Stay organized with collections
Save and categorize content based on your preferences.
This page documents production updates to Policy Intelligence.
Check this page for announcements about new or updated features, bug fixes,
known issues, and deprecated functionality.
You can see the latest product updates for all of Google Cloud on the
Google Cloud page, browse and filter all release notes in the
Google Cloud console,
or programmatically access release notes in
BigQuery.
The Organization Policy recommender generates insights and organization policy recommendations to restrict the creation and upload of service account keys. This feature is available in Preview.
Activity Analyzer checks service activation and quota for the project that you're using to analyze access (the client project) instead of the projects whose resources you're analyzing (the resource projects). As a result, you only need to enable the Policy Analyzer API in your client project, not in your resource projects.
May 17, 2024
The IAM recommender generates policy insights and role recommendations for identities in Workload Identity Federation pools. To learn more, see Availability. This feature is available in Preview.
During Preview, the actual observation period might be shorter than the observation period listed in recommendations for these principals.
Policy Troubleshooter for IAM currently doesn't fetch tags for regional resources, such as Google Kubernetes Engine (GKE) clusters. As a result, if you have IAM policies with tag-based conditions and you try to use Policy Troubleshooter to troubleshoot access to regional resources, you might get inaccurate results. Our engineering team is working to resolve this issue.
February 26, 2024
The IAM recommender offers role recommendations for BigQuery datasets. Role recommendations help you reduce excess permissions by suggesting role changes based on actual permission usage. This feature is available in Preview.
Policy Analyzer now offers organization policy analysis. Policy Analyzer helps you get more information about the resources affected by an organization policy constraint. This feature is available in Preview.
November 10, 2022
Role recommendations and policy insights for Cloud Storage buckets are now generally available. Additionally, you can now use the Google Cloud console to review bucket-level role recommendations and policy insights.
Recommender now offers role recommendations for Cloud Storage buckets. Role recommendations help you reduce excess permissions by suggesting role changes based on actual permission usage. This feature is available in Preview.
July 01, 2022
Lateral movement insights, which identify roles that allow a service account in one project to impersonate a service account in another project, are now generally available.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-28 UTC."],[],[],null,["# Policy Intelligence release notes\n\nThis page documents production updates to Policy Intelligence.\nCheck this page for announcements about new or updated features, bug fixes,\nknown issues, and deprecated functionality.\n\nYou can see the latest product updates for all of Google Cloud on the\n[Google Cloud](/release-notes) page, browse and filter all release notes in the\n[Google Cloud console](https://console.cloud.google.com/release-notes),\nor programmatically access release notes in\n[BigQuery](https://console.cloud.google.com/bigquery?p=bigquery-public-data&d=google_cloud_release_notes&t=release_notes&page=table).\n\nJuly 01, 2025\n-------------\n\n[Policy Simulator for Organization Policy](https://cloud.google.com/policy-intelligence/docs/test-organization-policies) is now [generally available (GA)](https://cloud.google.com/products#product-launch-stages).\n\nDecember 19, 2024\n-----------------\n\nThe [Organization Policy recommender](https://cloud.google.com/policy-intelligence/docs/organization-policy-recommendations-overview) generates insights and organization policy recommendations to restrict the creation and upload of service account keys. This feature is available in [Preview](https://cloud.google.com/products#product-launch-stages).\n\nDecember 16, 2024\n-----------------\n\nYou can use [Policy Simulator for principal access boundary policies](https://cloud.google.com/policy-intelligence/docs/pab-simulator-overview) to simulate changes to principal access boundary policies before you apply them. This feature is available in [Preview](https://cloud.google.com/products#product-launch-stages).\n\nDecember 11, 2024\n-----------------\n\nYou can use [Policy Simulator for deny policies](https://cloud.google.com/policy-intelligence/docs/deny-simulator-overview) to simulate changes to deny policies before you apply them. This feature is available in [Preview](https://cloud.google.com/products#product-launch-stages).\n\nAugust 15, 2024\n---------------\n\nThe IAM recommender generates policy insights and role recommendations for the following identities:\n\n- All identities in a workload identity pool\n- Single identity in a workload identity pool\n- All identities in a workforce identity pool\n- Single identity in a workforce identity pool\n- All Google Kubernetes Engine Pods that use a specific Kubernetes service account\n\nTo learn more, see [Availability](https://cloud.google.com/policy-intelligence/docs/role-recommendations-overview#availability). This feature is generally available.\n\nJuly 03, 2024\n-------------\n\nYou can use Policy Troubleshooter to [troubleshoot principal access boundary policies](https://cloud.google.com/policy-intelligence/docs/troubleshoot-access). This feature is available in [Preview](https://cloud.google.com/products#product-launch-stages).\n\nMay 31, 2024\n------------\n\n[Activity Analyzer](https://cloud.google.com/policy-intelligence/docs/activity-analyzer-service-account-authentication) checks service activation and quota for the project that you're using to analyze access (the client project) instead of the projects whose resources you're analyzing (the resource projects). As a result, you only need to enable the [Policy Analyzer API](https://cloud.google.com/policy-intelligence/docs/reference/policyanalyzer/rest) in your client project, not in your resource projects.\n\nMay 17, 2024\n------------\n\nThe IAM recommender generates policy insights and role recommendations for identities in Workload Identity Federation pools. To learn more, see [Availability](https://cloud.google.com/policy-intelligence/docs/role-recommendations-overview#availability). This feature is available in Preview.\n\nDuring Preview, the actual [observation period](https://cloud.google.com/policy-intelligence/docs/role-recommendations-overview#observation-period) might be shorter than the observation period listed in recommendations for these principals.\n\nMay 03, 2024\n------------\n\nSome Policy Intelligence features are only available for customers with [organization-level activations of Security Command Center](https://cloud.google.com/security-command-center/pricing#organization-level-activations). For more information, see [Billing questions](https://cloud.google.com/policy-intelligence/docs/billing-questions).\n\nApril 01, 2024\n--------------\n\n[Policy Troubleshooter for IAM](https://cloud.google.com/policy-intelligence/docs/troubleshoot-access) currently doesn't fetch tags for regional resources, such as [Google Kubernetes Engine (GKE) clusters](https://cloud.google.com/kubernetes-engine/docs/concepts/regional-clusters). As a result, if you have IAM policies with [tag-based conditions](https://cloud.google.com/iam/docs/tags-access-control) and you try to use Policy Troubleshooter to troubleshoot access to regional resources, you might get inaccurate results. Our engineering team is working to resolve this issue.\n\nFebruary 26, 2024\n-----------------\n\nThe IAM recommender offers [role recommendations for BigQuery datasets](https://cloud.google.com/policy-intelligence/docs/review-apply-role-recommendations-datasets). Role recommendations help you reduce excess permissions by suggesting role changes based on actual permission usage. This feature is available in Preview.\n\nJanuary 12, 2024\n----------------\n\nThe requirement that customers have [organization-level activations of Security Command Center](https://cloud.google.com/security-command-center/pricing#organization-level-activations) to use certain Policy Intelligence features has been delayed until April 29, 2024. For more information about which features are affected by this change, see [Billing questions](https://cloud.google.com/policy-intelligence/docs/billing-questions).\n\nNovember 07, 2023\n-----------------\n\nYou can use the Google Cloud console to [analyze organization policies](https://cloud.google.com/policy-intelligence/docs/analyze-organization-policies). This feature is available in Preview.\n\nSeptember 28, 2023\n------------------\n\nAfter January 15, 2024, some Policy Intelligence features will only be available for customers with [organization-level activations of Security Command Center](https://cloud.google.com/security-command-center/pricing#organization-level-activations). For more information, see [Billing questions](https://cloud.google.com/policy-intelligence/docs/billing-questions). \nUsing [Policy Troubleshooter](https://cloud.google.com/policy-intelligence/docs/troubleshoot-access) to troubleshoot deny policies is generally available.\n\nJuly 05, 2023\n-------------\n\nYou can use Policy Troubleshooter to [troubleshoot deny policies](https://cloud.google.com/policy-intelligence/docs/troubleshoot-access). This feature is in [Preview](https://cloud.google.com/products#product-launch-stages).\n\nJanuary 24, 2023\n----------------\n\n[Configurable IAM recommendations](https://cloud.google.com/policy-intelligence/docs/configure-role-recommendations) are now generally available. With configurable IAM recommendations, you can set the [minimum observation period](https://cloud.google.com/policy-intelligence/docs/role-recommendations-overview#observation-period) for the IAM recommender to 30 or 60 days instead of the default period of 90 days.\n\nDecember 12, 2022\n-----------------\n\nYou can now use the Google Cloud console to [write IAM policy analysis results to BigQuery](https://cloud.google.com/policy-intelligence/docs/policy-analyzer-write-to-bigquery). This feature is generally available.\n\nDecember 05, 2022\n-----------------\n\nYou can now set the [minimum observation period](https://cloud.google.com/policy-intelligence/docs/role-recommendations-overview#observation-period) for the IAM recommender to 30 or 60 days instead of the default period of 90 days. For more information, see [Configure role recommendation generation](https://cloud.google.com/policy-intelligence/docs/configure-role-recommendations). This feature is available in Preview.\n\nNovember 18, 2022\n-----------------\n\nPolicy Analyzer now offers [organization policy analysis](https://cloud.google.com/policy-intelligence/docs/analyze-organization-policies). Policy Analyzer helps you get more information about the resources affected by an organization policy constraint. This feature is available in Preview.\n\nNovember 10, 2022\n-----------------\n\n[Role recommendations](https://cloud.google.com/policy-intelligence/docs/review-apply-role-recommendations-buckets) and [policy insights](https://cloud.google.com/policy-intelligence/docs/policy-insights-buckets) for Cloud Storage buckets are now generally available. Additionally, you can now use the Google Cloud console to review bucket-level role recommendations and policy insights.\n\nAugust 30, 2022\n---------------\n\nThe user interface for [Policy Troubleshooter](https://cloud.google.com/policy-intelligence/docs/troubleshoot-access) in the Cloud console has been updated to improve usability. To view the new user interface, visit the [Policy Troubleshooter page in the Cloud console](https://console.cloud.google.com/iam-admin/troubleshooter).\n\nJuly 08, 2022\n-------------\n\nRecommender now offers [role recommendations for Cloud Storage buckets](https://cloud.google.com/policy-intelligence/docs/review-apply-role-recommendations-buckets). Role recommendations help you reduce excess permissions by suggesting role changes based on actual permission usage. This feature is available in Preview.\n\nJuly 01, 2022\n-------------\n\n[Lateral movement insights](https://cloud.google.com/policy-intelligence/docs/role-recommendations-overview#lateral-movement-insights), which identify roles that allow a service account in one project to impersonate a service account in another project, are now generally available.\n\nJune 27, 2022\n-------------\n\nIn the Cloud console, [Policy Troubleshooter for IAM allow policies](https://cloud.google.com/policy-intelligence/docs/access-troubleshooters) now reports if there are deny policies that could affect a principal's access."]]