IamPolicyAnalysisQuery

IAM policy analysis query message.

JSON representation
{
  "parent": string,
  "resourceSelector": {
    object (ResourceSelector)
  },
  "identitySelector": {
    object (IdentitySelector)
  },
  "accessSelector": {
    object (AccessSelector)
  }
}
Fields
parent

string

Required. The relative name of the root asset. Only resources and IAM policies within the parent will be analyzed. This can only be an organization number (such as "organizations/123") or a folder number (such as "folders/123").

resourceSelector

object (ResourceSelector)

Optional. Specifies a resource for analysis. Leaving it empty means ANY.

identitySelector

object (IdentitySelector)

Optional. Specifies an identity for analysis. Leaving it empty means ANY.

accessSelector

object (AccessSelector)

Optional. Specifies roles or permissions for analysis. Leaving it empty means ANY.

ResourceSelector

Specifies the resource to analyze for access policies, which may be set directly on the resource, or on ancestors such as organizations, folders or projects. At least one of ResourceSelector, IdentitySelector or AccessSelector must be specified in a request.

JSON representation
{
  "fullResourceName": string
}
Fields
fullResourceName

string

Required. The full resource name .

IdentitySelector

Specifies an identity for which to determine resource access, based on roles assigned either directly to them or to the groups they belong to, directly or indirectly.

JSON representation
{
  "identity": string
}
Fields
identity

string

Required. The identity appear in the form of members in IAM policy binding.

AccessSelector

Specifies roles and/or permissions to analyze, to determine both the identities possessing them and the resources they control. If multiple values are specified, results will include identities and resources matching any of them.

JSON representation
{
  "roles": [
    string
  ],
  "permissions": [
    string
  ]
}
Fields
roles[]

string

Optional. The roles to appear in result.

permissions[]

string

Optional. The permissions to appear in result.