Stay organized with collections
Save and categorize content based on your preferences.
When an organization resource is created, all users in your domain are granted the
Billing Account Creator and Project Creator roles by default. These
default roles allow your users to start using Google Cloud immediately, but
are not intended for use in regular operation of your organization resource.
This page describes how to designate a Billing Account Creator and
Project Creator for regular operations, and how to remove roles that were
assigned by default to the organization resource.
Adding a Billing Account Creator and Project Creator
To migrate existing billing accounts into an organization resource, a user must have the
Billing Account Creator IAM role. Users with the Project Creator
role are able to create and manage Project resources. To add additional Billing
Account Creators and Project Creators, follow these steps:
Console
To grant the Billing Account Creator or Project Creator role using
Google Cloud console:
Go to the Manage resources page in the Google Cloud console:
On the Organization drop-down list, select your organization resource.
Select the check box for the organization resource. If you do not have a
Folder resource, the organization resource will not be visible. To
continue, see the instructions for granting roles through the
IAM
page.
On the right side Info Panel, under Permissions, enter the
email address of the principal you want to add.
In the Select a role drop-down, select
Billing > Billing Account Creator or Resource Manager > Project Creator.
Click Add. A dialog will appear to confirm the addition or update of
the principal's new role.
Removing default roles from the organization resource
After you designate your own Billing Account Creator and Project Creator roles,
you can remove these roles from the organization resource to restrict those
permissions to specifically designated users. To remove roles from the
organization resource, follow these steps:
Console
To remove the roles assigned to users by default using the Google Cloud console:
Go to the Manage resources page in the Google Cloud console:
Click the Organization drop-down list at the top of the page and then select
your organization resource.
Select the check box for the organization resource for which you want to
change permissions. If you do not have a Folder resource, the
organization resource will not be visible. To continue, see the
instructions for revoking roles through the
IAM
page.
On the right side Info Panel, under Permissions, click to expand the role
from which you want to remove users.
Under the expanded role list, next to the principal you want to remove from
the role, click remove.
On the Remove principal? dialog that appears, click Remove to confirm removing the role from the specified principal.
Repeat the above two steps for each role you want to remove.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-29 UTC."],[],[],null,["# Managing default organization roles\n\nWhen an organization resource is created, all users in your domain are granted the **Billing Account Creator** and **Project Creator** roles by default. These default roles allow your users to start using Google Cloud immediately, but are not intended for use in regular operation of your organization resource.\n\n\u003cbr /\u003e\n\nThis page describes how to designate a **Billing Account Creator** and\n**Project Creator** for regular operations, and how to remove roles that were\nassigned by default to the organization resource.\n\nAdding a Billing Account Creator and Project Creator\n----------------------------------------------------\n\nTo migrate existing billing accounts into an organization resource, a user must have the\nBilling Account Creator IAM role. Users with the Project Creator\nrole are able to create and manage Project resources. To add additional Billing\nAccount Creators and Project Creators, follow these steps: \n\n### Console\n\nTo grant the Billing Account Creator or Project Creator role using\nGoogle Cloud console:\n\n1. Go to the **Manage resources** page in the Google Cloud console:\n\n [Open the Manage resources page](https://console.cloud.google.com/cloud-resource-manager)\n\n \u003cbr /\u003e\n\n2. On the **Organization** drop-down list, select your organization resource.\n\n3. Select the check box for the organization resource. If you do not have a\n Folder resource, the organization resource will not be visible. To\n continue, see the instructions for granting roles through the\n [IAM](/iam/docs/granting-changing-revoking-access#grant_access)\n page.\n\n4. On the right side **Info Panel** , under **Permissions**, enter the\n email address of the principal you want to add.\n\n5. In the **Select a role** drop-down, select\n **Billing \\\u003e Billing Account Creator** or **Resource Manager \\\u003e Project Creator**.\n\n6. Click **Add**. A dialog will appear to confirm the addition or update of\n the principal's new role.\n\nRemoving default roles from the organization resource\n-----------------------------------------------------\n\nAfter you designate your own Billing Account Creator and Project Creator roles,\nyou can remove these roles from the organization resource to restrict those\npermissions to specifically designated users. To remove roles from the\norganization resource, follow these steps: \n\n### Console\n\nTo remove the roles assigned to users by default using the Google Cloud console:\n\n1. Go to the **Manage resources** page in the Google Cloud console:\n\n [Open the Manage resources page](https://console.cloud.google.com/cloud-resource-manager)\n\n \u003cbr /\u003e\n\n2. Click the **Organization** drop-down list at the top of the page and then select\n your organization resource.\n\n3. Select the check box for the organization resource for which you want to\n change permissions. If you do not have a Folder resource, the\n organization resource will not be visible. To continue, see the\n instructions for revoking roles through the\n [IAM](/iam/docs/granting-changing-revoking-access#revoke_access)\n page.\n\n4. On the right side **Info Panel** , under **Permissions**, click to expand the role\n from which you want to remove users.\n\n5. Under the expanded role list, next to the principal you want to remove from\n the role, click remove.\n\n6. On the **Remove principal?** dialog that appears, click **Remove** to confirm removing the role from the specified principal.\n\n7. Repeat the above two steps for each role you want to remove."]]