Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Pemberi rekomendasi peran IAM menggunakan data akses IAM gabungan, yang dikumpulkan selama penggunaan layanan diGoogle Cloud, untuk memberikan rekomendasi. Data ini terutama digunakan untuk tujuan kepatuhan.
Admin BigQuery (roles/bigquery.admin)
di project yang akan Anda gunakan untuk mengekspor data
Untuk memublikasikan notifikasi transfer Anda ke topik Pub/Sub yang ada:
Pelihat Pub/Sub (roles/pubsub.viewer)
di project tempat Anda akan mengekspor data
Untuk memublikasikan notifikasi topik Anda ke topik Pub/Sub baru:
Pub/Sub Editor (roles/pubsub.editor)
di project tempat Anda akan mengekspor data
Pilih organisasi Anda dari menu drop-down, lalu klik Pilih.
Klik Transparansi & kontrol.
Di tabel Grup pemrosesan data, klik IAM.
Di bagian Sumber data di halaman, klik
tambahkanBuat transfer.
Di kolom Project, klik Browse, lalu pilih project yang
ingin Anda ekspor datanya. Jika project belum mengaktifkan
BigQuery Data Transfer Service API, klik Aktifkan API dan tunggu hingga API
diaktifkan.
Klik Berikutnya.
Konfigurasi transfer data:
Di kolom Nama tampilan, masukkan nama tampilan untuk transfer data Anda.
Di bagian Opsi jadwal, pilih kapan transfer data akan dimulai
dan seberapa sering transfer data akan dijalankan.
Untuk memilih kapan harus memulai transfer, Anda dapat membiarkan nilai default Mulai sekarang, atau mengklik Mulai pada waktu yang ditentukan.
Di kolom Ulangi, pilih opsi seberapa sering transfer dijalankan. Jika Anda memilih opsi selain Harian, opsi tambahan tersedia. Misalnya, jika Anda memilih Mingguan, sebuah opsi akan muncul untuk memilih hari.
Untuk Tanggal mulai dan waktu pelaksanaan, masukkan tanggal dan waktu untuk memulai
transfer. Jika Anda memilih Mulai sekarang, opsi ini akan dinonaktifkan.
Di kolom Dataset ID, pilih set data BigQuery
untuk mengekspor data.
Anda dapat mengekspor data ke set data yang ada, atau membuat set data baru:
Untuk mengekspor data ke set data yang ada, klik kolom ID Set Data,
lalu pilih set data dari daftar drop-down.
Untuk mengekspor data ke set data baru, klik kolom ID Set Data, klik
Buat set data baru, lalu isi kolom di panel Buat
set data:
Di kolom Dataset ID, masukkan ID untuk set data. Huruf, angka, dan garis bawah diperbolehkan.
Dari daftar drop-down Data location, pilih United
States (US) atau European Union (EU).
Opsional: Aktifkan masa berlaku tabel dengan
memilih Aktifkan masa berlaku tabel.
Opsional: Pilih metode enkripsi. Metode enkripsi
default adalah Google-managed encryption key. Jika Anda memilih
Customer-managed encryption key (CMEK), Anda juga harus memilih
kunci yang dikelola pelanggan.
Transfer yang Anda siapkan akan berada di region yang sama dengan set data, dan tidak dapat dipindahkan.
Di kolom project_numbers, masukkan nomor project untuk project yang data akses IAM gabungannya ingin Anda ekspor. Jika Anda mencantumkan beberapa nomor project, pisahkan nomor project dengan koma. Anda dapat mengekspor data untuk hingga 10 project sekaligus.
Untuk menemukan nomor project, lakukan hal berikut:
Opsional: Aktifkan notifikasi untuk transfer Anda:
Untuk mengaktifkan notifikasi untuk operasi transfer yang gagal, klik tombol
Notifikasi email.
Saat Anda mengaktifkan opsi ini, administrator transfer akan menerima notifikasi email saat proses transfer gagal.
Pilih organisasi Anda dari menu drop-down, lalu klik Pilih.
Klik Transparansi & kontrol.
Di tabel Grup pemrosesan data, klik IAM. Bagian Transfer
data di halaman ini mencantumkan semua transfer data akses IAM
gabungan untuk organisasi Anda.
Untuk mengelola transfer tertentu, klik nama tampilan transfer.
Untuk melihat semua transfer data dalam project, termasuk transfer data akses IAM gabungan, gunakan BigQuery:
Di konsol Google Cloud , buka halaman Transfer data.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-11 UTC."],[],[],null,["# Export data for role recommendations\n\nThe [IAM role recommender](/policy-intelligence/docs/role-recommendations-overview) uses aggregated\nIAM access data, collected during the usage of services in\nGoogle Cloud, to provide recommendations. This data is primarily used for\ncompliance purposes.\n\nThis page explains how to export that access data to BigQuery using the\n[BigQuery Data Transfer Service](/bigquery-transfer/docs/introduction).\n\nIf you want to export a snapshot of your insights and recommendations, see\n[Export recommendations to\nBigQuery](/policy-intelligence/docs/export-recommendations).\n\nBefore you begin\n----------------\n\n-\n\n\n Enable the IAM, Resource Manager, Recommender, BigQuery, BigQuery Data Transfer Service, and Pub/Sub APIs.\n\n\n [Enable the APIs](https://console.cloud.google.com/flows/enableapi?apiid=iam.googleapis.com,cloudresourcemanager.googleapis.com,recommender.googleapis.com,bigquery.googleapis.com,bigquerydatatransfer.googleapis.com,pubsub.googleapis.com&redirect=https://console.cloud.google.com)\n\n \u003cbr /\u003e\n\n- Read about [role recommendations](/policy-intelligence/docs/role-recommendations-overview).\n\n### Required permissions\n\n\nTo get the permissions that\nyou need to create a data transfer,\n\nask your administrator to grant you the\nfollowing IAM roles:\n\n- [Data Processing Controls Resource Admin](/iam/docs/roles-permissions/dataprocessing#dataprocessing.admin) (`roles/dataprocessing.admin`) on your organization\n- [BigQuery Admin](/iam/docs/roles-permissions/bigquery#bigquery.admin) (`roles/bigquery.admin`) on the project that you will export data to\n- To publish notifications for your transfer to an existing Pub/Sub topic: [Pub/Sub Viewer](/iam/docs/roles-permissions/pubsub#pubsub.viewer) (`roles/pubsub.viewer`) on the project that you will export data to\n- To publish notifications for your topic to a new Pub/Sub topic: [Pub/Sub Editor](/iam/docs/roles-permissions/pubsub#pubsub.editor) (`roles/pubsub.editor`) on the project that you will export data to\n\n\nFor more information about granting roles, see [Manage access to projects, folders, and organizations](/iam/docs/granting-changing-revoking-access).\n\n\nYou might also be able to get\nthe required permissions through [custom\nroles](/iam/docs/creating-custom-roles) or other [predefined\nroles](/iam/docs/roles-overview#predefined).\n\nExport aggregated IAM access data\n---------------------------------\n\nTo export your projects' aggregated IAM access history to\nBigQuery, use the Transparency and Control Center to set up a data\ntransfer:\n\n1. In the Google Cloud console, go to the **Privacy \\& Security** page.\n\n [Go to Privacy \\& Security](https://console.cloud.google.com/projectselector/iam-admin/privacy?supportedpurview=organizationId)\n2. Select your organization from the drop-down list, then click **Select**.\n\n3. Click **Transparency \\& control**.\n\n4. In the **Data processing group** table, click **IAM**.\n\n5. In the **Data sources** section of the page, click\n add **Create transfer**.\n\n6. In the **Project** field, click **Browse** , then select the project that\n you want to export data to. If the project does not have the\n BigQuery Data Transfer Service API enabled, click **Enable API** and wait until the API is\n enabled.\n\n7. Click **Next**.\n\n8. Configure the data transfer:\n\n 1. In the **Display name** field, enter a display name for your data transfer.\n 2. In **Schedule options** section, choose when the data transfer will start\n and how often it will run.\n\n - To choose when to start the transfer, you can leave the default value of **Start now** , or click **Start at a set time**.\n - In the **Repeats** field, choose an option for how often to run the transfer. If you choose an option other than Daily, additional options are available. For example, if you choose **Weekly**, an option appears for you to select the day of the week.\n - For **Start date and run time** , enter the date and time to start the transfer. If you choose **Start now**, this option is disabled.\n 3. In the **Dataset ID** field, choose a BigQuery dataset\n to export the data to.\n\n | **Important:** This dataset must have a location of **United States (US)** or **European Union (EU)**. No other regions are supported.\n\n You can export data to an existing dataset, or create a new dataset:\n - To export data to an existing dataset, click the **Dataset ID** field, then select a dataset from the drop-down list.\n - To export data to a new dataset, click the **Dataset ID** field, click\n **Create new dataset** , and fill out the fields in the **Create\n dataset** pane:\n\n 1. In the **Dataset ID** field, enter an ID for the dataset. Letters, numbers, and underscores are allowed.\n 2. From the **Data location** drop-down list, select either **United\n States (US)** or **European Union (EU)**.\n 3. Optional: Enable [table expiration](/bigquery/docs/managing-tables#updating_a_tables_expiration_time) by selecting **Enable table expiration**.\n 4. Optional: Select an encryption method. The default encryption method is **Google-managed encryption key** . If you select **Customer-managed encryption key (CMEK)** , you must also select a [customer-managed key](/kms/docs/cmek).\n\n The transfer you set up will be in the same region as the dataset, and\n cannot be moved.\n 4. In the **project_numbers** field, enter the project numbers for the\n projects whose aggregated IAM access data you want to\n export. If you list multiple project numbers, separate the project\n numbers with commas. You can export data for up to 10 projects at a time.\n\n To find a project's number, do the following:\n 1. In the Google Cloud console, go to the **Settings** page.\n\n [Go to Settings](https://console.cloud.google.com/projectselector/iam-admin/settings?supportedpurview=project)\n 2. Select your project.\n\n 3. Copy the project ID from the **Project number** field.\n\n 5. Optional: Enable notifications for your transfer:\n\n - To enable notifications for failed transfer runs, click the **Email notifications** toggle. When you enable this option, the transfer administrator receives an email notification when a transfer run fails.\n - To enable [Pub/Sub notifications for your\n transfer](/bigquery-transfer/docs/transfer-run-notifications), click **Select a Pub/Sub\n topic**, then select or create a topic.\n9. Click **Done**.\n\n10. If prompted, allow **IAM Recommender Aggregated Access Transfers** access\n to your Google account.\n\nManage existing data transfers\n------------------------------\n\nYou can view and manage your transfers in the Transparency and Control Center, or\nin BigQuery:\n\n- To view all aggregated IAM access data transfers for your\n organization, use the Transparency and Control Center:\n\n 1. In the Google Cloud console, go to the **Privacy \\& Security** page.\n\n [Go to Privacy \\& Security](https://console.cloud.google.com/projectselector/iam-admin/privacy?supportedpurview=organizationId)\n 2. Select your organization from the drop-down list, then click **Select**.\n\n 3. Click **Transparency \\& control**.\n\n 4. In the **Data processing group** table, click **IAM** . The **Data\n transfers** section of the page lists all aggregated IAM\n access data transfers for your organization.\n\n 5. To manage an individual transfer, click the transfer's display name.\n\n- To view all data transfers in a project, including aggregated\n IAM access data transfers, use BigQuery:\n\n 1. In the Google Cloud console, go to the **Data transfers** page.\n\n [Go to Data transfers](https://console.cloud.google.com/projectselector/bigquery/transfers?supportedpurview=project)\n 2. Select the project that you exported data to.\n\n 3. The **Data transfers** page shows all data transfers for your project,\n including aggregated IAM access data transfers.\n\n 4. To manage an individual transfer, click the transfer's display name.\n\nWhat's next\n-----------\n\n- Learn how to [export a snapshot of your recommendations and\n insights](/policy-intelligence/docs/export-recommendations).\n- Understand [best practices for using role recommendations](/policy-intelligence/docs/role-recommendations-best-practices).\n- Find out how to [review and apply recommendations](/policy-intelligence/docs/review-apply-role-recommendations).\n- Learn how to [disable role recommendations](/recommender/docs/opting-out)."]]