Access control with IAM

Cloud Tasks uses Identity and Access Management (IAM) for access control. For an introduction to IAM and its features, see the IAM overview. To learn how to grant and revoke access, see Manage access to projects, folders, and organizations.

You can configure access control at the project level and at the queue level. For example, you might grant a user permission to create and add tasks to a queue, but not delete the queue. Or you might grant access to all Cloud Tasks resources within a project to a group of users. For more information, see Secure queue configuration.

Every Cloud Tasks method requires the caller to have the necessary permissions. This page describes the permissions and roles that Cloud Tasks supports. Permissions are also checked when queue.yaml (or the legacy queue.xml file) is updated; or when you use the Google Cloud console.

Enable the Cloud Tasks API