Rôles et autorisations Artifact Guard

Artifact Guard utilise des rôles et des autorisations IAM (Identity and Access Management) pour gérer l'accès aux ressources. Vous pouvez attribuer des rôles IAM aux utilisateurs, aux groupes ou aux comptes de service. Pour plus d'informations sur l'attribution de rôles, consultez la page Gérer l'accès aux projets, aux dossiers et aux organisations.

Rôles Artifact Guard

Les rôles IAM suivants sont disponibles pour Artifact Guard.

Rôle Autorisations
Administrateur Artifact Scan Guard
(roles/artifactscanguard.admin)

Accès complet aux ressources Artifact Guard. Créez des règles, évaluez-les et visualisez leurs performances.
artifactscanguard.artifactEvaluations.create
artifactscanguard.artifactEvaluations.get
artifactscanguard.artifactPoliciesEvaluations.create
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.connectors.create
artifactscanguard.connectors.delete
artifactscanguard.connectors.get
artifactscanguard.connectors.list
artifactscanguard.connectors.update
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.delete
artifactscanguard.operations.get
artifactscanguard.operations.list
artifactscanguard.policies.create
artifactscanguard.policies.delete
artifactscanguard.policies.get
artifactscanguard.policies.list
artifactscanguard.policies.update
artifactscanguard.reports.listConnectorEvaluations
artifactscanguard.reports.listPolicyEvaluationSummaries
monitoring.timeSeries.create
orgpolicy.policy.get
resourcemanager.organizations.get
resourcemanager.projects.get
resourcemanager.projects.list
storage.folders.create
storage.folders.delete
storage.folders.get
storage.folders.list
{10ancers.rename
storage.managedFolders.create
storage.managedFolders.delete
storage.managedFolders.get
storage.managedFolders.list
storage.multipartUploads.abort
storage.multipartUploads.create
storage.multipartUploads.list
storage.multipartUploads.listParts
storage.objects.create
storage.objects.createContext
storage.objects.delete
storage.objects.deleteContext
storage.objects.get
storage.objects.list
storage.objects.move
storage.objects.restore
storage.objects.update
storage.objects.updateContext
Administrateur d'évaluation Artifact Scan Guard
(roles/artifactscanguard.policyEvaluator)

Accès complet aux ressources d'évaluation des artefacts.
artifactscanguard.artifactEvaluations.create
artifactscanguard.artifactEvaluations.get
artifactscanguard.artifactPoliciesEvaluations.create
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
monitoring.timeSeries.create
orgpolicy.policy.get
resourcemanager.organizations.get
resourcemanager.projects.get
resourcemanager.projects.list
storage.folders.create
storage.folders.delete
storage.folders.get
storage.folders.list
storage.folders.rename
storage.managedFolders.create
storage.managedFolders.delete
storage.managedFolders.get
storage.managedFolders.list
storage.multipartUploads.abort
storage.multipartUploads.create
storage.multipartUploads.list
storage.multipartUploads.listParts
storage.objects.create
storage.objects.createContext
storage.objects.delete
storage.objects.deleteContext
storage.objects.get
storage.objects.list
storage.objects.move
storage.objects.restore
storage.objects.update
storage.objects.updateContext
Administrateur de connecteur Artifact Scan Guard
(roles/artifactscanguard.connectorAdmin)

Accès complet aux ressources de connecteur.
artifactscanguard.connectors.create
artifactscanguard.connectors.delete
artifactscanguard.connectors.get
artifactscanguard.connectors.list
artifactscanguard.connectors.update
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
resourcemanager.organizations.get
resourcemanager.projects.get
Administrateur des règles Artifact Scan Guard
(roles/artifactscanguard.policyAdmin)

Accès complet aux ressources de règles. Créez des règles et visualisez leurs performances
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.policies.create
artifactscanguard.policies.delete
artifactscanguard.policies.get
artifactscanguard.policies.list
artifactscanguard.policies.update
resourcemanager.organizations.get
resourcemanager.projects.get
Administrateur d'évaluation des règles Artifact Scan Guard
(roles/artifactscanguard.policyEvaluationAdmin)

Accès complet aux ressources d'évaluation des règles.
artifactscanguard.artifactPoliciesEvaluations.create
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
monitoring.timeSeries.create
orgpolicy.policy.get
resourcemanager.organizations.get
resourcemanager.projects.get
resourcemanager.projects.list
storage.folders.create
storage.folders.delete
storage.folders.get
storage.folders.list
storage.folders.rename
storage.managedFolders.create
storage.managedFolders.delete
storage.managedFolders.get
storage.managedFolders.list
storage.multipartUploads.abort
storage.multipartUploads.create
storage.multipartUploads.list
storage.multipartUploads.listParts
storage.objects.create
storage.objects.createContext
storage.objects.delete
storage.objects.deleteContext
storage.objects.get
storage.objects.list
storage.objects.move
storage.objects.restore
storage.objects.update
storage.objects.updateContext
Administrateur de rapports Artifact Scan Guard
(roles/artifactscanguard.reportAdmin)

Accès complet aux ressources de rapports.
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.reports.listConnectorEvaluations
artifactscanguard.reports.listPolicyEvaluationSummaries
resourcemanager.organizations.get
resourcemanager.projects.get
Lecteur Artifact Scan Guard
(roles/artifactscanguard.viewer)

Accès en lecture seule aux ressources Artifact Guard.
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.connectors.get
artifactscanguard.connectors.list
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.policies.get
artifactscanguard.policies.list
artifactscanguard.reports.listConnectorEvaluations
artifactscanguard.reports.listPolicyEvaluationSummaries
resourcemanager.organizations.get
resourcemanager.projects.get
Lecteur de connecteur Artifact Scan Guard
(roles/artifactscanguard.connectorViewer)

Accès en lecture seule aux ressources de connecteur.
artifactscanguard.connectors.get
artifactscanguard.connectors.list
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
resourcemanager.organizations.get
resourcemanager.projects.get
Lecteur de règles Artifact Scan Guard
(roles/artifactscanguard.policyViewer)

Accès en lecture seule aux ressources de règles.
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.policies.get
artifactscanguard.policies.list
resourcemanager.organizations.get
resourcemanager.projects.get
Lecteur d'évaluation des règles Artifact Scan Guard
(roles/artifactscanguard.policyEvaluationViewer)

Accès en lecture seule aux ressources d'évaluation des règles.
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
resourcemanager.organizations.get
resourcemanager.projects.get
Lecteur de rapports Artifact Scan Guard
(roles/artifactscanguard.reportViewer)

Accès en lecture seule aux ressources de rapports.
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.reports.listConnectorEvaluations
artifactscanguard.reports.listPolicyEvaluationSummaries
resourcemanager.organizations.get
resourcemanager.projects.get