The Advisory Notifications service uses Security and Privacy Advisory notifications to inform you of critical security and privacy events.
Who receives Security and Privacy Advisory notifications
Advisory Notifications contacts different users depending on whether the notification is sent to an organization or project.
Organization contacts
Advisory Notifications integrates with Essential Contacts to identify which users should receive notifications. Essential Contacts lets you control who receives notifications by providing a list of contacts. Security and privacy advisory notifications are sent to contacts in the Security and All categories at the organization level. For more information, see Managing contacts for notifications.
If Essential Contacts hasn't been configured, Advisory Notifications sends notifications to the default contacts, which are determined by Identity and Access Management roles.
If one or more users have been granted the Organization Administrator role (roles/resourcemanager.organizationAdmin
) on the organization,
only they are contacted. If no users have been granted the Organization
Administrator role, then Advisory Notifications moves on to the
next role in the hierarchy and determines if one or more users have been granted
the Owner basic role (roles/owner
) on any project owned by the organization. If
any are found, only they are contacted. Finally, if no users have been granted
the Organization Administrator or Project Owner role,
Advisory Notifications contacts any users who have been granted
the Billing Account Administrator role (roles/billing.admin
) on any billing account owned by the
organization.
Project contacts
When a notification is sent to a project, Advisory Notifications contacts Identity and Access Management roles in the following order. If one or more users have been granted
the Owner basic role (roles/owner
) on the project, only they are contacted. Otherwise, if no users have been granted
the Project Owner role,
Advisory Notifications contacts any users who have been granted
the Billing Account Administrator role (roles/billing.admin
) on the billing account associated with the
project, if it exists.
Opting out
Security and Privacy Advisory notifications are mandatory. You cannot opt out of receiving these notifications.
What's next
- Learn about Sensitive Actions notifications.
- Learn how to view notifications.