[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-29。"],[],[],null,["# Control access with IAM\n=======================\n\nCloud Profiler controls access to profiling activities\nin Google Cloud projects by using [Identity and Access Management (IAM)](/iam/docs/overview)\nroles and permissions.\n| **Note:** Cloud Profiler doesn't support [Workload identity federation](/iam/docs/workload-identity-federation). You can't use Cloud Profiler in an environment that relies exclusively on Workload identity federation for authentication.\n\nOverview\n--------\n\nTo use Cloud Profiler for a Google Cloud project, you must have the\nappropriate IAM permissions on that project.\n\nPermissions are not granted directly to users; permissions are instead\ngranted indirectly through roles, which group permissions.\nFor more information on these concepts, see the\nIAM documentation on [roles, permissions, and related\nconcepts](/iam/docs/overview#concepts_related_to_access_management).\n\nPermissions and roles\n---------------------\n\nThis section summarizes the permissions and roles that apply to\nProfiler.\n\n### Permissions\n\nThe following table lists the permissions required for profiling activities:\n\n### Roles\n\nIAM roles include permissions and can be assigned to users,\ngroups, and service accounts. The following table lists the roles for\nProfiler:\n\nTo learn how to assign Identity and Access Management roles to a user or service account, see\n[Managing Policies](/iam/docs/managing-policies)."]]