Secured Landing Zone roles and permissions
Note: Some or all of the roles and permissions in this
table do not apply to Trusted Cloud.
This page lists the IAM roles and permissions for Secured Landing Zone. To
search through all roles and permissions, see the role and
permission index .
Secured Landing Zone roles
Role
Permissions
(roles/securedlandingzone.bqdwOrgRemediator
)
Access to modify (remediate) resources in SLZ BQDW Blueprint at Organization.
accesscontextmanager.servicePerimeters.get
accesscontextmanager.servicePerimeters.list
accesscontextmanager.servicePerimeters.update
(roles/securedlandingzone.bqdwProjectRemediator
)
Access to modify (remediate) resources in SLZ BQDW Blueprint at Project.
bigquery.datasets.get
bigquery.datasets.getIamPolicy
bigquery.datasets.setIamPolicy
bigquery.datasets.update
cloudkms.cryptoKeys.get
cloudkms.cryptoKeys.getIamPolicy
cloudkms.cryptoKeys.list
cloudkms.cryptoKeys.setIamPolicy
cloudkms.cryptoKeys.update
cloudkms.keyRings.getIamPolicy
cloudkms.keyRings.setIamPolicy
pubsub.topics.get
pubsub.topics.getIamPolicy
pubsub.topics.list
pubsub.topics.setIamPolicy
pubsub.topics.update
resourcemanager.projects.update
serviceusage.services.use
storage.buckets.get
storage.buckets.getIamPolicy
storage.buckets.list
storage.buckets.setIamPolicy
storage.buckets.update
Overwatch Activator
Beta
(roles/securedlandingzone.overwatchActivator
)
This role can activate or suspend Overwatches
resourcemanager.projects.get
resourcemanager.projects.list
securedlandingzone.overwatches.activate
securedlandingzone.overwatches.suspend
Overwatch Admin
Beta
(roles/securedlandingzone.overwatchAdmin
)
Full access to Overwatches
resourcemanager.projects.get
resourcemanager.projects.list
securedlandingzone.*
securedlandingzone.operations.get
securedlandingzone.overwatches.activate
securedlandingzone.overwatches.create
securedlandingzone.overwatches.delete
securedlandingzone.overwatches.get
securedlandingzone.overwatches.list
securedlandingzone.overwatches.suspend
securedlandingzone.overwatches.update
Overwatch Viewer
Beta
(roles/securedlandingzone.overwatchViewer
)
This role can view all properties of Overwatches
resourcemanager.projects.get
resourcemanager.projects.list
securedlandingzone.operations.get
securedlandingzone.overwatches.get
securedlandingzone.overwatches.list
Secured Landing Zone Service Agent
(roles/securedlandingzone.serviceAgent
)
Grants Secured Landing Zone service account permissions to manage resources in the customer project
Warning: Do not grant service agent roles to any principals except
service agents .
cloudasset.assets.exportOrgPolicy
cloudasset.assets.exportResource
cloudasset.feeds.create
cloudasset.feeds.delete
cloudasset.feeds.update
logging.logEntries.list
pubsub.subscriptions.consume
pubsub.subscriptions.create
pubsub.subscriptions.delete
pubsub.topics.attachSubscription
pubsub.topics.create
pubsub.topics.delete
pubsub.topics.detachSubscription
pubsub.topics.getIamPolicy
pubsub.topics.setIamPolicy
resourcemanager.projects.get
securitycenter.assetsecuritymarks.update
securitycenter.findings.list
securitycenter.findings.update
securitycenter.sources.list
securitycenter.sources.update
serviceusage.services.use
Secured Landing Zone permissions
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License , and code samples are licensed under the Apache 2.0 License . For details, see the Google Developers Site Policies . Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-08-28 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-28 UTC."],[],[],null,["# Secured Landing Zone roles and permissions\n\nThis page lists the IAM roles and permissions for Secured Landing Zone. To\nsearch through all roles and permissions, see the [role and\npermission index](/iam/docs/roles-permissions).\n\nSecured Landing Zone roles\n--------------------------\n\nSecured Landing Zone permissions\n--------------------------------"]]