This page lists the IAM roles and permissions for Organization Policy Service. To search through all roles and permissions, see the role and permission index.
Organization Policy Service roles
| Role | Permissions | 
|---|---|
| Organization Policy Administrator( Provides access to define what restrictions an organization wants to place on the configuration of cloud resources by setting Organization Policies. Lowest-level resources where you can grant this role: 
 | 
 
 
 
 
       
 
 
       
 
       
 
       
 | 
| Organization Policy Viewer( Provides access to view Organization Policies on resources. Lowest-level resources where you can grant this role: 
 | 
 
 
 
 
 | 
Organization Policy Service permissions
| Permission | Included in roles | 
|---|---|
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Organization Policy Administrator ( 
          Organization Policy Viewer ( 
          Folder Admin ( 
          Folder Creator ( 
          Folder Editor ( 
          Folder Viewer ( 
          Organization Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( Service agent roles 
 | 
| 
 | 
          Organization Policy Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( | 
| 
 | 
          Organization Policy Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Auditor ( 
          Support User ( 
          Organization Policy Administrator ( 
          Organization Policy Viewer ( 
          OrgPolicy Simulator Admin ( 
          Security Posture Admin ( 
          Security Posture Deployer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Organization Policy Administrator ( 
          Organization Policy Viewer ( 
          OrgPolicy Simulator Admin ( 
          Security Posture Admin ( 
          Security Posture Deployer ( | 
| 
 | 
          Organization Policy Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( | 
| 
 | 
          Assured Workloads Administrator ( 
          Assured Workloads Editor ( 
          Organization Policy Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( | 
| 
 | 
          Assured Workloads Administrator ( 
          Assured Workloads Editor ( 
          Organization Policy Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Assured Workloads Administrator ( 
          Assured Workloads Editor ( 
          Assured Workloads Reader ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Organization Policy Administrator ( 
          Organization Policy Viewer ( 
          OrgPolicy Simulator Admin ( 
          Folder Admin ( 
          Folder Creator ( 
          Folder Editor ( 
          Folder Viewer ( 
          Organization Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( Service agent roles 
 | 
| 
 | 
          Assured Workloads Administrator ( 
          Assured Workloads Editor ( 
          Organization Policy Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Assured Workloads Administrator ( 
          Assured Workloads Editor ( 
          Assured Workloads Reader ( 
          Environment and Storage Object Administrator ( 
          Composer Worker ( 
          Consumer Procurement Entitlement Manager ( 
          Consumer Procurement Entitlement Viewer ( 
          Consumer Procurement Administrator ( 
          Consumer Procurement Viewer ( 
          Application Design Center Admin ( 
          Application Design Center User ( 
          Firebase Admin ( 
          Firebase Develop Admin ( 
          Firebase Admin SDK Administrator Service Agent ( 
          Firebase App Hosting Compute Runner ( 
          Data Scientist ( 
          Databases Admin ( 
          Dev Ops ( 
          Infrastructure Administrator ( 
          ML Engineer ( 
          Security Auditor ( 
          Support User ( 
          Organization Policy Administrator ( 
          Organization Policy Viewer ( 
          OrgPolicy Simulator Admin ( 
          Folder Admin ( 
          Folder Creator ( 
          Folder Editor ( 
          Folder Viewer ( 
          Organization Administrator ( 
          Cloud Run Source Developer ( 
          Security Posture Admin ( 
          Security Posture Deployer ( 
          API Keys Admin ( 
          Storage Admin ( 
          Storage Express Mode User Access ( 
          Storage Folder Admin ( 
          Storage HMAC Key Admin ( 
          Storage Object Admin ( 
          Storage Object Creator ( 
          Storage Object User ( 
          Workload Manager Admin ( 
          Workload Manager Evaluation Admin ( 
          Workload Manager Evaluation Viewer ( 
          Workload Manager Viewer ( 
          Workload Manager Worker ( Service agent roles 
 | 
| 
 | 
          Assured Workloads Administrator ( 
          Assured Workloads Editor ( 
          Organization Policy Administrator ( 
          Security Posture Admin ( 
          Security Posture Deployer ( |