Organization Policy Service roles and permissions

This page lists the IAM roles and permissions for Organization Policy Service. To search through all roles and permissions, see the role and permission index.

Organization Policy Service roles

Role Permissions

(roles/orgpolicy.policyAdmin)

Provides access to define what restrictions an organization wants to place on the configuration of cloud resources by setting Organization Policies.

Lowest-level resources where you can grant this role:

  • Organization

cloudasset.assets.analyzeOrgPolicy

cloudasset.assets.exportResource

cloudasset.assets.listResource

cloudasset.assets.searchAllResources

orgpolicy.*

  • orgpolicy.constraints.list
  • orgpolicy.customConstraints.create
  • orgpolicy.customConstraints.delete
  • orgpolicy.customConstraints.get
  • orgpolicy.customConstraints.list
  • orgpolicy.customConstraints.update
  • orgpolicy.policies.create
  • orgpolicy.policies.delete
  • orgpolicy.policies.list
  • orgpolicy.policies.update
  • orgpolicy.policy.get
  • orgpolicy.policy.set

policysimulator.orgPolicyViolations.list

policysimulator.orgPolicyViolationsPreviews.*

  • policysimulator.orgPolicyViolationsPreviews.create
  • policysimulator.orgPolicyViolationsPreviews.get
  • policysimulator.orgPolicyViolationsPreviews.list

recommender.orgPolicyInsights.*

  • recommender.orgPolicyInsights.get
  • recommender.orgPolicyInsights.list
  • recommender.orgPolicyInsights.update

recommender.orgPolicyRecommendations.*

  • recommender.orgPolicyRecommendations.get
  • recommender.orgPolicyRecommendations.list
  • recommender.orgPolicyRecommendations.update

(roles/orgpolicy.policyViewer)

Provides access to view Organization Policies on resources.

Lowest-level resources where you can grant this role:

  • Project

orgpolicy.constraints.list

orgpolicy.customConstraints.get

orgpolicy.customConstraints.list

orgpolicy.policies.list

orgpolicy.policy.get

Organization Policy Service permissions

Permission Included in roles

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Organization Policy Viewer (roles/orgpolicy.policyViewer)

Folder Admin (roles/resourcemanager.folderAdmin)

Folder Creator (roles/resourcemanager.folderCreator)

Folder Editor (roles/resourcemanager.folderEditor)

Folder Viewer (roles/resourcemanager.folderViewer)

Organization Administrator (roles/resourcemanager.organizationAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Service agent roles

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Organization Policy Viewer (roles/orgpolicy.policyViewer)

OrgPolicy Simulator Admin (roles/policysimulator.orgPolicyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Organization Policy Viewer (roles/orgpolicy.policyViewer)

OrgPolicy Simulator Admin (roles/policysimulator.orgPolicyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Assured Workloads Administrator (roles/assuredworkloads.admin)

Assured Workloads Editor (roles/assuredworkloads.editor)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Assured Workloads Administrator (roles/assuredworkloads.admin)

Assured Workloads Editor (roles/assuredworkloads.editor)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Assured Workloads Administrator (roles/assuredworkloads.admin)

Assured Workloads Editor (roles/assuredworkloads.editor)

Assured Workloads Reader (roles/assuredworkloads.reader)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Organization Policy Viewer (roles/orgpolicy.policyViewer)

OrgPolicy Simulator Admin (roles/policysimulator.orgPolicyAdmin)

Folder Admin (roles/resourcemanager.folderAdmin)

Folder Creator (roles/resourcemanager.folderCreator)

Folder Editor (roles/resourcemanager.folderEditor)

Folder Viewer (roles/resourcemanager.folderViewer)

Organization Administrator (roles/resourcemanager.organizationAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Service agent roles

Assured Workloads Administrator (roles/assuredworkloads.admin)

Assured Workloads Editor (roles/assuredworkloads.editor)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Assured Workloads Administrator (roles/assuredworkloads.admin)

Assured Workloads Editor (roles/assuredworkloads.editor)

Assured Workloads Reader (roles/assuredworkloads.reader)

Environment and Storage Object Administrator (roles/composer.environmentAndStorageObjectAdmin)

Composer Worker (roles/composer.worker)

Consumer Procurement Entitlement Manager (roles/consumerprocurement.entitlementManager)

Consumer Procurement Entitlement Viewer (roles/consumerprocurement.entitlementViewer)

Consumer Procurement Administrator (roles/consumerprocurement.procurementAdmin)

Consumer Procurement Viewer (roles/consumerprocurement.procurementViewer)

Application Design Center Admin (roles/designcenter.admin)

Application Design Center User (roles/designcenter.user)

Firebase Admin (roles/firebase.admin)

Firebase Develop Admin (roles/firebase.developAdmin)

Firebase Admin SDK Administrator Service Agent (roles/firebase.sdkAdminServiceAgent)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Organization Policy Viewer (roles/orgpolicy.policyViewer)

OrgPolicy Simulator Admin (roles/policysimulator.orgPolicyAdmin)

Folder Admin (roles/resourcemanager.folderAdmin)

Folder Creator (roles/resourcemanager.folderCreator)

Folder Editor (roles/resourcemanager.folderEditor)

Folder Viewer (roles/resourcemanager.folderViewer)

Organization Administrator (roles/resourcemanager.organizationAdmin)

Cloud Run Source Developer (roles/run.sourceDeveloper)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)

API Keys Admin (roles/serviceusage.apiKeysAdmin)

Storage Admin (roles/storage.admin)

Storage Express Mode User Access (roles/storage.expressModeUserAccess)

Storage Folder Admin (roles/storage.folderAdmin)

Storage HMAC Key Admin (roles/storage.hmacKeyAdmin)

Storage Object Admin (roles/storage.objectAdmin)

Storage Object Creator (roles/storage.objectCreator)

Storage Object User (roles/storage.objectUser)

Workload Manager Admin (roles/workloadmanager.admin)

Workload Manager Evaluation Admin (roles/workloadmanager.evaluationAdmin)

Workload Manager Evaluation Viewer (roles/workloadmanager.evaluationViewer)

Workload Manager Viewer (roles/workloadmanager.viewer)

Workload Manager Worker (roles/workloadmanager.worker)

Service agent roles

Assured Workloads Administrator (roles/assuredworkloads.admin)

Assured Workloads Editor (roles/assuredworkloads.editor)

Organization Policy Administrator (roles/orgpolicy.policyAdmin)

Security Posture Admin (roles/securityposture.admin)

Security Posture Deployer (roles/securityposture.postureDeployer)