Grant data profiling access to a service agent

This page describes how to grant the required role to a service agent so that it can be used to profile data at the organization or folder level.

Perform these tasks if both of the following conditions apply:

  • You created a scan configuration at the organization or folder level.
  • Cloud DLP isn't generating any data profiles for the scan configuration. When you view the configuration details, you see the following error message:

    None of the driver projects (PROJECT_ID) have MISSING_PERMISSION
    permission for organizations/ORGANIZATION_ID.

Get the ID of the service agent

Get the service agent ID that is associated with your scan configuration:

  1. Go to the data profile configurations list.

    Go to data profile configurations

  2. Select your scan configuration.

  3. On the details page that opens, copy the service agent ID. This ID is in the format of an email address.

  4. Give your service agent ID to a Google Cloud administrator, who must then grant data profiling access to the service agent.

Grant data profiling access

This section describes how to grant access to a service agent so that it can be used to profile data at the organization or folder level.

Only someone who has the permissions to grant IAM roles to a service agent, such as a Google Cloud administrator, can perform these steps.

To complete these steps, you need the ID of the service agent that you want to grant data profiling access to.

To grant data profiling access at the organization or folder level, follow these steps:

  1. In the Cloud Console, go to the IAM page.

    Go to IAM

  2. If you're in the project view, switch to the organization view. On the toolbar, click the project selector, and select your organization.

    Screenshot of the project selector on the toolbar

  3. Click Add.

  4. In the New principals field, enter the service agent ID.

  5. Grant the DLP Organization Data Profiles Driver role.

  6. Click Save.