Access change propagation
In IAM, access changes, such as granting a role or denying a
permission, are eventually consistent. This means that it takes time for access changes to propagate
through the system. In the meantime, recent access changes might not be effective
everywhere. For example, principals might still be able to use a recently
revoked role or a recently denied permission. Alternatively, they might not be
able to use a recently granted role or a permission they were, until recently,
denied from using.
Changes to allow or deny policies typically propagate in
2 minutes, but could potentially take 7 minutes
or longer.
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-10-01 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-10-01 UTC."],[],[],null,[]]