This page explains how to configure access control for Cloud Customer Care's support services.
Before you begin
- You must have the Standard Support, Enhanced Support, or Premium Support service.
- You must have the Organization Administrator role (
roles/resourcemanager.organizationAdmin) for your Google Cloud organization.
What is Identity and Access Management (IAM)
Google Cloud offers IAM, which lets you give more granular access to specific Google Cloud resources and prevents unwanted access to other resources. IAM lets you adopt the security principle of least privilege, so you grant only the necessary access to your resources.
IAM lets you control who (identity) has what access
(roles) to which resource by setting IAM policies.
IAM policies grant specific role(s) to a principal, giving the
principal certain permissions. For example, for a given resource, such as a
project, you can assign the Tech Support Viewer role
(roles/cloudsupport.techSupportViewer) to a Google Account and that account
can view support cases in the project, but cannot manage support cases.
Access considerations
If you have transitioned from Silver, Gold, or Platinum Support, keep in mind that support cases are no longer accessible through the Google Cloud Support Center (GCSC). After you enable Standard, Enhanced, or Premium Support, you can manage access to transitioned cases by granting IAM roles to users, groups, or domains.
Organization-level Cases
Customer Care cases can be created within either organizations or projects.
In order to manage organization-level cases, the user must have
the resourcemanager.organizations.get permission at the organization level, or
else they won't be able to select the organization in the Google Cloud console.
The simplest way to grant this permission is to grant the user the
roles/resourcemanager.organizationViewer role on the organization. This role
only grants the resourcemanager.organizations.get permission.
NOTE: Granting a user the Organization Viewer role is not the same as granting a
user the Viewer role at the Organization level. This is a common point of
confusion. The Organization Viewer role does not give the user access to view
any resources within the organization, it only allows the user to see that the
organization exists.
In addition, the user must have the relevant Technical Support IAM permissions, which are described in the following sections.
Customer Care IAM roles
With IAM, every support user must have the appropriate permissions to view and manage cases and users. Users gain these permissions when you add them to an IAM role, a group that belongs to a role, or a domain assigned to a role.
The following table lists the IAM roles available to Cloud Customer Care users, the associated permissions to which resources, and the lowest resource level that you can apply the permissions to.
| Role | Permissions |
|---|---|
Support Account Administrator( |