudcontrolspartner.platformcontrols.get

cloudcontrolspartner.violations.*

  • cloudcontrolspartner.violations.get
  • cloudcontrolspartner.violations.list

cloudcontrolspartner.workloads.*

  • cloudcontrolspartner.workloads.get
  • cloudcontrolspartner.workloads.list

resourcemanager.projects.get

resourcemanager.projects.list

(roles/cloudcontrolspartner.inspectabilityReader)

Readonly access to Cloud Controls Partner inspectability resources.

cloudcontrolspartner.customers.get

cloudcontrolspartner.customers.list

cloudcontrolspartner.inspectabilityevents.get

cloudcontrolspartner.platformcontrols.get

(roles/cloudcontrolspartner.monitoringReader)

Read-only access to Cloud Controls Partner monitoring resources.

cloudcontrolspartner.customers.get

cloudcontrolspartner.customers.list

cloudcontrolspartner.violations.*

  • cloudcontrolspartner.violations.get
  • cloudcontrolspartner.violations.list

cloudcontrolspartner.workloads.*

  • cloudcontrolspartner.workloads.get
  • cloudcontrolspartner.workloads.list

(roles/cloudcontrolspartner.reader)

Read-only access to Cloud Controls Partner resources.

cloudcontrolspartner.accessapprovalrequests.list

cloudcontrolspartner.customers.get

cloudcontrolspartner.customers.list

cloudcontrolspartner.ekmconnections.get

cloudcontrolspartner.inspectabilityevents.get

cloudcontrolspartner.partnerpermissions.get

cloudcontrolspartner.partners.get

cloudcontrolspartner.platformcontrols.get

cloudcontrolspartner.violations.*

  • cloudcontrolspartner.violations.get
  • cloudcontrolspartner.violations.list

cloudcontrolspartner.workloads.*

  • cloudcontrolspartner.workloads.get
  • cloudcontrolspartner.workloads.list

Service agent roles

Service agent roles should only be granted to service agents.

Role Permissions

(roles/cloudcontrolspartner.accessApprovalServiceAgent)

Gives the Partner Console service account access to read Access Approval Requests for workloads associated with a partner.

accessapproval.requests.get

accessapproval.requests.list

(roles/cloudcontrolspartner.ekmServiceAgent)

Gives Cloud Controls Partner service agent permission to list EKM connections, get EKM connection status, and provide EKM diagnostic information.

cloudkms.ekmConnections.get

cloudkms.ekmConnections.getIamPolicy

cloudkms.ekmConnections.list

cloudkms.ekmConnections.verifyConnectivity

(roles/cloudcontrolspartner.monitoringServiceAgent)

Gives Cloud Controls Partner monitoring service agent permission to view and list Assured Workload violations. The role is assigned to enable partner monitoring capability.

assuredworkloads.violations.get

assuredworkloads.violations.list

(roles/cloudcontrolspartner.supportCaseServiceAgent)

Gives the Partner Console service account access to support cases for workloads associated with a partner.

cloudsupport.techCases.get

Cloud Controls Partner API permissions

Permission Included in roles

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Security Auditor (roles/iam.securityAuditor)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Owner (roles/owner)

Editor (roles/editor)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Cloud Controls Partner Inspectability Reader (roles/cloudcontrolspartner.inspectabilityReader)

Cloud Controls Partner Monitoring Reader (roles/cloudcontrolspartner.monitoringReader)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Cloud Controls Partner Inspectability Reader (roles/cloudcontrolspartner.inspectabilityReader)

Cloud Controls Partner Monitoring Reader (roles/cloudcontrolspartner.monitoringReader)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Security Auditor (roles/iam.securityAuditor)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Cloud Controls Partner Inspectability Reader (roles/cloudcontrolspartner.inspectabilityReader)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Cloud Controls Partner Inspectability Reader (roles/cloudcontrolspartner.inspectabilityReader)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Cloud Controls Partner Monitoring Reader (roles/cloudcontrolspartner.monitoringReader)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Cloud Controls Partner Monitoring Reader (roles/cloudcontrolspartner.monitoringReader)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Security Auditor (roles/iam.securityAuditor)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Cloud Controls Partner Monitoring Reader (roles/cloudcontrolspartner.monitoringReader)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Support User (roles/iam.supportUser)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud Controls Partner Admin (roles/cloudcontrolspartner.admin)

Cloud Controls Partner Editor (roles/cloudcontrolspartner.editor)

Cloudcontrolspartner Viewer (roles/cloudcontrolspartner.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Cloud Controls Partner Monitoring Reader (roles/cloudcontrolspartner.monitoringReader)

Cloud Controls Partner Reader (roles/cloudcontrolspartner.reader)

Security Auditor (roles/iam.securityAuditor)

Support User (roles/iam.supportUser)