Es posible que parte de la información de esta página (o toda) no se aplique a Cloud de Confiance de S3NS. Consulta Diferencias con Google Cloud para obtener más información.
Google uses AI technology to translate content into your preferred language. AI translations can contain errors.
En este documento, se proporciona una lista de los roles y permisos predefinidos de Identity and Access Management (IAM) para BigQuery. En esta página, se incluyen los roles y permisos para lo siguiente:
BigQuery: Roles y permisos que se aplican a los recursos de BigQuery, como conjuntos de datos, tablas, vistas y rutinas. Muchos de estos roles y permisos también se pueden otorgar a recursos de Resource Manager, como proyectos, carpetas y organizaciones.
API de BigQuery Connection: Es el rol que otorga acceso de agente de servicio a una conexión de Cloud SQL.
Consulta continua de BigQuery: Es el rol que otorga a una cuenta de servicio acceso a una consulta continua.
Política de datos de BigQuery: Roles y permisos que se aplican a las políticas de datos en BigQuery.
Servicio de transferencia de datos de BigQuery: Es el rol que otorga a un agente de servicio acceso para crear trabajos que transfieran datos.
BigQuery Engine para Apache Flink: Roles y permisos que se aplican a los recursos de BigQuery Engine para Apache Flink.
API del Servicio de migración de BigQuery: Roles y permisos que se aplican a los recursos del Servicio de migración de BigQuery.
BigQuery Omni: Es el rol que otorga a un agente de servicio acceso a las tablas.
Uso compartido de BigQuery: Roles y permisos que se aplican a los recursos de uso compartido de BigQuery
Funciones predefinidas de IAM de BigQuery
En las siguientes tablas, se enumeran los roles predefinidos de IAM de BigQuery con una lista correspondiente de todos los permisos que se incluyen en cada rol. Ten en cuenta que cada permiso es aplicable a un tipo de recurso específico.
Funciones de BigQuery
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para BigQuery. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
Para obtener información sobre cómo otorgar roles predefinidos en recursos de BigQuery, como conjuntos de datos, tablas y rutinas, consulta Controla el acceso a los recursos con IAM.
Role
Permissions
BigQuery Admin
(roles/bigquery.admin)
Provides permissions to manage all resources within the project. Can manage
all data within the project, and can cancel jobs from other users running
within the project.
It is possible to grant this role to the following lowest-level resources, but it is not
recommended. Other predefined roles grant full permissions over these resources and are less
permissive. BigQuery Admin is typically granted at the project level.
Lowest-level resources where you can grant this role:
Dataset
These resources within a dataset:
Table
View
Routine
Connection
Saved query
Data canvas
Pipeline
Data preparation
Repository
This role can also be granted on Resource Manager resources (projects, folders, and
organizations).
Manages BigQuery workloads, but is unable to create or modify slot commitments.
This role can only be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.bireservations.get
bigquery.capacityCommitments.get
bigquery.capacityCommitments.list
bigquery.jobs.get
bigquery.jobs.list
bigquery.jobs.listAll
bigquery.jobs.listExecutionMetadata
bigquery.reservationAssignments.*
bigquery.reservationAssignments.create
bigquery.reservationAssignments.delete
bigquery.reservationAssignments.list
bigquery.reservationAssignments.search
bigquery.reservationGroups.*
bigquery.reservationGroups.create
bigquery.reservationGroups.delete
bigquery.reservationGroups.get
bigquery.reservationGroups.list
bigquery.reservations.create
bigquery.reservations.delete
bigquery.reservations.get
bigquery.reservations.list
bigquery.reservations.listFailoverDatasets
bigquery.reservations.update
bigquery.reservations.use
resourcemanager.projects.get
resourcemanager.projects.list
BigQuery Resource Viewer
(roles/bigquery.resourceViewer)
Can view BigQuery workloads, but cannot create or modify slot reservations or commitments.
This role can only be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.bireservations.get
bigquery.capacityCommitments.get
bigquery.capacityCommitments.list
bigquery.jobs.get
bigquery.jobs.list
bigquery.jobs.listAll
bigquery.jobs.listExecutionMetadata
bigquery.reservationAssignments.list
bigquery.reservationAssignments.search
bigquery.reservationGroups.get
bigquery.reservationGroups.list
bigquery.reservations.get
bigquery.reservations.list
bigquery.reservations.listFailoverDatasets
resourcemanager.projects.get
resourcemanager.projects.list
BigQuery Studio Admin
(roles/bigquery.studioAdmin)
Combination role of BigQuery Admin, Dataform Admin, Notebook Runtime Admin and Dataproc
Serverless Editor.
It is possible to grant this role to the following lowest-level resources, but it is not
recommended. Other predefined roles grant full permissions over these resources and are less
permissive. BigQuery Studio Admin is typically granted at the project level.
Lowest-level resources where you can grant this role:
Dataset
These resources within a dataset:
Table
View
Routine
Connection
Saved query
Data canvas
Data preparation
Pipeline
Repository
This role can also be granted on Resource Manager resources (projects, folders, and
organizations).
When granted on a dataset, this role provides the ability to read the dataset's metadata and list
tables in the dataset.
When granted on a project, this role also provides the ability to run jobs, including queries,
within the project. A principal with this role can enumerate their own jobs, cancel their own jobs, and
enumerate datasets within a project. Additionally, allows the creation of new datasets within the
project; the creator is granted the BigQuery Data Owner role (roles/bigquery.dataOwner)
on these new datasets.
Lowest-level resources where you can grant this role:
Dataset
These resources within a dataset:
Routine
This role can also be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.bireservations.get
bigquery.capacityCommitments.get
bigquery.capacityCommitments.list
bigquery.config.get
bigquery.datasets.create
bigquery.datasets.get
bigquery.datasets.getIamPolicy
bigquery.jobs.create
bigquery.jobs.list
bigquery.models.list
bigquery.propertyGraphs.list
bigquery.readsessions.*
bigquery.readsessions.create
bigquery.readsessions.getData
bigquery.readsessions.update
bigquery.reservationAssignments.list
bigquery.reservationAssignments.search
bigquery.reservationGroups.get
bigquery.reservationGroups.list
bigquery.reservations.get
bigquery.reservations.list
bigquery.reservations.listFailoverDatasets
bigquery.reservations.use
bigquery.routines.list
bigquery.savedqueries.get
bigquery.savedqueries.list
bigquery.tables.list
bigquery.transfers.get
bigquerymigration.translation.translate
cloudkms.keyHandles.*
cloudkms.keyHandles.create
cloudkms.keyHandles.get
cloudkms.keyHandles.list
cloudkms.operations.get
cloudkms.projects.showEffectiveAutokeyConfig
dataform.folders.create
dataform.locations.*
dataform.locations.get
dataform.locations.list
dataform.repositories.create
dataform.repositories.list
dataplex.projects.search
resourcemanager.projects.get
resourcemanager.projects.list
BigQuery Filtered Data Viewer
(roles/bigquery.filteredDataViewer)
Access to view filtered table data defined by a row access policy.
bigquery.filteredDataViewer is a system-managed role. Grant the role by using
row-level access policies. Don't apply the role directly to a resource through
Identity and Access Management (IAM).
bigquery.rowAccessPolicies.getFilteredData
BigQuery ObjectRef Admin
(roles/bigquery.objectRefAdmin)
Administer ObjectRef resources that includes read and write permissions
Lowest-level resources where you can grant this role:
Connection
This role can also be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.objectRefs.*
bigquery.objectRefs.read
bigquery.objectRefs.write
BigQuery ObjectRef Reader
(roles/bigquery.objectRefReader)
Role for reading referenced objects via ObjectRefs in BigQuery
Lowest-level resources where you can grant this role:
Connection
This role can also be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.objectRefs.read
BigQuery Authorized Routine Admin
Beta
(roles/bigquery.routineAdmin)
Role for Authorized Routine to administer supported resources
bigquery.connections.use
bigquery.datasets.get
bigquery.models.getData
bigquery.models.getMetadata
bigquery.routines.get
bigquery.routines.list
bigquery.tables.create
bigquery.tables.delete
bigquery.tables.get
bigquery.tables.getData
bigquery.tables.list
bigquery.tables.update
bigquery.tables.updateData
BigQuery Authorized Routine Data Editor
Beta
(roles/bigquery.routineDataEditor)
Role for Authorized Routine to edit contents of supported resources
bigquery.datasets.get
bigquery.models.getData
bigquery.models.getMetadata
bigquery.routines.get
bigquery.routines.list
bigquery.tables.create
bigquery.tables.delete
bigquery.tables.get
bigquery.tables.getData
bigquery.tables.list
bigquery.tables.update
bigquery.tables.updateData
BigQuery Authorized Routine Data Viewer
Beta
(roles/bigquery.routineDataViewer)
Role for Authorized Routine to view data and contents of supported resources
bigquery.datasets.get
bigquery.models.getData
bigquery.models.getMetadata
bigquery.routines.get
bigquery.routines.list
bigquery.tables.get
bigquery.tables.getData
bigquery.tables.list
BigQuery Authorized Routine Metadata Viewer
Beta
(roles/bigquery.routineMetadataViewer)
Role for Authorized Routine to view metadata of supported resources
bigquery.datasets.get
bigquery.models.getMetadata
bigquery.routines.get
bigquery.routines.list
bigquery.tables.get
bigquery.tables.list
BigQuery Security Admin
Beta
(roles/bigquery.securityAdmin)
Administer all BigQuery security controls
bigquery.dataPolicies.attach
bigquery.dataPolicies.create
bigquery.dataPolicies.delete
bigquery.dataPolicies.get
bigquery.dataPolicies.getIamPolicy
bigquery.dataPolicies.list
bigquery.dataPolicies.setIamPolicy
bigquery.dataPolicies.update
bigquery.datasets.createTagBinding
bigquery.datasets.deleteTagBinding
bigquery.datasets.get
bigquery.datasets.getIamPolicy
bigquery.datasets.listEffectiveTags
bigquery.datasets.listSharedDatasetUsage
bigquery.datasets.listTagBindings
bigquery.datasets.setIamPolicy
bigquery.datasets.update
bigquery.datasets.updateTag
bigquery.rowAccessPolicies.create
bigquery.rowAccessPolicies.delete
bigquery.rowAccessPolicies.get
bigquery.rowAccessPolicies.getIamPolicy
bigquery.rowAccessPolicies.list
bigquery.rowAccessPolicies.setIamPolicy
bigquery.rowAccessPolicies.update
bigquery.tables.createTagBinding
bigquery.tables.deleteTagBinding
bigquery.tables.get
bigquery.tables.getIamPolicy
bigquery.tables.list
bigquery.tables.listEffectiveTags
bigquery.tables.listTagBindings
bigquery.tables.setColumnDataPolicy
bigquery.tables.setIamPolicy
bigquery.tables.update
bigquery.tables.updateTag
dataplex.projects.search
Service agent roles
Service agent roles should only be granted to service agents.
Role
Permissions
Connected Sheets Service Agent
(roles/bigquery.connectedSheetsServiceAgent)
Grants Connected Sheets Service Account access to create and manage BigQuery jobs on the customers resources.
bigquery.datasets.get
bigquery.jobs.create
bigquery.tables.create
bigquery.tables.update
bigquery.tables.updateData
Roles de la API de BigQuery Connection
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para la API de BigQuery Connection. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
BigQuery Connection API offers the following service agent roles.
Service agent roles should only be granted to service agents.
Role
Permissions
BigQuery Connection Service Agent
(roles/bigqueryconnection.serviceAgent)
Gives BigQuery Connection Service access to Cloud SQL instances in user projects.
cloudsql.instances.connect
cloudsql.instances.get
logging.logEntries.create
logging.logEntries.route
monitoring.metricDescriptors.create
monitoring.metricDescriptors.get
monitoring.metricDescriptors.list
monitoring.monitoredResourceDescriptors.*
monitoring.monitoredResourceDescriptors.get
monitoring.monitoredResourceDescriptors.list
monitoring.timeSeries.create
Roles de consultas continuas de BigQuery
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para BigQuery Continuous Query. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
BigQuery Continuous Query offers the following service agent roles.
Service agent roles should only be granted to service agents.
Role
Permissions
BigQuery Continuous Query Service Agent
(roles/bigquerycontinuousquery.serviceAgent)
Gives BigQuery Continuous Query access to the service accounts in the user project.
iam.serviceAccounts.getAccessToken
Roles de la política de datos de BigQuery
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para la política de datos de BigQuery. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
Role
Permissions
BigQuery Data Policy Admin
(roles/bigquerydatapolicy.admin)
Role for managing Data Policies in BigQuery
This role can only be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.dataPolicies.attach
bigquery.dataPolicies.create
bigquery.dataPolicies.delete
bigquery.dataPolicies.get
bigquery.dataPolicies.getIamPolicy
bigquery.dataPolicies.list
bigquery.dataPolicies.setIamPolicy
bigquery.dataPolicies.update
BigQuery Data Policy Editor
(roles/bigquerydatapolicy.editor)
Editor role for BigQuery Data Policy
bigquery.bireservations.*
bigquery.bireservations.get
bigquery.bireservations.update
bigquery.capacityCommitments.get
bigquery.capacityCommitments.list
bigquery.capacityCommitments.update
bigquery.config.*
bigquery.config.get
bigquery.config.update
bigquery.connections.create
bigquery.connections.delete
bigquery.connections.get
bigquery.connections.getIamPolicy
bigquery.connections.list
bigquery.connections.update
bigquery.connections.updateTag
bigquery.connections.use
bigquery.dataPolicies.attach
bigquery.dataPolicies.create
bigquery.dataPolicies.delete
bigquery.dataPolicies.get
bigquery.dataPolicies.getIamPolicy
bigquery.dataPolicies.list
bigquery.dataPolicies.update
bigquery.datasets.create
bigquery.datasets.get
bigquery.datasets.getIamPolicy
bigquery.datasets.listEffectiveTags
bigquery.datasets.listTagBindings
bigquery.datasets.updateTag
bigquery.jobs.create
bigquery.jobs.createGlobalQuery
bigquery.jobs.delete
bigquery.jobs.get
bigquery.jobs.list
bigquery.jobs.listExecutionMetadata
bigquery.models.*
bigquery.models.create
bigquery.models.delete
bigquery.models.export
bigquery.models.getData
bigquery.models.getMetadata
bigquery.models.list
bigquery.models.updateData
bigquery.models.updateMetadata
bigquery.models.updateTag
bigquery.objectRefs.*
bigquery.objectRefs.read
bigquery.objectRefs.write
bigquery.propertyGraphs.*
bigquery.propertyGraphs.create
bigquery.propertyGraphs.delete
bigquery.propertyGraphs.get
bigquery.propertyGraphs.list
bigquery.propertyGraphs.update
bigquery.readsessions.*
bigquery.readsessions.create
bigquery.readsessions.getData
bigquery.readsessions.update
bigquery.reservationAssignments.*
bigquery.reservationAssignments.create
bigquery.reservationAssignments.delete
bigquery.reservationAssignments.list
bigquery.reservationAssignments.search
bigquery.reservationGroups.*
bigquery.reservationGroups.create
bigquery.reservationGroups.delete
bigquery.reservationGroups.get
bigquery.reservationGroups.list
bigquery.reservations.create
bigquery.reservations.delete
bigquery.reservations.get
bigquery.reservations.getIamPolicy
bigquery.reservations.list
bigquery.reservations.listFailoverDatasets
bigquery.reservations.update
bigquery.reservations.use
bigquery.routines.*
bigquery.routines.create
bigquery.routines.delete
bigquery.routines.get
bigquery.routines.list
bigquery.routines.update
bigquery.routines.updateTag
bigquery.rowAccessPolicies.create
bigquery.rowAccessPolicies.delete
bigquery.rowAccessPolicies.get
bigquery.rowAccessPolicies.getIamPolicy
bigquery.rowAccessPolicies.list
bigquery.rowAccessPolicies.update
bigquery.savedqueries.*
bigquery.savedqueries.create
bigquery.savedqueries.delete
bigquery.savedqueries.get
bigquery.savedqueries.list
bigquery.savedqueries.update
bigquery.tables.createIndex
bigquery.tables.createSnapshot
bigquery.tables.deleteIndex
bigquery.tables.getIamPolicy
bigquery.tables.listEffectiveTags
bigquery.tables.listTagBindings
bigquery.tables.replicateData
bigquery.tables.restoreSnapshot
bigquery.tables.updateIndex
bigquery.transfers.*
bigquery.transfers.get
bigquery.transfers.update
resourcemanager.projects.get
resourcemanager.projects.list
BigQuery Data Policy Viewer
(roles/bigquerydatapolicy.viewer)
Role for viewing Data Policies in BigQuery
This role can only be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.dataPolicies.get
bigquery.dataPolicies.list
Masked Reader
(roles/bigquerydatapolicy.maskedReader)
Masked read access to sub-resources tagged by the policy tag associated with a data policy, for
example, BigQuery columns
This role can only be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.dataPolicies.maskedGet
Raw Data Reader
Beta
(roles/bigquerydatapolicy.rawDataReader)
Raw read access to sub-resources associated with a data policy, for example, BigQuery columns
This role can only be granted on Resource Manager resources (projects, folders, and
organizations).
bigquery.dataPolicies.getRawData
Roles del Servicio de transferencia de datos de BigQuery
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para el Servicio de transferencia de datos de BigQuery. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
BigQuery Data Transfer Service offers the following service agent roles.
Service agent roles should only be granted to service agents.
Role
Permissions
BigQuery Data Transfer Service Agent
(roles/bigquerydatatransfer.serviceAgent)
Gives BigQuery Data Transfer Service access to start BigQuery jobs in consumer project.
bigquery.config.get
bigquery.connections.delegate
bigquery.jobs.create
compute.networkAttachments.get
compute.networkAttachments.update
compute.regionOperations.get
compute.subnetworks.use
dataform.folders.create
dataform.locations.*
dataform.locations.get
dataform.locations.list
dataform.repositories.create
dataform.repositories.list
dataplex.entryGroups.get
dataplex.entryGroups.useContactsAspect
dataplex.entryGroups.useDataProfileAspect
dataplex.entryGroups.useDatabaseDataPolicyAspect
dataplex.entryGroups.useMySQLConnectorTypes
dataplex.entryGroups.useOracleConnectorTypes
dataplex.entryGroups.useOverviewAspect
dataplex.entryGroups.usePostgreSQLConnectorTypes
dataplex.entryGroups.useSQLAccessAspect
dataplex.entryGroups.useSQLServerConnectorTypes
dataplex.entryGroups.useSQLTriggersAspect
dataplex.entryGroups.useSchemaAspect
dataplex.entryGroups.useSecondaryIndexesAspect
dataplex.entryGroups.useStorageAspect
dataplex.metadataJobs.create
dataplex.metadataJobs.get
dataplex.metadataJobs.list
iam.serviceAccounts.getAccessToken
logging.logEntries.create
logging.logEntries.route
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.services.use
Roles de BigQuery Engine para Apache Flink
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para el motor de BigQuery para Apache Flink. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
Role
Permissions
Managed Flink Admin
Beta
(roles/managedflink.admin)
Full access to Managed Flink resources.
managedflink.*
managedflink.deployments.create
managedflink.deployments.delete
managedflink.deployments.get
managedflink.deployments.list
managedflink.deployments.update
managedflink.jobs.create
managedflink.jobs.delete
managedflink.jobs.get
managedflink.jobs.list
managedflink.jobs.update
managedflink.locations.get
managedflink.locations.list
managedflink.operations.cancel
managedflink.operations.delete
managedflink.operations.get
managedflink.operations.list
managedflink.sessions.create
managedflink.sessions.delete
managedflink.sessions.get
managedflink.sessions.list
managedflink.sessions.update
resourcemanager.projects.get
resourcemanager.projects.list
Managed Flink Viewer
Beta
(roles/managedflink.viewer)
Readonly access to Managed Flink resources.
managedflink.deployments.get
managedflink.deployments.list
managedflink.jobs.get
managedflink.jobs.list
managedflink.locations.*
managedflink.locations.get
managedflink.locations.list
managedflink.operations.get
managedflink.operations.list
managedflink.sessions.get
managedflink.sessions.list
resourcemanager.projects.get
resourcemanager.projects.list
Managed Flink Developer
Beta
(roles/managedflink.developer)
Full access to Managed Flink Jobs and Sessions and read access to Deployments.
managedflink.deployments.get
managedflink.deployments.list
managedflink.jobs.*
managedflink.jobs.create
managedflink.jobs.delete
managedflink.jobs.get
managedflink.jobs.list
managedflink.jobs.update
managedflink.locations.*
managedflink.locations.get
managedflink.locations.list
managedflink.operations.get
managedflink.operations.list
managedflink.sessions.*
managedflink.sessions.create
managedflink.sessions.delete
managedflink.sessions.get
managedflink.sessions.list
managedflink.sessions.update
resourcemanager.projects.get
resourcemanager.projects.list
Service agent roles
Service agent roles should only be granted to service agents.
Role
Permissions
Managed Flink Service Agent
(roles/managedflink.serviceAgent)
Gives Managed Flink Service Agent access to Cloud Platform resources.
compute.networkAttachments.create
compute.networkAttachments.delete
compute.networkAttachments.get
compute.networkAttachments.list
compute.networkAttachments.update
compute.networks.get
compute.networks.list
compute.regionOperations.get
compute.subnetworks.get
compute.subnetworks.list
compute.subnetworks.use
dns.networks.targetWithPeeringZone
managedkafka.clusters.get
managedkafka.clusters.list
managedkafka.clusters.update
monitoring.metricDescriptors.create
monitoring.metricDescriptors.get
monitoring.metricDescriptors.list
monitoring.monitoredResourceDescriptors.*
monitoring.monitoredResourceDescriptors.get
monitoring.monitoredResourceDescriptors.list
monitoring.timeSeries.create
serviceusage.services.use
storage.objects.get
Roles del Servicio de migración de BigQuery
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para el Servicio de migración de BigQuery. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
User of EDW migration interactive SQL translation service.
bigquerymigration.translation.translate
Task Worker
(roles/bigquerymigration.worker)
Worker that executes EDW migration subtasks.
storage.objects.create
storage.objects.get
storage.objects.list
Service agent roles
Service agent roles should only be granted to service agents.
Role
Permissions
BigQuery Migration Service Agent
(roles/bigquerymigration.serviceAgent)
Access required for the BigQuery Migration Service to perform data discovery, metadata registration, and manage data transfers.
resourcemanager.projects.get
Roles de BigQuery Omni
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para BigQuery Omni. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
BigQuery Omni offers the following service agent roles.
Service agent roles should only be granted to service agents.
Role
Permissions
BigQuery Omni Service Agent
(roles/bigqueryomni.serviceAgent)
Gives BigQuery Omni access to tables in user projects.
bigquery.jobs.create
bigquery.tables.updateData
Roles de uso compartido de BigQuery
En esta tabla, se enumeran los roles y permisos predefinidos de IAM para el uso compartido de BigQuery. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
Role
Permissions
Analytics Hub Admin
(roles/analyticshub.admin)
Administer Data Exchanges and Listings
analyticshub.dataExchanges.create
analyticshub.dataExchanges.delete
analyticshub.dataExchanges.get
analyticshub.dataExchanges.getIamPolicy
analyticshub.dataExchanges.list
analyticshub.dataExchanges.setIamPolicy
analyticshub.dataExchanges.update
analyticshub.dataExchanges.viewSubscriptions
analyticshub.listings.create
analyticshub.listings.delete
analyticshub.listings.get
analyticshub.listings.getIamPolicy
analyticshub.listings.list
analyticshub.listings.setIamPolicy
analyticshub.listings.update
analyticshub.listings.viewSubscriptions
analyticshub.subscriptions.*
analyticshub.subscriptions.create
analyticshub.subscriptions.delete
analyticshub.subscriptions.get
analyticshub.subscriptions.list
analyticshub.subscriptions.update
resourcemanager.projects.get
resourcemanager.projects.list
Analytics Hub Editor
(roles/analyticshub.editor)
Editor role for Analytics Hub
analyticshub.dataExchanges.create
analyticshub.dataExchanges.delete
analyticshub.dataExchanges.get
analyticshub.dataExchanges.getIamPolicy
analyticshub.dataExchanges.list
analyticshub.dataExchanges.update
analyticshub.listings.create
analyticshub.listings.delete
analyticshub.listings.get
analyticshub.listings.getIamPolicy
analyticshub.listings.list
analyticshub.listings.update
analyticshub.subscriptions.*
analyticshub.subscriptions.create
analyticshub.subscriptions.delete
analyticshub.subscriptions.get
analyticshub.subscriptions.list
analyticshub.subscriptions.update
resourcemanager.projects.get
resourcemanager.projects.list
Analytics Hub Viewer
(roles/analyticshub.viewer)
Can browse Data Exchanges and Listings
analyticshub.dataExchanges.get
analyticshub.dataExchanges.getIamPolicy
analyticshub.dataExchanges.list
analyticshub.listings.get
analyticshub.listings.getIamPolicy
analyticshub.listings.list
resourcemanager.projects.get
resourcemanager.projects.list
Analytics Hub Listing Admin
(roles/analyticshub.listingAdmin)
Grants full control over the Listing, including updating, deleting and setting ACLs
analyticshub.dataExchanges.get
analyticshub.dataExchanges.getIamPolicy
analyticshub.dataExchanges.list
analyticshub.listings.delete
analyticshub.listings.get
analyticshub.listings.getIamPolicy
analyticshub.listings.list
analyticshub.listings.setIamPolicy
analyticshub.listings.update
analyticshub.listings.viewSubscriptions
resourcemanager.projects.get
resourcemanager.projects.list
Analytics Hub Publisher
(roles/analyticshub.publisher)
Can publish to Data Exchanges thus creating Listings
analyticshub.dataExchanges.get
analyticshub.dataExchanges.getIamPolicy
analyticshub.dataExchanges.list
analyticshub.listings.create
analyticshub.listings.get
analyticshub.listings.getIamPolicy
analyticshub.listings.list
resourcemanager.projects.get
resourcemanager.projects.list
Analytics Hub Subscriber
(roles/analyticshub.subscriber)
Can browse Data Exchanges and subscribe to Listings
analyticshub.dataExchanges.get
analyticshub.dataExchanges.getIamPolicy
analyticshub.dataExchanges.list
analyticshub.dataExchanges.subscribe
analyticshub.listings.get
analyticshub.listings.getIamPolicy
analyticshub.listings.list
analyticshub.listings.subscribe
resourcemanager.projects.get
resourcemanager.projects.list
Analytics Hub Subscription Owner
(roles/analyticshub.subscriptionOwner)
Grants full control over the Subscription, including updating and deleting
analyticshub.dataExchanges.get
analyticshub.dataExchanges.getIamPolicy
analyticshub.dataExchanges.list
analyticshub.listings.get
analyticshub.listings.getIamPolicy
analyticshub.listings.list
analyticshub.subscriptions.*
analyticshub.subscriptions.create
analyticshub.subscriptions.delete
analyticshub.subscriptions.get
analyticshub.subscriptions.list
analyticshub.subscriptions.update
resourcemanager.projects.get
resourcemanager.projects.list
Permisos de BigQuery
En las siguientes tablas, se enumeran los permisos disponibles en BigQuery. Estos están incluidos en roles predefinidos y pueden usarse en las definiciones de roles personalizados. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
Permisos de BigQuery
En esta tabla, se enumeran los permisos de IAM para BigQuery y los roles que los incluyen. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
Permisos del Servicio de transferencia de datos de BigQuery
No hay permisos de IAM para este servicio.
Permisos de BigQuery Engine para Apache Flink
En esta tabla, se enumeran los permisos de IAM para BigQuery Engine para Apache Flink y los roles que los incluyen. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
En esta tabla, se enumeran los permisos de IAM para el Servicio de migración de BigQuery y los roles que los incluyen. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
En esta tabla, se enumeran los permisos de IAM para BigQuery sharing y los roles que los incluyen. Para buscar todos los roles y permisos, consulta el índice de roles y permisos.
Borrar un modelo mediante la declaración DROP MODEL
bigquery.models.getMetadata
Obtiene metadatos del modelo mediante la API models.get
bigquery.models.list
Enumera modelos y los metadatos en estos mediante la API models.list
bigquery.models.updateMetadata
Actualiza los metadatos del modelo mediante la API models.delete. Si configuras o actualizas un tiempo de vencimiento distinto de cero para el modelo, también se necesita el permiso bigquery.models.delete
bigquery.jobs.create bigquery.models.getData
Realiza evaluaciones, predicciones e inspecciones de modelos y características mediante funciones como ML.EVALUATE, ML.PREDICT, ML.TRAINING_INFO y ML.WEIGHTS.
[[["Fácil de comprender","easyToUnderstand","thumb-up"],["Resolvió mi problema","solvedMyProblem","thumb-up"],["Otro","otherUp","thumb-up"]],[["Falta la información que necesito","missingTheInformationINeed","thumb-down"],["Muy complicado o demasiados pasos","tooComplicatedTooManySteps","thumb-down"],["Desactualizado","outOfDate","thumb-down"],["Problema de traducción","translationIssue","thumb-down"],["Problema con las muestras o los códigos","samplesCodeIssue","thumb-down"],["Otro","otherDown","thumb-down"]],["Última actualización: 2026-06-24 (UTC)"],[],[]]