CCAI Insights service account access
CCAI Insights uses per-project service accounts to access audio and transcript files in your Google Cloud Storage bucket during analysis. Each project's service account is automatically created the first time any analysis is created within that project. The service account is automatically given read-only Google Cloud Storage access to the project.
After you create your first analysis, you should see the service account's permissions in your project's IAM settings. If you accidentally remove the service account's permissions or you do not see the permissions, then you can manually give the account access to the correct permissions. The service account always has the form:
service-<project_number>@gcp-sa-contactcenterinsights.iam.gserviceaccount.com
To change an account's permissions manually, navigate to the IAM panel of the GCP Console and give that user the storage.objects.get permission. If you prefer, the service account can also be given per-bucket or per-object access in order to restrict its access.