Skip to content
Cloud
Docs

IAM

IAM controls who can act on a Project's resources and which operations they can perform. It combines service-defined permissions, roles, policies, and identities for software.

Why use IAM?

Different people and applications need different access to the same Project. IAM lets you assign the permissions needed for a task and inspect those assignments as the application grows.

What you can do

  • Discover permissions and predefined roles published by services.
  • Create Project-owned custom roles from service permissions.
  • Read and update Project policies and inherited Account policies.
  • Manage service accounts and their credentials for software acting on Project resources.

Core concepts

A Permission names an allowed operation. A Role groups permissions. A Policy binds roles to members and can include conditions and deny rules. A Service account gives software an identity that can be assigned access.

OAuth handles client registration and token issuance. IAM handles access policies for Project resources. Enabling a service through Service Usage is a separate step from granting an identity permission to use it.

Use IAM

Read the CLI reference for commands or the API reference for resources, request fields, and responses.