Access Transparency exclusions
Access Transparency logs are generated when S3NS personnel access content that you've uploaded into an Access Transparency supported service, except in the following scenarios:
S3NS is legally prohibited from notifying you of the access.
You've granted the S3NS personnel access to your content by using your Identity and Access Management (IAM) policy; their activities are recorded in Cloud Audit Logs (when enabled), not Access Transparency logs.
The access doesn't target Customer Data; for example, S3NS personnel querying for the average size of records in a database that contains content from multiple Cloud de Confiance by S3NS customers.
The content in question is a public resource identifier or a resource name. For example:
- Cloud de Confiance by S3NS project IDs
- Cloud Storage bucket names
- Compute Engine VM names
- Google Kubernetes Engine cluster names
- BigQuery resource names (including datasets, tables, and reservations)
The access originates from S3NS's standard automated systems and code. These system accesses are validated by code authorization, which verifies that the job originates from code that was checked into production and subject to a multi-party security and privacy review, including a verified source code owner.
What's next
- Learn about the services that Access Transparency supports.