This page lists the IAM roles and permissions for Network Connectivity Center. To search through all roles and permissions, see the role and permission index.
Network Connectivity Center roles
| Role | Permissions | 
|---|---|
| Service Automation Consumer Network Admin( Service Automation Consumer Network Admin is responsible for setting up ServiceConnectionPolicies. | 
       
 
 
 | 
| Group Admin( Enables full access to group resources and read-only access to hub and spoke resources | 
 
 
       
 
 
 
 
 
 
 
 
 
 
       
 
 
 
 
 
 
 
 | 
| Group User( Enables use access on group resources | 
 | 
| Hub & Spoke Admin( Enables full access to hub and spoke resources. Lowest-level resources where you can grant this role: 
 | 
       
 
       
 
       
 
       
 
       
 
       
 
       
 
       
 
 
 | 
| Hub & Spoke Viewer( Enables read-only access to hub and spoke resources. Lowest-level resources where you can grant this role: 
 | 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
       
 
 
 
 
 
 | 
| Multicloud Data Transfer Config Admin( Full access to all Multicloud Data Transfer Config resources. | 
       
 
       
 
       
 
 
 | 
| Multicloud Data Transfer Config Viewer( Read-only access to all Multicloud Data Transfer Config resources. | 
 
 
 
 
       
 
 
 | 
| Destination Admin( Access to all Destination resources. | 
       
 
       
 
 
 | 
| Destination Viewer( Read-only access to all Destination resources. | 
 
 
       
 
 
 | 
| Regional Endpoint Admin( Full access to all Regional Endpoint resources. | 
       
 
 
 | 
| Regional Endpoint Viewer( Read-only access to all Regional Endpoint resources. | 
 
 
 
 | 
| Network Connectivity Service Agent( Grants the Network Connectivity API authority to read some networking resources. It does not mutate these resources. | 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 | 
| Service Class User( Service Class User uses a ServiceClass | 
 
 
 
 
 | 
| Service Automation Service Producer Admin( Service Automation Producer Admin uses information from a consumer request to manage ServiceClasses and ServiceConnectionMaps | 
 
 
       
 
       
 
 
 | 
| Spoke Admin( Enables full access to spoke resources and read-only access to hub resources. Lowest-level resources where you can grant this role: 
 | 
       
 
 
 
 
 
 
 
 
 
 
       
 
 
 
       
 
 
 | 
Network Connectivity Center permissions
| Permission | Included in roles | 
|---|---|
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Group Admin ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Group Admin ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Group Admin ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Group Admin ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Network Administrator ( 
          Security Admin ( 
          Group Admin ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Group Admin ( 
          Group User ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Network Administrator ( 
          Security Admin ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Network Administrator ( 
          Security Admin ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Support User ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Support User ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( | 
| 
 | 
          Owner ( 
          Network Administrator ( 
          Security Admin ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Compute Network User ( 
          Compute Network Viewer ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Compute Network User ( 
          Compute Network Viewer ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Compute Network User ( 
          Compute Network Viewer ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Compute Network User ( 
          Compute Network Viewer ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Multicloud Data Transfer Config Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Multicloud Data Transfer Config Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Support User ( 
          Multicloud Data Transfer Config Admin ( 
          Multicloud Data Transfer Config Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Multicloud Data Transfer Config Admin ( 
          Multicloud Data Transfer Config Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Multicloud Data Transfer Config Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Multicloud Data Transfer Config Admin ( 
          Destination Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Multicloud Data Transfer Config Admin ( 
          Destination Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Support User ( 
          Multicloud Data Transfer Config Admin ( 
          Multicloud Data Transfer Config Viewer ( 
          Destination Admin ( 
          Destination Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Multicloud Data Transfer Config Admin ( 
          Multicloud Data Transfer Config Viewer ( 
          Destination Admin ( 
          Destination Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Multicloud Data Transfer Config Admin ( 
          Destination Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Support User ( 
          Multicloud Data Transfer Config Admin ( 
          Multicloud Data Transfer Config Viewer ( 
          Destination Admin ( 
          Destination Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Multicloud Data Transfer Config Admin ( 
          Multicloud Data Transfer Config Viewer ( 
          Destination Admin ( 
          Destination Viewer ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Hub & Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Hub & Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Compute Network User ( 
          Compute Network Viewer ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Service Automation Service Producer Admin ( 
          Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Compute Network User ( 
          Compute Network Viewer ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Service Automation Service Producer Admin ( 
          Spoke Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Compute Network User ( 
          Compute Network Viewer ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Compute Network User ( 
          Compute Network Viewer ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Regional Endpoint Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Regional Endpoint Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Support User ( 
          Regional Endpoint Admin ( 
          Regional Endpoint Viewer ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Regional Endpoint Admin ( 
          Regional Endpoint Viewer ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Support User ( 
          Service Class User ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Service Class User ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Class User ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Support User ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Service Producer Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Consumer Network Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Consumer Network Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Support User ( 
          Service Automation Consumer Network Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Compute Network Admin ( 
          Databases Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Service Automation Consumer Network Admin ( 
          Cloud Memorystore Redis Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Compute Network Admin ( 
          Infrastructure Administrator ( 
          Network Administrator ( 
          Service Automation Consumer Network Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Group Admin ( 
          Hub & Spoke Admin ( 
          Hub & Spoke Viewer ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Network Administrator ( 
          Security Admin ( 
          Hub & Spoke Admin ( 
          Spoke Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Network Administrator ( 
          Hub & Spoke Admin ( 
          Spoke Admin ( |