This page lists the IAM roles and permissions for Confidential Computing. To search through all roles and permissions, see the role and permission index.
Confidential Computing roles
| Role | Permissions | 
|---|---|
| Confidential Space Workload User( Grants the ability to generate an attestation token and run a workload in a VM. Intended for service accounts that run on Confidential Space VMs. | 
       
 
 | 
Confidential Computing permissions
| Permission | Included in roles | 
|---|---|
| 
 | 
          Owner ( 
          Editor ( 
          Confidential Space Workload User ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Confidential Space Workload User ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Confidential Space Workload User ( 
          Support User ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Confidential Space Workload User ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( |