Enabling Access Transparency
This page explains how you can enable and disable Access Transparency for your Google Cloud organization.
Requirements for enabling Access Transparency
To enable Access Transparency for a Google Cloud project, the project must reside in an organization.
Configuring Access Transparency using the Google Cloud console
To enable Access Transparency, do the following:
Check your organization-level permissions:
Go to the Identity and Access Management page on the Google Cloud console.
If you're prompted, select the Google Cloud organization in the selector menu.
Verify that you have the IAM role Access Transparency Admin (
roles/axt.admin
) listed in the Role column for your Principal listing under the organization. Roles added to the project level do not grant sufficient permissions to enable Access Transparency.
Select any Google Cloud project within the organization using the selector menu.
Access Transparency is configured on a Google Cloud project page but Access Transparency is enabled for the entire organization.
Make sure that your Google Cloud project is subscribed to the Standard, Enhanced, or Premium support package.
Verify that the project is associated with a billing account.
You aren't charged for Access Transparency logs but you can configure Access Transparency in the Google Cloud console only from a project that is associated with a billing account. To verify that the project is associated with a billing account, do the following:
Go to the Billing page on the Google Cloud console.
If you see the message This project is not associated with a billing account, then either select a different project or see instructions for Changing the billing account for a project.
Go to the IAM & Admin > Settings page.
- Click the Enable Access Transparency button.
Disabling Access Transparency
To disable Access Transparency, contact Google Cloud Support.
What's next
For information about the pricing of Access Transparency, see Pricing.