Overview of Security and Privacy Advisory notifications

The Advisory Notifications service uses Security and Privacy Advisory notifications to inform you of critical security and privacy events.

Who receives Security and Privacy Advisory notifications

Advisory Notifications contacts different users depending on whether the notification is sent to an organization or project.

Organization contacts

Advisory Notifications integrates with Essential Contacts to identify which users should receive notifications. Essential Contacts lets you control who receives notifications by providing a list of contacts. Security and privacy advisory notifications are sent to contacts in the Security and All categories at the organization level. For more information, see Managing contacts for notifications.

If Essential Contacts hasn't been configured, Advisory Notifications sends notifications to the default contacts, which are determined by Identity and Access Management roles.

If one or more users have been granted the Organization Administrator role (roles/resourcemanager.organizationAdmin) on the organization, only they are contacted. If no users have been granted the Organization Administrator role, then Advisory Notifications moves on to the next role in the hierarchy and determines if one or more users have been granted the Owner basic role (roles/owner) on any project owned by the organization. If any are found, only they are contacted. Finally, if no users have been granted the Organization Administrator or Project Owner role, Advisory Notifications contacts any users who have been granted the Billing Account Administrator role (roles/billing.admin) on any billing account owned by the organization.

Project contacts

When a notification is sent to a project, Advisory Notifications contacts Identity and Access Management roles in the following order. If one or more users have been granted the Owner basic role (roles/owner) on the project, only they are contacted. Otherwise, if no users have been granted the Project Owner role, Advisory Notifications contacts any users who have been granted the Billing Account Administrator role (roles/billing.admin) on the billing account associated with the project, if it exists.

Opting out

Security and Privacy Advisory notifications are mandatory. You cannot opt out of receiving these notifications.

What's next