Remove a role from a member in a project. The member can be either a human user or a service account.
EXAMPLES
To remove the role "pr-test-role" for user "test-user@example.com" with IdP prefix "fop" in project "iam-test", run:
gdcloud projects remove-iam-policy-binding iam-test --role=pr-test-role --member=user:fop-test-user@example.com
To remove the role "pr-test-role" for service account "test-sa" of project "test-sa-project" in the project "iam-test", run:
gdcloud projects remove-iam-policy-binding iam-test --role=pr-test-role --member=serviceAccount:test-sa-project:test-sa
REQUIRED FLAGS
--member string Member to remove the binding for, defined by either user:EMAIL or serviceAccount:SERVICE_ACCOUNT_PROJECT:SERVICE_ACCOUNT_NAME. The email should contain the IdP prefix for the user.
--role string Role name to be removed from the member.
GDCLOUD WIDE FLAGS
These flags are available to all commands: --configuration, --format, --help, --project, --quiet.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-29 UTC."],[[["\u003cp\u003eThis command \u003ccode\u003egdcloud projects remove-iam-policy-binding\u003c/code\u003e removes a specified role from a given member within a project.\u003c/p\u003e\n"],["\u003cp\u003eThe member can be a human user, indicated by \u003ccode\u003euser:EMAIL\u003c/code\u003e, or a service account, indicated by \u003ccode\u003eserviceAccount:SERVICE_ACCOUNT_PROJECT:SERVICE_ACCOUNT_NAME\u003c/code\u003e.\u003c/p\u003e\n"],["\u003cp\u003eThe user's email must include the Identity Provider (IdP) prefix.\u003c/p\u003e\n"],["\u003cp\u003eThe command requires two flags: \u003ccode\u003e--member\u003c/code\u003e to specify the user or service account and \u003ccode\u003e--role\u003c/code\u003e to specify the role to be removed.\u003c/p\u003e\n"]]],[],null,["# gdcloud projects remove-iam-policy-binding\n\nNAME\n----\n\ngdcloud projects remove-iam-policy-binding - Remove a role from a member in a project.\n\nSYNOPSIS\n--------\n\n gdcloud projects remove-iam-policy-binding PROJECT_ID [flags]\n\nDESCRIPTION\n-----------\n\nRemove a role from a member in a project. The member can be either a human user or a service account.\n\n### EXAMPLES\n\n\n To remove the role \"pr-test-role\" for user \"test-user@example.com\" with IdP prefix \"fop\" in project \"iam-test\", run:\n\n gdcloud projects remove-iam-policy-binding iam-test --role=pr-test-role --member=user:fop-test-user@example.com\n\n To remove the role \"pr-test-role\" for service account \"test-sa\" of project \"test-sa-project\" in the project \"iam-test\", run:\n\n gdcloud projects remove-iam-policy-binding iam-test --role=pr-test-role --member=serviceAccount:test-sa-project:test-sa\n\n### REQUIRED FLAGS\n\n --member string Member to remove the binding for, defined by either user:EMAIL or serviceAccount:SERVICE_ACCOUNT_PROJECT:SERVICE_ACCOUNT_NAME. The email should contain the IdP prefix for the user.\n --role string Role name to be removed from the member.\n\n### GDCLOUD WIDE FLAGS\n\nThese flags are available to all commands: `--configuration`, `--format`, `--help`, `--project`, `--quiet`.\n\nFor more information, see the [gdcloud CLI reference overview](/distributed-cloud/hosted/docs/latest/gdch/resources/gdcloud-reference/gdcloud) page."]]