[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-11。"],[],[],null,["# Configure access control for Producer Portal users\n\nThis page describes the Identity and Access Management (IAM) roles and permissions that\nyou'll need to grant to members of your team who\n[use Producer Portal](/marketplace/docs/partners/get-started#integrate).\n| **Note:** [IAM basic roles](/iam/docs/understanding-roles#basic), such as the Project Editor role (`roles/editor`), might enable users to perform necessary tasks, but we recommend that you only grant the minimal necessary roles. You shouldn't grant basic roles in a production environment, although you can grant them in a development or test environment.\n\nFor more information about granting access to roles and resources, see the\nIAM documentation on\n[Granting, changing, and revoking access to resources](/iam/docs/granting-changing-revoking-access).\nIf you don't have the permissions you need to grant roles, contact your\norganization's administrator and request access.\n\nAccess control for managing your Partner Advantage account and your organization\n--------------------------------------------------------------------------------\n\nFor users to manage your Partner Advantage account and your organization-level\nsettings, grant them one of the following two roles:\n\n- [Commerce Business Enablement Configuration Admin](/marketplace/docs/access-control#commercebusinessenablement.admin)\n (`roles/commercebusinessenablement.admin`)\n\n- [Commerce Business Enablement Configuration Viewer](/marketplace/docs/access-control#commercebusinessenablement.viewer)\n (`roles/commercebusinessenablement.viewer`)\n\nAccess control for viewing product listings\n-------------------------------------------\n\nFor users to view in-progress product listings that you create in\nProducer Portal, grant them the\n[Commerce Producer Viewer](/marketplace/docs/access-control#commerceproducer.viewer)\nrole.\n\nAccess control for creating and managing product listings\n---------------------------------------------------------\n\nFor users to create and manage product listings in Producer Portal,\ngrant them the following roles:\n\n- [Commerce Producer Admin](/marketplace/docs/access-control#commerceproducer.admin)\n- [Service Management Administrator](https://console.cloud.google.com/iam-admin/roles/details/roles%3Cservicemanagement.admin)\n\n| **Note:** The [Commerce Producer Admin](/marketplace/docs/access-control#commerceproducer.admin) role provides full access to all resources for your products.\n\n### Additional roles for software as a service (SaaS) products\n\nFor SaaS products, where you need to create a service account to interact with\nthe Cloud Commerce Consumer Procurement API and report usage to us, grant your\nusers the\n[Service Account Admin](https://console.cloud.google.com/iam-admin/roles/details/roles%3Ciam.serviceAccountAdmin)\nrole.\n\n#### Additional roles for virtual machine (VM) and Kubernetes products\n\nFor VM or Kubernetes products, grant your users the\n[Compute Storage Admin](https://console.cloud.google.com/iam-admin/roles/details/roles%3Ccompute.storageAdmin)\nrole.\n\nIf you used the\n[VM guided configuration](/marketplace/docs/partners/vm/create-deployment-package#simple-deployment)\nto create your VM product's deployment package, grant your users the following\nroles for the Cloud Storage bucket where you store your product's deployment\npackage:\n\n- [Storage Object Viewer](https://console.cloud.google.com/iam-admin/roles/details/roles%3Cstorage.objectViewer)\n- [Storage Object Creator](https://console.cloud.google.com/iam-admin/roles/details/roles%3Cstorage.objectCreator)\n\nAccess control for previewing your products in Cloud Marketplace\n----------------------------------------------------------------\n\nIf you want users to be able to preview your product's listing as your customers\nsee it in Cloud Marketplace, you must grant them the following role:\n\n- [Service Management Consumer](https://console.cloud.google.com/iam-admin/roles/details/roles%3Cservicemanagement.serviceConsumer)\n\nAccess control for creating and managing private offers in Producer Portal\n--------------------------------------------------------------------------\n\nFor users to create and manage private offers in the\n[Private offers](https://console.cloud.google.com/producer-portal/private-offers) tab of\nProducer Portal, grant them the following roles:\n\n- [Commerce Price Management Private Offers Admin](https://console.cloud.google.com/iam-admin/roles/details/roles%3Ccommercepricemanagement.privateOffersAdmin)\n- [Commerce Producer Viewer](/marketplace/docs/access-control#commerceproducer.viewer)\n\n### Access control for viewing key events for private offers\n\nFor users to\n[view the history of an offer](/marketplace/docs/partners/offers/view-offer-status#key-events)\nthat your organization has published, grant them the\n[Commerce Price Management Events Viewer](https://console.cloud.google.com/iam-admin/roles/details/roles%3Ccommercepricemanagement.eventsViewer)\nrole.\n\nAccess control for managing disbursements and payments in Producer Portal\n-------------------------------------------------------------------------\n\nFor users to create payment profiles to manage disbursement\nand payment settings in the [Payments](https://console.cloud.google.com/producer-portal/payments)\ntab of Producer Portal, grant them the following roles:\n\n- [Commerce Business Enablement PaymentConfig Admin](/marketplace/docs/access-control#commercebusinessenablement.paymentConfigAdmin)\n- [Commerce Producer Viewer](/marketplace/docs/access-control#commerceproducer.viewer)\n\n| **Note:** These roles enable users to create payment profiles. To add users to an existing payment profile, see [Controlling access to payment profiles](/marketplace/docs/partners/receive-payments#adding-users).\n\nAccess control for reselling of your Cloud Marketplace products\n---------------------------------------------------------------\n\nIf you've allowed resellers to resell your Cloud Marketplace products, you\ncan refer to the following guidelines for granting roles within your\nGoogle Cloud organization.\n\n### Access control for viewing which resellers are allowed to resell your products\n\nFor users to view which resellers are allowed to resell your\nCloud Marketplace products, or which resellers have been disallowed from\nreselling your products, grant them one of the following roles:\n\n- [Commerce Business Enablement Configuration Viewer](/marketplace/docs/access-control#commercebusinessenablement.viewer) (`roles/commercebusinessenablement.viewer`)\n- [Commerce Business Enablement Configuration Admin](/marketplace/docs/access-control#commercebusinessenablement.admin) (`roles/commercebusinessenablement.admin`)\n\n### Access control for managing which resellers are allowed to resell your products\n\nFor users to manage which resellers are allowed to resell your\nCloud Marketplace products, grant them the\n[Commerce Business Enablement Configuration Admin](/marketplace/docs/access-control#commercebusinessenablement.admin)\n(`roles/commercebusinessenablement.admin`) role.\n\n### Access control for viewing reseller discounts in Producer Portal\n\nFor users to view resources and configurations related to reseller discounts in\nProducer Portal, grant them the following roles:\n\n- [Commerce Business Enablement Reseller Discount Viewer](/marketplace/docs/access-control#commercebusinessenablement.resellerDiscountViewer)\n (`roles/commercebusinessenablement.resellerDiscountViewer`)\n\n- [Commerce Price Management Viewer](/marketplace/docs/access-control#commercepricemanagement.viewer)\n (`roles/commercepricemanagement.viewer`)\n\n### Access control for creating and managing reseller discounts in Producer Portal\n\nFor users to create and manage resources and configurations related to reseller\ndiscounts in Producer Portal, grant them the following roles:\n\n- [Commerce Business Enablement Reseller Discount Admin](/marketplace/docs/access-control#commercebusinessenablement.resellerDiscountAdmin)\n (`roles/commercebusinessenablement.resellerDiscountAdmin`)\n\n- [Commerce Price Management Viewer](/marketplace/docs/access-control#commercepricemanagement.viewer)\n (`roles/commercepricemanagement.viewer`)\n\nAccess control for managing analytics and reports in Producer Portal\n--------------------------------------------------------------------\n\nFor users to manage analytics, test accounts, sales lead management, and reports\nfor your products in the [**Analytics**](https://console.cloud.google.com/producer-portal/analytics),\n[**Test billing accounts**](https://console.cloud.google.com/producer-portal/test-billing-accounts),\n[**Sales lead management**](https://console.cloud.google.com/producer-portal/sales-lead-management),\nand [**Reports**](https://console.cloud.google.com/producer-portal/partner-report) tabs of Producer Portal,\ngrant them the following roles:\n\n- [Commerce Business Enablement Configuration Admin](/marketplace/docs/access-control#commercebusinessenablement.admin)\n (`roles/commercebusinessenablement.admin`)\n\n- [Commerce Producer Viewer](/marketplace/docs/access-control#commerceproducer.viewer) (`roles/commerceproducer.viewer`)\n\n- [Project Viewer](https://console.cloud.google.com/iam-admin/roles/details/roles%3Cviewer)(`roles/viewer`)"]]