本页介绍如何使用 Identity and Access Management (IAM) 控制 CTS 访问和权限。
概览
Google Cloud Platform 提供了 Identity and Access Management (IAM),借助此服务,您可以授予对特定 Google Cloud Platform 资源的更精细的访问权限,并防止对其他资源进行不必要的访问。本页面介绍了 Cloud Talent Solution IAM 角色和权限。如需详细了解 Google Cloud Platform IAM,请参阅 IAM 文档。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-18。"],[],[],null,["# Identity and Access Management (IAM)\n\nThis page describes how you can control CTS access and\npermissions using Identity and Access Management (IAM).\n\nOverview\n--------\n\nGoogle Cloud Platform offers Identity and Access Management (IAM), which lets you give\nmore granular access to specific Google Cloud Platform resources and prevents unwanted\naccess to other resources. This page describes the Cloud Talent Solution IAM\nroles and permissions. For a detailed description of Google Cloud Platform\nIAM, see the [IAM documentation](/iam/docs).\n\nCTS provides a set of [predefined roles](#roles) designed\nto help you easily control access to your CTS resources.\nYou can also create your own [custom roles](#custom-roles), if the predefined\nroles do not provide the sets of permissions you need. In addition, the older\nbasic roles (Editor, Viewer, and Owner) are also still available to you,\nalthough they do not provide the same fine-grained control as the\nCTS roles. In particular, the basic roles provide\naccess to resources across Google Cloud Platform rather than just for\nCTS. See the [basic roles](/iam/docs/understanding-roles#basic)\ndocumentation for more information.\n\nThe table below outlines the predefined roles available for Job Search.\n\nPredefined roles\n----------------\n\nCTS provides predefined roles you can use to provide\nfiner-grained permissions to principals.\nThe role you grant to a principal controls what actions the\nprincipal can take. Principals can be individuals, groups, or service accounts.\n\nYou can grant multiple roles to the same principal, and you can change\nthe roles granted to a principal at any time, provided you have the\npermissions to do so.\n\nThe broader roles include the more narrowly defined roles. For example, the\njobsEditor role includes all of the permissions of the\njobsViewer role, along with the addition permissions of the\njobsEditor role.\n\nThe basic roles (Owner, Editor, Viewer) provide permissions across\nGoogle Cloud Platform. The roles specific to CTS provide only\nCTS permissions, except for the following\nGCP permissions, which are needed for general\nGCP usage:\n\n- `resourcemanager.projects.get`\n- `resourcemanager.projects.list`\n- `serviceusage.services.list`\n- `serviceusage.services.get`\n\nThe following table lists the predefined roles available for\nCTS, along with their permissions:\n\nManaging CTS IAM\n----------------\n\nYou can get and set IAM policies and roles using the Google Cloud Platform\nConsole, IAM API methods, or the Cloud Talent Solution APIs themselves. For more\ninformation, see\n[Granting, Changing, and Revoking Access](/iam/docs/granting-changing-revoking-access).\n\nWhat's next\n-----------\n\n- Learn how to [grant and revoke access](/iam/docs/granting-changing-revoking-access).\n- Learn more about [IAM](/iam/docs).\n- Learn more about [basic roles](/iam/docs/understanding-roles#basic).\n- Learn more about [custom roles](/iam/docs/understanding-custom-roles)."]]