IAM for project-level activations

This page describes how to use Identity and Access Management (IAM) to control access to resources in a project-level activation of Security Command Center. Refer to this page only if Security Command Center isn't activated for your organization.

See IAM for organization-level activations—instead of this page—if either of the following conditions apply:

  • Security Command Center is activated at the organization level and not at the project level.
  • Security Command Center Standard is already activated at the organization level. Additionally, you have Security Command Center Premium activated on one or more projects.

Security Command Center uses IAM roles to let you control who can do what with assets, findings, and security sources in your Security Command Center environment. You grant roles to individuals and applications, and each role provides specific permissions.

Permissions

To set up Security Command Center or change the configuration of your project, you need both of the following roles:

  • Project IAM Admin (roles/resourcemanager.projectIamAdmin)
  • Security Center Admin (roles/securitycenter.admin)

If a user doesn't require edit permissions, consider granting them viewer roles. To view all assets and findings in Security Command Center, users need the Security Center Admin Viewer (roles/securitycenter.adminViewer) role. Users who also need to view settings need the Security Center Settings Viewer (roles/securitycenter.settingsViewer) role.

Although you can set all these roles at any level of the resource hierarchy, we recommend setting these roles at the project level. This practice is in accordance with the principle of least privilege.

For instructions on managing roles and permissions, see Manage access to projects, folders, and organizations.

Inherited access to project-level activations of Security Command Center

A project inherits any role bindings that are set at the level of the folders and organization that contain that project. For example, if a principal has the Security Center Findings Editor role (roles/securitycenter.findingsEditor) at the organization level, that principal has the same role at the project level. That principal can view and edit findings in any of that organization's projects where Security Command Center is active.

The following figure illustrates a Security Command Center resource hierarchy with roles granted at the organization level.

Security Command Center resource hierarchy and permission structure
Security Command Center resource hierarchy and organization-level roles (click to enlarge)

To view a list of principals that have access to your project, including those who have inherited permissions, see View current access.

Security Command Center roles

The following IAM roles are available for Security Command Center. You can grant these roles at the organization, folder, or project level.

Role Permissions

(roles/securitycenter.admin)

Admin(super user) access to security center

Lowest-level resources where you can grant this role:

  • Project

aiplatform.artifacts.get

aiplatform.artifacts.list

aiplatform.batchPredictionJobs.get

aiplatform.batchPredictionJobs.list

aiplatform.customJobs.get

aiplatform.customJobs.list

aiplatform.datasets.get

aiplatform.datasets.list

aiplatform.endpoints.get

aiplatform.endpoints.list

aiplatform.executions.get

aiplatform.executions.list

aiplatform.models.get

aiplatform.models.list

aiplatform.tuningJobs.get

aiplatform.tuningJobs.list

appengine.applications.get

artifactregistry.attachments.get

artifactregistry.attachments.list

artifactregistry.dockerimages.*

  • artifactregistry.dockerimages.get
  • artifactregistry.dockerimages.list

artifactregistry.files.download

artifactregistry.files.get

artifactregistry.files.list

artifactregistry.locations.*

  • artifactregistry.locations.get
  • artifactregistry.locations.list

artifactregistry.mavenartifacts.*

  • artifactregistry.mavenartifacts.get
  • artifactregistry.mavenartifacts.list

artifactregistry.npmpackages.*

  • artifactregistry.npmpackages.get
  • artifactregistry.npmpackages.list

artifactregistry.packages.get

artifactregistry.packages.list

artifactregistry.projectconfigs.get

artifactregistry.projectsettings.get

artifactregistry.pythonpackages.*

  • artifactregistry.pythonpackages.get
  • artifactregistry.pythonpackages.list

artifactregistry.repositories.create

artifactregistry.repositories.downloadArtifacts

artifactregistry.repositories.exportArtifacts

artifactregistry.repositories.get

artifactregistry.repositories.list

artifactregistry.repositories.listEffectiveTags

artifactregistry.repositories.listTagBindings

artifactregistry.repositories.readViaVirtualRepository

artifactregistry.rules.get

artifactregistry.rules.list

artifactregistry.tags.get

artifactregistry.tags.list

artifactregistry.versions.get

artifactregistry.versions.list

assuredoss.*

  • assuredoss.config.get
  • assuredoss.customers.create
  • assuredoss.locations.get
  • assuredoss.locations.list
  • assuredoss.metadata.get
  • assuredoss.metadata.list
  • assuredoss.operations.cancel
  • assuredoss.operations.delete
  • assuredoss.operations.get
  • assuredoss.operations.list

auditmanager.auditReports.*

  • auditmanager.auditReports.generate
  • auditmanager.auditReports.get
  • auditmanager.auditReports.list

auditmanager.auditSchedules.*

  • auditmanager.auditSchedules.create
  • auditmanager.auditSchedules.get
  • auditmanager.auditSchedules.list
  • auditmanager.auditSchedules.update

auditmanager.auditScopeReports.generate

auditmanager.billingSettings.get

auditmanager.controlReports.*

  • auditmanager.controlReports.get
  • auditmanager.controlReports.list

auditmanager.controls.list

auditmanager.findings.list

auditmanager.locations.*

  • auditmanager.locations.enrollResource
  • auditmanager.locations.get
  • auditmanager.locations.list

auditmanager.operations.*

  • auditmanager.operations.get
  • auditmanager.operations.list

auditmanager.resourceEnrollmentStatuses.*

  • auditmanager.resourceEnrollmentStatuses.get
  • auditmanager.resourceEnrollmentStatuses.list

cloudasset.assets.exportAiplatformBatchPredictionJobs

cloudasset.assets.exportAiplatformCustomJobs

cloudasset.assets.exportAiplatformDataLabelingJobs

cloudasset.assets.exportAiplatformDatasets

cloudasset.assets.exportAiplatformEndpoints

cloudasset.assets.exportAiplatformHyperparameterTuningJobs

cloudasset.assets.exportAiplatformMetadataStores

cloudasset.assets.exportAiplatformModelDeploymentMonitoringJobs

cloudasset.assets.exportAiplatformModels

cloudasset.assets.exportAiplatformPipelineJobs

cloudasset.assets.exportAiplatformSpecialistPools

cloudasset.assets.exportAiplatformTrainingPipelines

cloudasset.assets.exportIamPolicy

cloudasset.assets.exportOSInventories

cloudasset.assets.exportResource

cloudasset.assets.queryAccessPolicy

cloudasset.assets.queryIamPolicy

cloudasset.assets.queryOSInventories

cloudasset.assets.queryResource

cloudasset.assets.searchAllIamPolicies

cloudasset.assets.searchAllResources

cloudasset.assets.searchEnrichmentResourceOwners

cloudasset.othercloudconnections.get

cloudasset.othercloudconnections.list

cloudasset.othercloudconnections.verify

cloudnotifications.activities.list

cloudsecuritycompliance.*

  • cloudsecuritycompliance.auditReports.generate
  • cloudsecuritycompliance.auditReports.get
  • cloudsecuritycompliance.auditReports.list
  • cloudsecuritycompliance.auditScopeReports.generate
  • cloudsecuritycompliance.billingSettings.get
  • cloudsecuritycompliance.cloudControlDeployments.create
  • cloudsecuritycompliance.cloudControlDeployments.delete
  • cloudsecuritycompliance.cloudControlDeployments.get
  • cloudsecuritycompliance.cloudControlDeployments.list
  • cloudsecuritycompliance.cloudControlDeployments.update
  • cloudsecuritycompliance.cloudControlPredictions.create
  • cloudsecuritycompliance.cloudControlPredictions.get
  • cloudsecuritycompliance.cloudControlPredictions.list
  • cloudsecuritycompliance.cloudControls.create
  • cloudsecuritycompliance.cloudControls.delete
  • cloudsecuritycompliance.cloudControls.get
  • cloudsecuritycompliance.cloudControls.list
  • cloudsecuritycompliance.cloudControls.update
  • cloudsecuritycompliance.cmEnrollments.get
  • cloudsecuritycompliance.cmEnrollments.update
  • cloudsecuritycompliance.controlComplianceSummaries.list