This page describes changes to the public Identity and Access Management (IAM) permissions for all Generally Available (GA) and Preview services on Google Cloud. This change log can help you maintain and troubleshoot your custom roles.
When a permission is retired or is no longer supported in custom roles, IAM automatically removes the permission from your custom roles. In contrast, when a permission is added, IAM does not automatically add the permission to your custom roles.
For changes that occurred before 2022, see Archived permissions change log.
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your
feed
reader, or add the feed URL directly: https://cloud.google.com/feeds/cloud-iam-permissions-change-log.xml
Upcoming IAM changes for the week of 2023-09-25
Service | Description |
---|---|
Chronicle |
The following permissions have been added to the Chronicle API Restricted Data Access Viewer role (
|
Database Migration Service |
The following permissions have been added to the Database Migration Service Agent role (
|
Dataproc Metastore |
The Dataproc Metastore Metadata Editor role ( |
Dataproc Metastore |
The Dataproc Metastore Metadata Mutate Admin role ( |
Dataproc Metastore |
The Dataproc Metastore Data Owner role ( |
Dataproc Metastore |
The Dataproc Metastore Metadata Query Admin role ( |
Dataproc Metastore |
The Dataproc Metastore Metadata User role ( |
Dataproc Metastore |
The Dataproc Metastore Metadata Viewer role ( |
Network Connectivity Center |
The following permissions have been added to the Network Connectivity Service Agent role (
|
Privileged Access Manager |
The Privileged Access Manager Folder Service Agent role ( |
Privileged Access Manager |
The Privileged Access Manager Organization Service Agent role ( |
Privileged Access Manager |
The Privileged Access Manager Project Service Agent role ( |
Rapid Migration Assessment |
The following permissions have been added to the RMA Service Agent role (
|
Chronicle |
The following permissions have been added:
|
Chronicle |
The following permissions are supported in custom roles:
|
Memorystore for Memcached |
The following permissions have been added:
|
Memorystore for Memcached |
The following permissions have reached General Availability (GA):
|
Dataproc Metastore |
The following permissions have reached General Availability (GA):
|
IAM changes as of 2023-09-22
Service | Description |
---|---|
Vertex AI |
The Colab Enterprise Admin role ( |
Vertex AI |
The Colab Enterprise User role ( |
Vertex AI |
The Notebook Runtime Admin role ( |
Vertex AI |
The Notebook Runtime User role ( |
Anthos Service Mesh |
The following permissions have been added to the Anthos Service Mesh Service Agent role (
|
Dataform |
The Dataform Admin role ( |
Dataform |
The Dataform Editor role ( |
Dataform |
The Dataform Viewer role ( |
Cloud Data Fusion |
The following permissions have been removed from the Cloud Data Fusion Developer role (
|
Cloud Data Fusion |
The following permissions have been removed from the Cloud Data Fusion Operator role (
|
Cloud Data Fusion |
The following permissions have been removed from the Cloud Data Fusion Viewer role (
|
Dataplex |
The Dataplex DataScan Creator role ( |
Basic Role |
The following permissions have been removed from the Viewer role (
|
VM Migration |
The following permissions have been added to the VM Migration Service Agent role (
|
Cloud Workstations |
The following permissions have been added to the Cloud Workstations Admin role (
|
Advisory Notifications |
The following permissions have been added:
|
Advisory Notifications |
The following permissions are supported in custom roles:
|
Vertex AI |
The following permissions have been added:
|
Vertex AI |
The following permissions have reached General Availability (GA):
|
Apigee |
The following permissions have been added:
|
Apigee |
The following permissions are supported in custom roles:
|
Apigee |
The following permissions have reached General Availability (GA):
|
Chronicle |
The following permissions have been added:
|
Chronicle |
The following permissions are supported in custom roles:
|
Compute Engine |
The following permissions have been added:
|
Compute Engine |
The following permissions are supported in custom roles:
|
Compute Engine |
The following permissions have reached General Availability (GA):
|
Dataform |
The following permissions are supported in custom roles:
|
Dataform |
The following permissions have reached General Availability (GA):
|
Dialogflow |
The following permissions have been added:
|
Dialogflow |
The following permissions have reached General Availability (GA):
|
Network Services |
The following permissions have been added:
|
Network Services |
The following permissions are supported in custom roles:
|
Cloud OS Config |
The following permissions have been added:
|
Cloud OS Config |
The following permissions are supported in custom roles:
|
Policy Remediator Manager |
The following permissions have been added:
|
Policy Remediator Manager |
The following permissions are supported in custom roles:
|
Workflows |
The following permissions have been added:
|
Workflows |
The following permissions have reached General Availability (GA):
|
IAM changes as of 2023-09-17
Service | Description |
---|---|
Vertex AI |
The following permissions have been added to the Vertex AI Administrator role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Custom Code Service Agent role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Service Agent role (
|
Vertex AI |
The following permissions have been added to the Vertex AI User role (
|
Anthos Service Mesh |
The following permissions have been added to the Anthos Service Mesh Service Agent role (
|
Assured Workloads |
The Assured Workloads Monitoring Service Agent role ( |
Assured Workloads |
The following permissions have been added to the Assured Workloads Reader role (
|
Bare Metal Solution |
The following permissions have been added to the Bare Metal Solution Editor role (
|
Bare Metal Solution |
The following permissions have been added to the Bare Metal Solution Instances Admin role (
|
Chronicle |
The Chronicle API Restricted Data Access role (
|
Chronicle |
The Chronicle API Restricted Data Access Viewer role (
|
Cloud Controls Partner API |
The Cloud Controls Partner Access Approval Service Agent role ( |
Cloud Controls Partner API |
The following permissions have been added to the Cloud Controls Partner Admin role (
|
Cloud Deploy |
The following permissions have been added to the Cloud Deploy Service Agent role (
|
Commerce Price Management |
The following permissions have been added to the Commerce Price Management Private Offers Admin role (
|
Compute Engine |
The Compute Future Reservation Admin role (
|
Compute Engine |
The Compute Future Reservation User role (
|
Compute Engine |
The Compute Future Reservation Viewer role (
|
Connectors |
The following permissions have been added to the Connectors Endpoint Attachment Admin role (
|
Connectors |
The following permissions have been added to the Connectors Endpoint Attachment Viewer role (
|
Connectors |
The following permissions have been added to the Connectors Managed Zone Admin role (
|
Connectors |
The following permissions have been added to the Connectors Managed Zone Viewer role (
|
Data Catalog |
The following permissions have been added to the DataCatalog Data Steward role (
|
Data Catalog |
The following permissions have been added to the DataCatalog Entry Viewer role (
|
Dataplex |
The following permissions have been added to the Dataplex Metadata Reader role (
|
Dataplex |
The following permissions have been added to the Dataplex Metadata Writer role (
|
Datastore |
The Cloud Datastore Backups Admin role ( |
Datastore |
The Cloud Datastore Backup Schedules Admin role ( |
Datastore |
The Cloud Datastore Backup Schedules Viewer role ( |
Datastore |
The Cloud Datastore Backups Viewer role ( |
Datastore |
The Cloud Datastore Restore Admin role ( |
Discovery Engine |
The following permissions have been added to the Discovery Engine Service Agent role (
|
Sensitive Data Protection |
The DLP Connections Admin role ( |
Sensitive Data Protection |
The DLP Connections Viewer role ( |
Basic Role |
The following permissions have been added to the Editor role (
|
Firebase |
The following permissions have been added to the Firebase Service Management Service Agent role (
|
Multi Cluster Ingress |
The following permissions have been added to the Multi Cluster Ingress Service Agent role (
|
Network Connectivity Center |
The following permissions have been added to the Network Connectivity Service Agent role (
|
Basic Role |
The following permissions have been added to the Owner role (
|
Visual Inspection AI |
The following permissions have been added to the Visual Inspection AI Service Agent role (
|
VM Migration |
The following permissions have been added to the VM Migration Service Agent role (
|
Cloud Workstations |
The following permissions have been added to the Workstations Service Agent role (
|
Vertex AI |
The following permissions have been added:
|
BeyondCorp Enterprise |
The following permissions have been added:
|
BeyondCorp Enterprise |
The following permissions are supported in custom roles:
|
Certificate Manager |
The following permissions have reached General Availability (GA):
|
Cloud AI Companion API |
The following permissions have been added:
|
Cloud AI Companion API |
The following permissions are supported in custom roles:
|
Cloud Deploy |
The following permissions have been added:
|
Cloud Deploy |
The following permissions are supported in custom roles:
|
Cloud Deploy |
The following permissions have reached General Availability (GA):
|
Cloud Quotas |
The following permissions have been added:
|
Cloud Quotas |
The following permissions are supported in custom roles:
|
Commerce Business Enablement |
The following permissions have been added:
|
Commerce Business Enablement |
The following permissions are supported in custom roles:
|
Commerce Price Management |
The following permissions have been added:
|
Compute Engine |
The following permissions have been added:
|
Compute Engine |
The following permissions are supported in custom roles:
|
Compute Engine |
The following permissions have reached General Availability (GA):
|
Contact Center AI Platform |
The following permissions have reached General Availability (GA):
|
Contact Center AI Insights |
The following permissions have been added:
|
Contact Center AI Insights |
The following permissions are supported in custom roles:
|
Contact Center AI Insights |
The following permissions have reached General Availability (GA):
|
Dataproc |
The following permissions have been added:
|
Dataproc |
The following permissions are supported in custom roles:
|
Dataproc |
The following permissions have reached General Availability (GA):
|
Datastore |
The following permissions have been added:
|
Datastore |
The following permissions are supported in custom roles:
|
Datastore |
The following permissions have reached General Availability (GA):
|
Sensitive Data Protection |
The following permissions have been added:
|
Sensitive Data Protection |
The following permissions have reached General Availability (GA):
|
GDC Hardware Management API |
The following permissions have been added:
|
GDC Hardware Management API |
The following permissions are supported in custom roles:
|
Cloud Healthcare API |
The following permissions have been added:
|
Cloud Healthcare API |
The following permissions are supported in custom roles:
|
Payment Gateway issuer switch |
The following permissions have been added:
|
Payment Gateway issuer switch |
The following permissions are supported in custom roles:
|
Network Services |
The following permissions have been added:
|
Network Services |
The following permissions are supported in custom roles:
|
Recommender |
The following permissions have been added:
|
Recommender |
The following permissions are supported in custom roles:
|
Cloud Run |
The following permissions have been added:
|
Cloud Run |
The following permissions are supported in custom roles:
|
Cloud Run |
The following permissions have reached General Availability (GA):
|
Secure Source Manager |
The following permissions have been added:
|
Secure Source Manager |
The following permissions are supported in custom roles:
|
Workload Manager |
The following permissions have been added:
|
IAM changes as of 2023-08-18
Service | Description |
---|---|
Cloud Deploy |
The following permissions have been added to the Cloud Deploy Service Agent role (
|
Contact Center AI Insights |
The following permissions have been added to the Contact Center AI Insights Service Agent role (
|
Dataplex |
The following permissions have been added to the Dataplex DataScan Administrator role (
|
Dataplex |
The following permissions have been added to the Dataplex DataScan Editor role (
|
Eventarc |
The following permissions have been added to the Eventarc Service Agent role (
|
Cloud Storage |
The Storage Object User role ( |
Vertex AI |
The following permissions have been added:
|
Commerce Business Enablement |
The following permissions have been added:
|
Commerce Business Enablement |
The following permissions are supported in custom roles:
|
Contact Center AI Platform |
The following permissions have been added:
|
Contact Center AI Platform |
The following permissions are supported in custom roles:
|
GKE Hub |
The following permissions have been added:
|
GKE Hub |
The following permissions are supported in custom roles:
|
GKE Hub |
The following permissions have reached General Availability (GA):
|
Payment Gateway issuer switch |
The following permissions have been added:
|
Payment Gateway issuer switch |
The following permissions are supported in custom roles:
|
Recommender |
The following permissions have been added:
|
Recommender |
The following permissions are supported in custom roles:
|
IAM changes as of 2023-08-11
Service | Description |
---|---|
Vertex AI |
The following permissions have been added to the Vertex AI Service Agent role (
|
Firebase Remote Config |
The following permissions have been removed from the Cloud Config Service Agent role (
|
Database Migration Service |
The following permissions have been added to the Database Migration Service Agent role (
|
Google Cloud Migration Center |
The following permissions have been added to the Migration Center Admin role (
|
Google Cloud Migration Center |
The following permissions have been added to the Migration Center Viewer role (
|
Serverless Integrations |
The following permissions have been added to the Serverless Integrations Service Agent role (
|
Security Command Center |
The Security Center Attack Paths Reader role ( |
Security Command Center |
The Security Center Resource Value Configurations Editor role ( |
Security Command Center |
The Security Center Resource Value Configurations Viewer role ( |
Security Command Center |
The Security Center Simulations Reader role ( |
Security Command Center |
The Security Center Valued Resources Reader role ( |
BigQuery Reservation API |
The following permissions have been added:
|
Commerce Agreement Publishing |
The following permissions have been added:
|
Compute Engine |
The following permissions have been added:
|
Compute Engine |
The following permissions are supported in custom roles:
|
Compute Engine |
The following permissions have reached General Availability (GA):
|
Contact Center AI Insights |
The following permissions have been added:
|
Contact Center AI Insights |
The following permissions are supported in custom roles:
|
Contact Center AI Insights |
The following permissions have reached General Availability (GA):
|
Datastore |
The following permissions have been added:
|
Datastore |
The following permissions have reached General Availability (GA):
|
Recommender |
The following permissions have been added:
|
Recommender |
The following permissions are supported in custom roles:
|
Security Command Center |
The following permissions have been added:
|
Security Command Center |
The following permissions are supported in custom roles:
|
Security Command Center |
The following permissions have reached General Availability (GA):
|
IAM changes as of 2023-08-04
Service | Description |
---|---|
Cloud Billing |
The following permissions have been added to the Billing Account Administrator role (
|
Firebase Remote Config |
The following permissions have been added to the Cloud Config Service Agent role (
|
Google Cloud Support |
The following permissions have been added to the Tech Support Editor role (
|
Dialogflow |
The following permissions have been added to the Dialogflow Service Agent role (
|
Discovery Engine |
The following permissions have been added to the Discovery Engine Admin role (
|
Eventarc |
The following permissions have been added to the Eventarc Service Agent role (
|
GKE Dataplane Management |
The Warp Run Service Agent role ( |
Cloud Integrations |
The following permissions have been added to the Application Integration Service Agent role (
|
Recommender |
The Recommendations Exporter role ( |
Workload Manager |
The following permissions have been added to the Workload Manager Service Agent role (
|
Cloud Workstations |
The following permissions have been added to the Cloud Workstations User role (
|
Apigee |
The following permissions have been added:
|
Apigee |
The following permissions are supported in custom roles:
|
Apigee |
The following permissions have reached General Availability (GA):
|
Content Warehouse |
The following permissions have been added:
|
Content Warehouse |
The following permissions have reached General Availability (GA):
|
Discovery Engine |
The following permissions have been added:
|
Discovery Engine |
The following permissions are supported in custom roles:
|
Network Connectivity Center |
The following permissions are supported in custom roles:
|
Network Connectivity Center |
The following permissions have reached General Availability (GA):
|
Recommender |
The following permissions have reached General Availability (GA):
|
IAM changes as of 2023-07-28
Service | Description |
---|---|
Discovery Engine |
The following permissions have been added to the Discovery Engine Service Agent role (
|
Apigee |
The following permissions have been added:
|
Apigee |
The following permissions are supported in custom roles:
|
Apigee |
The following permissions have reached General Availability (GA):
|
BigQuery |
The following permissions have been added:
|
BigQuery |
The following permissions are supported in custom roles:
|
Compute Engine |
The following permissions are supported in custom roles:
|
Compute Engine |
The following permissions have reached General Availability (GA):
|
IAM changes as of 2023-07-21
Service | Description |
---|---|
Vertex AI |
The Vertex AI Notebook Service Agent role ( |
Analytics Hub |
The Analytics Hub Subscription Owner role ( |
Assured Workloads |
The following permissions have been added to the Assured Workloads Editor role (
|
Bare Metal Solution |
The OS Images Viewer role ( |
Cloud Billing |
The following permissions have been added to the Billing Account Administrator role (
|
Cloud Asset Inventory |
The Effective Policies Service Agent role ( |
Cloud Build |
The Cloud Build Connection Admin role ( |
Cloud Build |
The Cloud Build Connection Viewer role ( |
Cloud Build |
The Cloud Build Read Only Token Accessor role ( |
Cloud Build |
The Cloud Build Token Accessor role ( |
Commerce Business Enablement |
The following permissions have been added to the Commerce Business Enablement PaymentConfig Admin role (
|
Commerce Business Enablement |
The following permissions have been added to the Commerce Business Enablement PaymentConfig Viewer role (
|
Discovery Engine |
The following permissions have been added to the Discovery Engine Service Agent role (
|
Basic Role |
The following permissions have been added to the Editor role (
|
Basic Role |
The following permissions have been added to the Viewer role (
|
Analytics Hub |
The following permissions have been added:
|
Analytics Hub |
The following permissions are supported in custom roles:
|
Analytics Hub |
The following permissions have reached General Availability (GA):
|
Bare Metal Solution |
The following permissions have been added:
|
Bare Metal Solution |
The following permissions are supported in custom roles:
|
Bare Metal Solution |
The following permissions have reached General Availability (GA):
|
Cloud Billing |
The following permissions have been added:
|
Cloud Billing |
The following permissions are supported in custom roles:
|
Cloud Billing |
The following permissions have reached General Availability (GA):
|
Cloud Build |
The following permissions have been added:
|
Cloud Build |
The following permissions are supported in custom roles:
|
Cloud Build |
The following permissions have reached General Availability (GA):
|
Compute Engine |
The following permissions have been added:
|
Compute Engine |
The following permissions have reached General Availability (GA):
|
Data Catalog |
The following permissions have been added:
|
Data Catalog |
The following permissions are supported in custom roles:
|
Google Cloud NetApp Volumes |
The following permissions have been added:
|
Google Cloud NetApp Volumes |
The following permissions are supported in custom roles:
|
Policy Simulator |
The following permissions have been added:
|
Recommender |
The following permissions have been added:
|
Recommender |
The following permissions are supported in custom roles:
|
Recommender |
The following permissions have reached General Availability (GA):
|
IAM changes as of 2023-07-14
Service | Description |
---|---|
Vertex AI |
The following permissions have been added to the Vertex AI Administrator role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Custom Code Service Agent role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Feature Store EntityType owner role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Feature Store Admin role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Feature Store Data Viewer role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Feature Store Data Writer role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Service Agent role (
|
Vertex AI |
The following permissions have been added to the Vertex AI User role (
|
Vertex AI |
The following permissions have been added to the Vertex AI Viewer role (
|
Backup and Disaster Recovery |
The following permissions have been added to the Backup and DR Mount User role (
|
Backup and Disaster Recovery |
The following permissions have been added to the Backup and DR Restore User role (
|
Backup and Disaster Recovery |
The following permissions have been added to the Backup and DR Service Agent role (
|
Compute Engine |
The following permissions have been removed from the Compute Engine Service Agent role (
|
Connectors |
The Connectors Event Subscriptions Admin role ( |
Connectors |
The Connectors Event Subscriptions Viewer role ( |
Basic Role |
The following permissions have been added to the Editor role (
|
Network Connectivity Center |
The following permissions have been added to the Network Connectivity Service Agent role (
|
Basic Role |
The following permissions have been added to the Owner role (
|
Basic Role |
The following permissions have been added to the Viewer role (
|
Visual Inspection AI |
The following permissions have been added to the Visual Inspection AI Service Agent role (
|
Vertex AI |
The following permissions have been added:
|
Commerce Offer Catalog |
The following permissions have been added:
|
Commerce Offer Catalog |
The following permissions are supported in custom roles:
|
Connectors |
The following permissions have been added:
|
Connectors |
The following permissions have reached General Availability (GA):
|
Data Catalog |
The following permissions have been added:
|
Discovery Engine |
The following permissions have been added:
|
Discovery Engine |
The following permissions are supported in custom roles:
|
Network Connectivity Center |
The following permissions have been added:
|
Network Connectivity Center |
The following permissions are supported in custom roles:
|
Network Connectivity Center |
The following permissions have reached General Availability (GA):
|
Personalized Service Health |
The following permissions have been added:
|
Personalized Service Health |
The following permissions are supported in custom roles:
|
IAM changes as of 2023-06-30
Service | Description |
---|---|
Cloud Key Management Service |
The Cloud KMS Expert Raw AES-CBC Key Manager role ( |
Cloud Key Management Service |
The Cloud KMS Expert Raw AES-CTR Key Manager role ( |
Eventarc |
The following permissions have been added to the Eventarc Service Agent role (
|
Network Connectivity Center |
The Group User role ( |
Workload Certificate |
The following permissions have been added to the Workload Certificate Service Agent role (
|
Workload Manager |
The following permissions have been added to the Workload Manager Admin role (
|
BigQuery |
The following permissions have been added:
|
BigQuery |
The following permissions are supported in custom roles:
|
Cloud Key Management Service |
The following permissions have been added:
|
Cloud Key Management Service |
The following permissions have reached General Availability (GA):
|
Translation |
The following permissions have been added:
|
Translation |
The following permissions are supported in custom roles:
|
Translation |
The following permissions have reached General Availability (GA):
|
Cloud Config Manager API |
The following permissions have been added:
|
Cloud Config Manager API |
The following permissions are supported in custom roles:
|
Network Connectivity Center |
The following permissions have been added:
|
Network Connectivity Center |
The following permissions are supported in custom roles:
|
Network Connectivity Center |
The following permissions have reached General Availability (GA):
|
Network Security |
The following permissions have been added:
|
Cloud Spanner |
The following permissions are supported in custom roles:
|
IAM changes as of 2023-06-23
Service | Description |
---|---|
Access Approval |
The Access Approval Approver role ( |
Access Approval |
The Access Approval Config Editor role ( |
Access Approval |
The Access Approval Invalidator role ( |
Access Approval |
The Access Approval Viewer role ( |
Compute Engine |
The following permissions have been added to the Compute Security Admin role (
|
Security Command Center |
The following permissions have been removed from the Security Center Control Service Agent role (
|
Security Command Center |
The following permissions have been removed from the Security Health Analytics Service Agent role (
|