Access control with IAM
Stay organized with collections
Save and categorize content based on your preferences.
This page describes the Identity and Access Management (IAM) roles and permissions
that you need to purchase and manage commercial products on
Cloud Marketplace.
With IAM, you manage access control by defining who (identity)
has what access (role) for which resource. For commercial apps on
Cloud Marketplace, users in your Google Cloud organization require
IAM roles to sign up for Cloud Marketplace plans, and to
make changes to billing plans.
To grant Cloud Marketplace roles and permissions using gcloud, install
the gcloud CLI.
Otherwise, you can grant roles using the Google Cloud console.
Purchasing and managing roles
We recommend that you assign the
Billing Account Administrator
IAM role to users who are purchasing services from
Cloud Marketplace.
Users who want to access the services must have the
Viewer role, at a minimum.
For more granular control over users' permissions, you can
create custom roles with the permissions that you want to
grant.
Product-specific requirements
To use the following services in a Google Cloud project, you must have the
Project Editor role:
Google Cloud Dataprep by Trifacta
Neo4j Aura Professional
Redis Enterprise Cloud
List of IAM roles and permissions
You can grant users one or more of the following IAM roles.
Depending on the role you are granting to users, you must also assign the role
to a Google Cloud billing account, organization, or project. For details,
see the section on Granting IAM roles to users.
Role
Permissions
Consumer Procurement Entitlement Manager
(roles/consumerprocurement.entitlementManager)
Allows managing entitlements and enabling, disabling, and inspecting service states for a consumer
project.
commerceoffercatalog.offers.get
consumerprocurement.consents.check
consumerprocurement.consents.grant
consumerprocurement.consents.list
consumerprocurement.consents.revoke
consumerprocurement.entitlements.*
consumerprocurement.entitlements.get
consumerprocurement.entitlements.list
consumerprocurement.freeTrials.*
consumerprocurement.freeTrials.create
consumerprocurement.freeTrials.get
consumerprocurement.freeTrials.list
orgpolicy.policy.get
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.consumerpolicy.*
serviceusage.consumerpolicy.analyze
serviceusage.consumerpolicy.get
serviceusage.consumerpolicy.update
serviceusage.effectivepolicy.get
serviceusage.groups.*
serviceusage.groups.list
serviceusage.groups.listExpandedMembers
serviceusage.groups.listMembers
serviceusage.operations.get
serviceusage.services.disable
serviceusage.services.enable
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
Consumer Procurement Entitlement Viewer
(roles/consumerprocurement.entitlementViewer)
Allows inspecting entitlements and service states for a consumer project.
commerceoffercatalog.offers.get
consumerprocurement.consents.check
consumerprocurement.consents.list
consumerprocurement.entitlements.*
consumerprocurement.entitlements.get
consumerprocurement.entitlements.list
consumerprocurement.freeTrials.get
consumerprocurement.freeTrials.list
orgpolicy.policy.get
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.consumerpolicy.analyze
serviceusage.consumerpolicy.get
serviceusage.effectivepolicy.get
serviceusage.groups.*
serviceusage.groups.list
serviceusage.groups.listExpandedMembers
serviceusage.groups.listMembers
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
Consumer Procurement Events Viewer
(roles/consumerprocurement.eventsViewer)
Allows viewing key events for an offer
consumerprocurement.events.*
consumerprocurement.events.get
consumerprocurement.events.list
Consumer Procurement License Pool Editor
(roles/consumerprocurement.licensePoolEditor)
Allows managing license pools and license assignments.