Chrome Enterprise Premium roles and permissions

This page lists the IAM roles and permissions for Chrome Enterprise Premium. To search through all roles and permissions, see the role and permission index.

Chrome Enterprise Premium roles

Role Permissions

(roles/beyondcorp.admin)

Full access to all Cloud BeyondCorp resources.

beyondcorp.appConnections.*

  • beyondcorp.appConnections.create
  • beyondcorp.appConnections.delete
  • beyondcorp.appConnections.get
  • beyondcorp.appConnections.getIamPolicy
  • beyondcorp.appConnections.list
  • beyondcorp.appConnections.setIamPolicy
  • beyondcorp.appConnections.update

beyondcorp.appConnectors.*

  • beyondcorp.appConnectors.create
  • beyondcorp.appConnectors.delete
  • beyondcorp.appConnectors.get
  • beyondcorp.appConnectors.getIamPolicy
  • beyondcorp.appConnectors.list
  • beyondcorp.appConnectors.reportStatus
  • beyondcorp.appConnectors.setIamPolicy
  • beyondcorp.appConnectors.update

beyondcorp.appGateways.*

  • beyondcorp.appGateways.create
  • beyondcorp.appGateways.delete
  • beyondcorp.appGateways.get
  • beyondcorp.appGateways.getIamPolicy
  • beyondcorp.appGateways.list
  • beyondcorp.appGateways.setIamPolicy
  • beyondcorp.appGateways.update

beyondcorp.clientConnectorServices.create

beyondcorp.clientConnectorServices.delete

beyondcorp.clientConnectorServices.get

beyondcorp.clientConnectorServices.getIamPolicy

beyondcorp.clientConnectorServices.list

beyondcorp.clientConnectorServices.setIamPolicy

beyondcorp.clientConnectorServices.update

beyondcorp.clientGateways.*

  • beyondcorp.clientGateways.create
  • beyondcorp.clientGateways.delete
  • beyondcorp.clientGateways.get
  • beyondcorp.clientGateways.getIamPolicy
  • beyondcorp.clientGateways.list
  • beyondcorp.clientGateways.setIamPolicy

beyondcorp.locations.*

  • beyondcorp.locations.get
  • beyondcorp.locations.list

beyondcorp.operations.*

  • beyondcorp.operations.cancel
  • beyondcorp.operations.delete
  • beyondcorp.operations.get
  • beyondcorp.operations.list

beyondcorp.subscriptions.*

  • beyondcorp.subscriptions.create
  • beyondcorp.subscriptions.get
  • beyondcorp.subscriptions.list
  • beyondcorp.subscriptions.terminate
  • beyondcorp.subscriptions.update

resourcemanager.projects.get

resourcemanager.projects.list

(roles/beyondcorp.clientConnectorAdmin)

Full access to all BeyondCorp Client Connector resources.

beyondcorp.clientConnectorServices.create

beyondcorp.clientConnectorServices.delete

beyondcorp.clientConnectorServices.get

beyondcorp.clientConnectorServices.getIamPolicy

beyondcorp.clientConnectorServices.list

beyondcorp.clientConnectorServices.setIamPolicy

beyondcorp.clientConnectorServices.update

beyondcorp.clientGateways.*

  • beyondcorp.clientGateways.create
  • beyondcorp.clientGateways.delete
  • beyondcorp.clientGateways.get
  • beyondcorp.clientGateways.getIamPolicy
  • beyondcorp.clientGateways.list
  • beyondcorp.clientGateways.setIamPolicy

resourcemanager.projects.get

resourcemanager.projects.list

(roles/beyondcorp.clientConnectorServiceUser)

Access Client Connector Service

beyondcorp.clientConnectorServices.access

(roles/beyondcorp.clientConnectorViewer)

Read-only access to all BeyondCorp Client Connector resources.

beyondcorp.clientConnectorServices.get

beyondcorp.clientConnectorServices.getIamPolicy

beyondcorp.clientConnectorServices.list

beyondcorp.clientGateways.get

beyondcorp.clientGateways.getIamPolicy

beyondcorp.clientGateways.list

resourcemanager.projects.get

resourcemanager.projects.list

(roles/beyondcorp.partnerServiceDelegateAdmin)

Delegates access to all BeyondCorp partner service resources to a BeyondCorp Enterprise partner.

beyondcorp.operations.*

  • beyondcorp.operations.cancel
  • beyondcorp.operations.delete
  • beyondcorp.operations.get
  • beyondcorp.operations.list

beyondcorp.partnerTenants.*

  • beyondcorp.partnerTenants.create
  • beyondcorp.partnerTenants.delete
  • beyondcorp.partnerTenants.get
  • beyondcorp.partnerTenants.list
  • beyondcorp.partnerTenants.update

beyondcorp.proxyConfigs.*

  • beyondcorp.proxyConfigs.create
  • beyondcorp.proxyConfigs.delete
  • beyondcorp.proxyConfigs.get
  • beyondcorp.proxyConfigs.list
  • beyondcorp.proxyConfigs.update

resourcemanager.organizations.get

(roles/beyondcorp.partnerServiceDelegateViewer)

Delegates read-only access to all BeyondCorp partner service resources to a BeyondCorp Enterprise partner.

beyondcorp.partnerTenants.get

beyondcorp.partnerTenants.list

beyondcorp.proxyConfigs.get

beyondcorp.proxyConfigs.list

resourcemanager.organizations.get

(roles/beyondcorp.subscriptionAdmin)

Full access to all BeyondCorp Subscription resources.

beyondcorp.subscriptions.*

  • beyondcorp.subscriptions.create
  • beyondcorp.subscriptions.get
  • beyondcorp.subscriptions.list
  • beyondcorp.subscriptions.terminate
  • beyondcorp.subscriptions.update

resourcemanager.organizations.get

(roles/beyondcorp.subscriptionViewer)

Read-only access to all BeyondCorp Subscription resources.

beyondcorp.subscriptions.get

beyondcorp.subscriptions.list

resourcemanager.organizations.get

(roles/beyondcorp.viewer)

Read-only access to all Cloud BeyondCorp resources.

beyondcorp.appConnections.get

beyondcorp.appConnections.getIamPolicy

beyondcorp.appConnections.list

beyondcorp.appConnectors.get

beyondcorp.appConnectors.getIamPolicy

beyondcorp.appConnectors.list

beyondcorp.appGateways.get

beyondcorp.appGateways.getIamPolicy

beyondcorp.appGateways.list

beyondcorp.clientConnectorServices.get

beyondcorp.clientConnectorServices.getIamPolicy

beyondcorp.clientConnectorServices.list

beyondcorp.clientGateways.get

beyondcorp.clientGateways.getIamPolicy

beyondcorp.clientGateways.list

beyondcorp.locations.*

  • beyondcorp.locations.get
  • beyondcorp.locations.list

beyondcorp.operations.get

beyondcorp.operations.list

beyondcorp.subscriptions.get

beyondcorp.subscriptions.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

Chrome Enterprise Premium permissions

Permission Included in roles

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Security Admin (roles/iam.securityAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Security Admin (roles/iam.securityAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Security Admin (roles/iam.securityAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Service User (roles/beyondcorp.clientConnectorServiceUser)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Cloud BeyondCorp Client Connector Viewer (roles/beyondcorp.clientConnectorViewer)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Cloud BeyondCorp Client Connector Viewer (roles/beyondcorp.clientConnectorViewer)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Cloud BeyondCorp Client Connector Viewer (roles/beyondcorp.clientConnectorViewer)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Security Admin (roles/iam.securityAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Cloud BeyondCorp Client Connector Viewer (roles/beyondcorp.clientConnectorViewer)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Cloud BeyondCorp Client Connector Viewer (roles/beyondcorp.clientConnectorViewer)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Cloud BeyondCorp Client Connector Viewer (roles/beyondcorp.clientConnectorViewer)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Client Connector Admin (roles/beyondcorp.clientConnectorAdmin)

Security Admin (roles/iam.securityAdmin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Cloud BeyondCorp Partner Service Delegate Viewer (roles/beyondcorp.partnerServiceDelegateViewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Cloud BeyondCorp Partner Service Delegate Viewer (roles/beyondcorp.partnerServiceDelegateViewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Cloud BeyondCorp Partner Service Delegate Viewer (roles/beyondcorp.partnerServiceDelegateViewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Cloud BeyondCorp Partner Service Delegate Viewer (roles/beyondcorp.partnerServiceDelegateViewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Partner Service Delegate Admin (roles/beyondcorp.partnerServiceDelegateAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Subscription Admin (roles/beyondcorp.subscriptionAdmin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Subscription Admin (roles/beyondcorp.subscriptionAdmin)

Cloud BeyondCorp Subscription Viewer (roles/beyondcorp.subscriptionViewer)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Subscription Admin (roles/beyondcorp.subscriptionAdmin)

Cloud BeyondCorp Subscription Viewer (roles/beyondcorp.subscriptionViewer)

Cloud BeyondCorp Viewer (roles/beyondcorp.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Subscription Admin (roles/beyondcorp.subscriptionAdmin)

Owner (roles/owner)

Editor (roles/editor)

Cloud BeyondCorp Admin (roles/beyondcorp.admin)

Cloud BeyondCorp Subscription Admin (roles/beyondcorp.subscriptionAdmin)