Secured Landing Zone roles and permissions

This page lists the IAM roles and permissions for Secured Landing Zone. To search through all roles and permissions, see the role and permission index.

Secured Landing Zone roles

Role Permissions

(roles/securedlandingzone.bqdwOrgRemediator)

Access to modify (remediate) resources in SLZ BQDW Blueprint at Organization.

accesscontextmanager.servicePerimeters.get

accesscontextmanager.servicePerimeters.list

accesscontextmanager.servicePerimeters.update

(roles/securedlandingzone.bqdwProjectRemediator)

Access to modify (remediate) resources in SLZ BQDW Blueprint at Project.

bigquery.datasets.get

bigquery.datasets.getIamPolicy

bigquery.datasets.setIamPolicy

bigquery.datasets.update

cloudkms.cryptoKeys.get

cloudkms.cryptoKeys.getIamPolicy

cloudkms.cryptoKeys.list

cloudkms.cryptoKeys.setIamPolicy

cloudkms.cryptoKeys.update

cloudkms.keyRings.getIamPolicy

cloudkms.keyRings.setIamPolicy

pubsub.topics.get

pubsub.topics.getIamPolicy

pubsub.topics.list

pubsub.topics.setIamPolicy

pubsub.topics.update

resourcemanager.projects.update

serviceusage.services.use

storage.buckets.get

storage.buckets.getIamPolicy

storage.buckets.list

storage.buckets.setIamPolicy

storage.buckets.update

(roles/securedlandingzone.overwatchActivator)

This role can activate or suspend Overwatches

resourcemanager.projects.get

resourcemanager.projects.list

securedlandingzone.overwatches.activate

securedlandingzone.overwatches.suspend

(roles/securedlandingzone.overwatchAdmin)

Full access to Overwatches

resourcemanager.projects.get

resourcemanager.projects.list

securedlandingzone.*

  • securedlandingzone.operations.get
  • securedlandingzone.overwatches.activate
  • securedlandingzone.overwatches.create
  • securedlandingzone.overwatches.delete
  • securedlandingzone.overwatches.get
  • securedlandingzone.overwatches.list
  • securedlandingzone.overwatches.suspend
  • securedlandingzone.overwatches.update

(roles/securedlandingzone.overwatchViewer)

This role can view all properties of Overwatches

resourcemanager.projects.get

resourcemanager.projects.list

securedlandingzone.operations.get

securedlandingzone.overwatches.get

securedlandingzone.overwatches.list

(roles/securedlandingzone.serviceAgent)

Grants Secured Landing Zone service account permissions to manage resources in the customer project

cloudasset.assets.exportOrgPolicy

cloudasset.assets.exportResource

cloudasset.feeds.create

cloudasset.feeds.delete

cloudasset.feeds.update

logging.logEntries.list

pubsub.subscriptions.consume

pubsub.subscriptions.create

pubsub.subscriptions.delete

pubsub.topics.attachSubscription

pubsub.topics.create

pubsub.topics.delete

pubsub.topics.detachSubscription

pubsub.topics.getIamPolicy

pubsub.topics.setIamPolicy

resourcemanager.projects.get

securitycenter.assetsecuritymarks.update

securitycenter.findings.list

securitycenter.findings.update

securitycenter.sources.list

securitycenter.sources.update

serviceusage.services.use

Secured Landing Zone permissions

Permission Included in roles

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Overwatch Admin (roles/securedlandingzone.overwatchAdmin)

Overwatch Viewer (roles/securedlandingzone.overwatchViewer)

Owner (roles/owner)

Editor (roles/editor)

Overwatch Activator (roles/securedlandingzone.overwatchActivator)

Overwatch Admin (roles/securedlandingzone.overwatchAdmin)

Owner (roles/owner)

Editor (roles/editor)

Overwatch Admin (roles/securedlandingzone.overwatchAdmin)

Owner (roles/owner)

Editor (roles/editor)

Overwatch Admin (roles/securedlandingzone.overwatchAdmin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Overwatch Admin (roles/securedlandingzone.overwatchAdmin)

Overwatch Viewer (roles/securedlandingzone.overwatchViewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Overwatch Admin (roles/securedlandingzone.overwatchAdmin)

Overwatch Viewer (roles/securedlandingzone.overwatchViewer)

Owner (roles/owner)

Editor (roles/editor)

Overwatch Activator (roles/securedlandingzone.overwatchActivator)

Overwatch Admin (roles/securedlandingzone.overwatchAdmin)

Owner (roles/owner)

Editor (roles/editor)

Overwatch Admin (roles/securedlandingzone.overwatchAdmin)