Stay organized with collections
Save and categorize content based on your preferences.
IAM permissions and roles
This page describes how you use Identity and Access Management (IAM) roles and
permissions to control access to Google Cloud Carbon Footprint data.
Overview
IAM permissions and
roles determine your ability
to access data through the Google Cloud console and data export.
A role is a collection of permissions. You can't grant a permission to a
principal (user or service account) directly; instead, you grant principals a
role. When you grant a role to a principal, you grant them all the permissions
that the role contains. You can grant multiple roles to the same principal.
To access Carbon Footprint data associated with a billing account, a billing
account administrator must grant you one or more IAM roles on the billing
account that contain the appropriate carbon data permission.
The following table describes Identity and Access Management (IAM) roles
associated with Carbon Footprint, and lists the permissions
that are contained in each role.
Provides access to see and manage all aspects of billing accounts, including carbon information.
See Billing IAM roles documentation for complete list of permissions of this role. Includes but not limited to: billing.accounts.listbilling.accounts.getbilling.accounts.getCarbonInformation
Billing Account Viewer (roles/billing.viewer)
View billing account cost and pricing information, transactions, and billing and commitment recommendations, including carbon information.
See Billing IAM roles documentation for complete list of permissions of this role. Includes but not limited to: billing.accounts.listbilling.accounts.getbilling.accounts.getCarbonInformation
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-25 UTC."],[[["\u003cp\u003eIAM roles and permissions control access to Google Cloud Carbon Footprint data, determining who can view it through the Google Cloud console and data export features.\u003c/p\u003e\n"],["\u003cp\u003eAccess to Carbon Footprint data requires a billing account administrator to grant users or service accounts one or more IAM roles on the billing account, with roles being collections of permissions.\u003c/p\u003e\n"],["\u003cp\u003eThe \u003ccode\u003ebilling.accounts.getCarbonInformation\u003c/code\u003e permission is necessary to view the carbon footprint of a billing account.\u003c/p\u003e\n"],["\u003cp\u003eSpecific curated roles like Carbon Footprint Viewer, Billing Account Administrator, and Billing Account Viewer grant varying levels of access to Carbon Footprint data, and these roles contain the necessary permissions.\u003c/p\u003e\n"]]],[],null,["# IAM permissions and roles\n=========================\n\nThis page describes how you use [Identity and Access Management (IAM)](/iam) roles and\npermissions to control access to Google Cloud Carbon Footprint data.\n\nOverview\n--------\n\nIAM [permissions](https://cloud.google.com/iam/docs/overview#permissions) and\n[roles](https://cloud.google.com/iam/docs/overview#roles) determine your ability\nto access data through the Google Cloud console and [data export](https://cloud.google.com/carbon-footprint/docs/export).\n\nA role is a collection of permissions. You can't grant a permission to a\nprincipal (user or service account) directly; instead, you grant principals a\nrole. When you grant a role to a principal, you grant them all the permissions\nthat the role contains. You can grant multiple roles to the same principal.\n\nTo access Carbon Footprint data associated with a billing account, a billing\naccount administrator must grant you one or more IAM roles on the billing\naccount that contain the appropriate carbon data permission.\n\nPermissions\n-----------\n\nThe following table list the [Identity and Access Management (IAM)](/iam)\npermissions associated with Carbon Footprint.\n\nCurated roles\n-------------\n\nThe following table describes [Identity and Access Management (IAM)](/iam) roles\nassociated with Carbon Footprint, and lists the permissions\nthat are contained in each role."]]