Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Meninjau dan menyetujui permintaan akses menggunakan kunci penandatanganan yang dikelola Google
Dokumen ini menunjukkan cara menyiapkan Persetujuan Akses menggunakan konsolGoogle Cloud untuk menerima notifikasi email tentang permintaan akses untuk sebuah project.
Persetujuan Akses memastikan bahwa persetujuan yang ditandatangani secara kriptografis
ada agar personel Google dapat mengakses konten Anda yang disimpan di
Google Cloud.
Pada dialog, pilih mode pendaftaran untuk kebijakan Anda, lalu klik Daftarkan.
Mode pendaftaran utama Access Approval
Anda dapat mengonfigurasi Persetujuan Akses dalam salah satu dari tiga mode, dan dapat mengubah mode kapan saja di setelan Persetujuan Akses. Mode berikut dapat dipilih:
Transparansi (Direkomendasikan): Gunakan mode ini untuk mencatat akses administratif Google ke workload Anda saja tanpa mengganggu dukungan Google untuk kasus dukungan atau pemeliharaan proaktif pada workload Anda. Lihat dokumen Transparansi Akses untuk informasi selengkapnya.
Dukungan yang disederhanakan (Pratinjau): Gunakan mode ini untuk menyetujui akses Layanan Pelanggan secara otomatis untuk menangani kasus dukungan Anda. Akses pemeliharaan dan perbaikan proaktif akan diminta untuk disetujui dengan Persetujuan Akses. Fitur ini berada dalam tahap peluncuran Pratinjau.
Persetujuan Akses: Gunakan mode ini untuk mengaktifkan fungsi Persetujuan Akses penuh untuk semua akses.
Log Transparansi Akses dibuat secara otomatis untuk semua mode Persetujuan Akses.
Mengonfigurasi setelan
Di halaman Persetujuan Akses di konsol Google Cloud , klik
settingsKelola setelan.
Pilih layanan
Setelan Access Approval, termasuk daftar produk yang diaktifkan, diwarisi dari resource induk. Anda dapat memperluas cakupan pendaftaran dengan mengaktifkan Persetujuan Akses untuk semua atau layanan tambahan tertentu yang didukung.
Menyiapkan notifikasi email dan Pub/Sub
Bagian ini menjelaskan cara Anda dapat menerima notifikasi permintaan akses untuk project ini.
Memberikan peran IAM yang diperlukan kepada diri Anda sendiri
Untuk melihat dan menyetujui permintaan akses, Anda harus memiliki peran IAM Access Approval Approver (roles/accessapproval.approver).
Untuk memberikan peran IAM ini kepada diri Anda sendiri, lakukan hal berikut:
Untuk mengaktifkan notifikasi email, tambahkan alamat email Anda di kolom
Email pengguna atau grup di bagian Siapkan notifikasi persetujuan.
Untuk mengaktifkan notifikasi Pub/Sub, tambahkan topik Pub/Sub Anda di kolom
Topik Pub/Sub di bagian Siapkan notifikasi persetujuan.
Pilih kunci penandatanganan yang dikelola Google
Persetujuan Akses menggunakan kunci penandatanganan untuk memverifikasi integritas permintaan Persetujuan Akses.
Kunci penandatanganan yang dikelola Google adalah opsi default. Penggunaan
Google-owned and managed key tidak memerlukan konfigurasi
tambahan.
Meninjau permintaan Persetujuan Akses
Setelah mendaftar ke Persetujuan Akses dan menambahkan diri Anda sebagai pemberi persetujuan untuk permintaan akses, Anda akan menerima notifikasi email untuk permintaan akses.
Gambar berikut menunjukkan contoh notifikasi email yang dikirim Persetujuan Akses saat personel Google meminta akses ke Data Pelanggan.
Untuk meninjau dan menyetujui permintaan akses masuk, lakukan hal berikut:
Buka halaman Persetujuan Akses di konsol Google Cloud .
Untuk membuka halaman ini, Anda juga dapat mengklik link di email yang dikirimkan kepada Anda berisi permintaan persetujuan.
Klik Approve.
Setelah Anda menyetujui permintaan tersebut, personel Google dengan
karakteristik yang sesuai dengan persetujuan, seperti
pembenaran, lokasi, atau lokasi meja yang sama, dapat mengakses resource yang ditentukan dan
resource turunannya dalam jangka waktu yang disetujui.
Pembersihan
Untuk membatalkan pendaftaran dari Access Approval, lakukan hal berikut:
Di halaman Persetujuan Akses di konsol Google Cloud , klik Kelola setelan.
Klik Batalkan pendaftaran.
Pada dialog yang terbuka, klik Batalkan pendaftaran.
Untuk menonaktifkan Transparansi Akses bagi organisasi Anda, hubungi Cloud Customer Care.
Tidak ada langkah tambahan yang diperlukan untuk menghindari pengenaan biaya ke akun Anda.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-18 UTC."],[[["\u003cp\u003eAccess Approval allows for cryptographically-signed approvals for Google personnel to access content stored on Google Cloud.\u003c/p\u003e\n"],["\u003cp\u003eTo utilize Access Approval, you must first enable Access Transparency and have the \u003ccode\u003eroles/accessapproval.configEditor\u003c/code\u003e IAM role.\u003c/p\u003e\n"],["\u003cp\u003eYou can enroll in Access Approval through the Google Cloud console, enabling it for selected or all supported services.\u003c/p\u003e\n"],["\u003cp\u003eConfiguring settings involves selecting services, setting up email and Pub/Sub notifications, and using the Google-managed signing key for access request verification.\u003c/p\u003e\n"],["\u003cp\u003eReview and approve access requests by visiting the Access Approval page in the Google Cloud console, or by clicking on the provided link in the email notification.\u003c/p\u003e\n"]]],[],null,["# Review access requests using the default signing key\n\nReview and approve access requests using the Google-managed signing key\n=======================================================================\n\nThis document shows you how to set up Access Approval using the\nGoogle Cloud console to receive email notifications of access requests for a project.\n\nAccess Approval ensures that a cryptographically-signed approval\nis present for Google personnel to access your content stored on\nGoogle Cloud.\n\nBefore you begin\n----------------\n\n- Enable [Access Transparency](/assured-workloads/access-transparency/docs/overview) for your organization. For more information, see [Enabling Access Transparency](/assured-workloads/access-transparency/docs/enable).\n- Ensure that you have the [Access Approval Config Editor](/iam/docs/understanding-roles#access-approval-roles) (`roles/accessapproval.configEditor`) IAM role.\n\nEnroll in Access Approval\n-------------------------\n\nTo enroll in Access Approval, do the following:\n\n1. In the Google Cloud console, select the project for which you want to\n enable Access Approval.\n\n [Go to project selector](https://console.cloud.google.com/projectselector2/home/dashboard)\n2. Go to the **Access Approval** page.\n\n [Go to Access Approval](https://console.cloud.google.com/security/access-approval)\n3. To enroll in Access Approval, click **Enroll**.\n\n4. In the dialog, select the [enrollment mode](#enrollment-mode) for your policy and click **Enroll**.\n\n### Access Approval primary enrollment mode\n\nYou can configure Access Approval in one of three modes, and can change\nthe mode at any time in the Access Approval settings. The following\nmodes can be selected:\n\n1. Transparency (Recommended): Use this mode to only log Google administrative access into your workloads without interrupting Google's support for your support cases or proactive maintenance on your workloads. See the [Access Transparency docs](/assured-workloads/access-transparency/docs) for more information.\n2. Streamlined support (Preview): Use this mode to automatically approve Customer Care access to work on your support cases. Proactive maintenance and repair access will be requested for approval with Access Approval. This feature is in the Preview launch stage.\n3. Access Approval: Use this mode to enable full Access Approval functionality for all accesses.\n\nAccess Transparency logs are generated automatically for all Access Approval modes.\n\nConfigure settings\n------------------\n\nOn the **Access Approval** page in the Google Cloud console, click\nsettings**Manage settings**.\n\n\n### Select services\n\nAccess Approval settings, including the list of enabled products, are inherited from the parent resource. You can expand the scope of enrollment by enabling Access Approval for all or selected additional services [supported services](/assured-workloads/access-approval/docs/supported-services).\n\n### Set up email and Pub/Sub notifications\n\nThis section explains how you can receive access request notifications for this\nproject.\n\n#### Grant yourself the required IAM role\n\n\nTo view and approve access requests, you must have the Access Approval Approver\n(`roles/accessapproval.approver`) IAM role.\n\n\nTo grant this IAM role to yourself, do the following:\n\n1. Go to the **IAM** page in the Google Cloud console.\n\n\n [Go to IAM](https://console.cloud.google.com/iam-admin/iam?supportedpurview=project)\n2. In the **View by principals** tab, click person_add**Grant access**.\n3. In the **New principals** field in the right pane, enter your email address.\n4. Click the **Select a role** field, and select the **Access Approval Approver** role from the menu.\n5. Click **Save**.\n\n#### Add yourself as an approver for Access Approval requests and configure notifications\n\nTo add yourself as an approver so you can review and approve access requests, do\nthe following:\n\n1. Go to the **Access Approval** page in the Google Cloud console.\n\n [Go to Access Approval](https://console.cloud.google.com/security/access-approval)\n2. Click settings**Manage settings**.\n\n3. To enable email notifications, add your email address in the\n **User or group email** field under **Set up approval notifications**.\n\n4. To enable Pub/Sub notifications, add your Pub/Sub topic in the\n **Pub/Sub topic** field under **Set up approval notifications**.\n\n### Select a Google-managed signing key\n\nAccess Approval uses a signing key to verify the integrity of the\nAccess Approval request.\n\nGoogle-managed signing key is the default option. Using a\nGoogle-owned and managed key doesn't require any additional\nconfiguration.\n\nReview Access Approval requests\n-------------------------------\n\nNow that you have enrolled in Access Approval and added yourself as an\napprover for access requests, you can expect to receive email notifications for\naccess requests.\n\nThe following image shows a sample email notification that Access Approval\nsends when Google personnel request access to Customer Data.\n\n\nTo review and approve an incoming access request, do the following:\n\n1. Go to the **Access Approval** page in the Google Cloud console.\n\n [Go to Access Approval](https://console.cloud.google.com/security/access-approval)\n\n To be taken to this page, you can also click the link in the email\n sent to you with the approval request.\n2. Click **Approve**.\n\nAfter you approve the request, Google personnel with\n[characteristics](/assured-workloads/access-approval/docs/approval-request-details) matching the approval, such as, same\njustification, location, or desk location can access the specified resource and\nits child resources within the approved timeframe.\n\nClean up\n--------\n\n1. To unenroll from Access Approval, do the following:\n 1. On the **Access Approval** page in the Google Cloud console, click **Manage settings**.\n 2. Click **Unenroll**.\n 3. In the dialog that opens, click **Unenroll**.\n2. To disable Access Transparency for your organization, contact [Cloud Customer Care](/support).\n\nNo additional steps are required to avoid incurring charges to your account.\n\nWhat's next\n-----------\n\n- Learn about the [anatomy of an access request](/assured-workloads/access-approval/docs/approval-request-details).\n- Learn how to [approve Access Approval requests](/assured-workloads/access-approval/docs/approve-requests).\n- Learn how to [view historical Access Approval requests](/assured-workloads/access-approval/docs/view-historical-requests)."]]