This page lists the IAM roles and permissions for Confidential Computing. To search through all roles and permissions, see the role and permission index.
Confidential Computing roles
| Role | Permissions | 
|---|---|
Confidential Space Workload User( Grants the ability to generate an attestation token and run a workload in a VM. Intended for service accounts that run on Confidential Space VMs.  | 
   
       
 
  | 
Confidential Computing permissions
| Permission | Included in roles | 
|---|---|
        
       | 
      
         
          Owner ( 
          Editor ( 
          Confidential Space Workload User (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Confidential Space Workload User (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Confidential Space Workload User ( 
          Support User (  | 
    
        
       | 
      
         
          Owner ( 
          Editor ( 
          Viewer ( 
          Confidential Space Workload User ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User (  |