Access control with IAM
Stay organized with collections
Save and categorize content based on your preferences.
This page describes how you can control Discovery Engine API access and
permissions for Agent Search resources using Identity and Access Management (IAM).
Overview
Google Cloud offers IAM, which lets you give
more granular access to specific Google Cloud resources and prevents unwanted
access to other resources. This page describes the Agent Search IAM
roles and permissions. For a detailed description of Google Cloud
IAM, see the IAM documentation.
Agent Search provides a set of predefined roles designed
to help you control access to your Agent Search resources.
You can also create your own custom roles, if the predefined
roles don't provide the sets of permissions you need. In addition, the older
basic roles (Editor, Viewer, and Owner) are also still available to you,
although they don't provide the same fine-grained control as the
Agent Search roles. In particular, the basic roles provide
access to resources across Google Cloud rather than just for
Agent Search. See the basic roles
documentation for more information.
Predefined roles
Agent Search provides some predefined roles that you can use to provide
finer-grained permissions to principals. The role you grant to a principal
controls what actions the principal can take. Principals can be individuals,
groups, or service accounts.
You can grant multiple roles to the same principal, and you can change the roles
granted to a principal at any time, provided you have the permissions to do so.
The broader roles include the more narrowly defined roles. For example, the
Discovery Engine Editor role includes all of the permissions of the Discovery
Engine Viewer role, along with the addition permissions of the Discovery Engine
Editor role. Likewise, the Discovery Engine Admin role includes all of the
permissions of the Discovery Engine Editor role, along with its additional
permissions.
The basic roles (Owner, Editor, Viewer) provide permissions across Google Cloud. The roles specific to Agent Search provide only
Agent Search permissions, except for the following Google Cloud
permissions, which are needed for general Google Cloud usage:
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.services.list
serviceusage.services.get
The following table lists the Agent Search IAM roles with a corresponding list of all the permissions for each role.
Role
Permissions
Discovery Engine Admin
(roles/discoveryengine.admin)
Grants full access to all discoveryengine resources.