This page lists the IAM roles and permissions for Cloud Logging. To search through all roles and permissions, see the role and permission index.
Cloud Logging roles
Role | Permissions |
---|---|
Logging Admin( Provides all permissions necessary to use all features of Cloud Logging. Lowest-level resources where you can grant this role:
|
|
Logs Bucket Writer( Ability to write logs to a log bucket. Lowest-level resources where you can grant this role:
|
|
Logs Configuration Writer( Provides permissions to read and write the configurations of logs-based metrics and sinks for exporting logs. Lowest-level resources where you can grant this role:
|
|
Log Field Accessor( Ability to read restricted fields in a log bucket. Lowest-level resources where you can grant this role:
|
|
Log Link Accessor( Ability to see links for a bucket. |
|
Logs Writer( Provides the permissions to write log entries. Lowest-level resources where you can grant this role:
|
|
Private Logs Viewer( Provides permissions of the Logs Viewer role and in addition, provides read-only access to log entries in private logs. Lowest-level resources where you can grant this role:
|
|
Cloud Logging Service Agent( Grants a Cloud Logging Service Account the ability to create and link datasets. |
|
SQL Alert Writer Beta( Ability to write SQL Alerts. |
|
Logs View Accessor( Ability to read logs in a view. Lowest-level resources where you can grant this role:
|
|
Logs Viewer( Provides access to view logs. Lowest-level resources where you can grant this role:
|
|
Cloud Logging permissions
Permission | Included in roles |
---|---|
|
Owner (
Editor (
Viewer (
Logging Admin ( |
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
DLP Organization Data Profiles Driver (
DLP Project Data Profiles Driver (
Logging Admin (
Logs Configuration Writer (
Tag User ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
DLP Organization Data Profiles Driver (
DLP Project Data Profiles Driver (
Logging Admin (
Logs Configuration Writer (
Tag User ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
DLP Organization Data Profiles Driver (
DLP Project Data Profiles Driver (
Logging Admin (
Logs Configuration Writer (
Tag User (
Tag Viewer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
DLP Organization Data Profiles Driver (
DLP Project Data Profiles Driver (
Logging Admin (
Logs Configuration Writer (
Tag User (
Tag Viewer ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Logs Bucket Writer ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Logging Admin (
Log Field Accessor ( |
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Log Link Accessor (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Log Link Accessor (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Cloud Build Service Account (
Cloud Deploy Runner (
Composer Worker (
Confidential Space Workload User (
Cloud Infrastructure Manager Agent (
Kubernetes Engine Default Node Service Account (
Dataflow Worker (
Dataproc Hub Agent (
Dataproc Worker (
Anthos Multi-cloud Telemetry Writer (
Logging Admin (
Logs Writer (
Cloud Run Builder ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Logging Admin (
Logs View Accessor ( |
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Billing Account Administrator (
Cloud Build Service Account (
Cloud Hub Operator (
Composer Worker (
Dataproc Hub Agent (
Firebase Admin (
Firebase Develop Admin (
Firebase Develop Viewer (
Firebase Viewer (
Security Admin (
Security Reviewer (
Logging Admin (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Composer Worker (
Dataflow Worker (
Dataproc Hub Agent (
Dataproc Worker (
Anthos Multi-cloud Telemetry Writer (
Logging Admin (
Logs Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Billing Account Administrator (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Billing Account Administrator (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Logging Admin ( |
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Billing Account Administrator (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Error Reporting Admin (
Error Reporting User (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Error Reporting Admin (
Error Reporting User (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Error Reporting Admin (
Error Reporting User (
Error Reporting Viewer (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Error Reporting Admin (
Error Reporting User (
Error Reporting Viewer (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Error Reporting Admin (
Error Reporting User (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Billing Account Administrator (
Security Admin (
Security Reviewer (
Logging Admin (
Private Logs Viewer ( |
|
Owner (
Logging Admin ( |
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( |
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( |
|
Owner (
Logging Admin ( |
|
Owner (
Logging Admin ( |
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( |
|
Owner (
Editor (
Viewer (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Assured Workloads Administrator (
Assured Workloads Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer (
SQL Alert Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer (
SQL Alert Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
VPC Service Controls Troubleshooter Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( |
|
Owner (
Cloud Build Service Account (
Composer Worker (
Logging Admin (
Private Logs Viewer (
Logs View Accessor ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Cloud Hub Operator (
Dataproc Hub Agent (
Security Admin (
Security Reviewer (
Logging Admin (
Logs Configuration Writer (
Private Logs Viewer (
Logs Viewer (
Telco Automation Admin (
Telco Automation Tier 1 Operations Admin (
Telco Automation Tier 4 Operations Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
Logging Admin (
Logs View Accessor ( |
|
Owner (
Editor (
Viewer (
Logging Admin (
Logs View Accessor ( |
|
Owner (
Editor (
Viewer (
Logging Admin (
Logs View Accessor ( |
|
Owner (
Security Admin (
Logging Admin ( |
|
Owner (
Editor (
Logging Admin (
Logs Configuration Writer ( Service agent roles
|