本頁面說明如何使用 Identity and Access Management (IAM) 控管 CTS 的存取權與權限。
總覽
Google Cloud Platform 提供「身分與存取權管理」(IAM) 功能,可讓您以更精細的方式授予使用者 Google Cloud Platform 特定資源的存取權限,避免其他資源遭到未經授權者擅自存取。本頁面說明 Cloud Talent Solution 的 IAM 角色與權限。關於 Google Cloud Platform IAM 的詳細說明,請參閱 IAM 說明文件。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-05 (世界標準時間)。"],[],[],null,["# Identity and Access Management (IAM)\n\nThis page describes how you can control CTS access and\npermissions using Identity and Access Management (IAM).\n\nOverview\n--------\n\nGoogle Cloud Platform offers Identity and Access Management (IAM), which lets you give\nmore granular access to specific Google Cloud Platform resources and prevents unwanted\naccess to other resources. This page describes the Cloud Talent Solution IAM\nroles and permissions. For a detailed description of Google Cloud Platform\nIAM, see the [IAM documentation](/iam/docs).\n\nCTS provides a set of [predefined roles](#roles) designed\nto help you easily control access to your CTS resources.\nYou can also create your own [custom roles](#custom-roles), if the predefined\nroles do not provide the sets of permissions you need. In addition, the older\nbasic roles (Editor, Viewer, and Owner) are also still available to you,\nalthough they do not provide the same fine-grained control as the\nCTS roles. In particular, the basic roles provide\naccess to resources across Google Cloud Platform rather than just for\nCTS. See the [basic roles](/iam/docs/understanding-roles#basic)\ndocumentation for more information.\n\nThe table below outlines the predefined roles available for Job Search.\n\nPredefined roles\n----------------\n\nCTS provides predefined roles you can use to provide\nfiner-grained permissions to principals.\nThe role you grant to a principal controls what actions the\nprincipal can take. Principals can be individuals, groups, or service accounts.\n\nYou can grant multiple roles to the same principal, and you can change\nthe roles granted to a principal at any time, provided you have the\npermissions to do so.\n\nThe broader roles include the more narrowly defined roles. For example, the\njobsEditor role includes all of the permissions of the\njobsViewer role, along with the addition permissions of the\njobsEditor role.\n\nThe basic roles (Owner, Editor, Viewer) provide permissions across\nGoogle Cloud Platform. The roles specific to CTS provide only\nCTS permissions, except for the following\nGCP permissions, which are needed for general\nGCP usage:\n\n- `resourcemanager.projects.get`\n- `resourcemanager.projects.list`\n- `serviceusage.services.list`\n- `serviceusage.services.get`\n\nThe following table lists the predefined roles available for\nCTS, along with their permissions:\n\nManaging CTS IAM\n----------------\n\nYou can get and set IAM policies and roles using the Google Cloud Platform\nConsole, IAM API methods, or the Cloud Talent Solution APIs themselves. For more\ninformation, see\n[Granting, Changing, and Revoking Access](/iam/docs/granting-changing-revoking-access).\n\nWhat's next\n-----------\n\n- Learn how to [grant and revoke access](/iam/docs/granting-changing-revoking-access).\n- Learn more about [IAM](/iam/docs).\n- Learn more about [basic roles](/iam/docs/understanding-roles#basic).\n- Learn more about [custom roles](/iam/docs/understanding-custom-roles)."]]