Required Permissions
Note
When the connector is configured using client credentials, the refresh token holds the scopes and permissions.
The necessary permissions to manage Google Workspace connector are :
-
Roles assigned to an Impersonated user on the Google managed system.
-
Permissions assigned to Service Account Scopes.
Important
The impersonated user should be the IAM User and not the Service Account.
To perform necessary connector operations, refer to the following for minimum Service Account Scopes and Roles for Impersonate User:
-
Service Account Scopes and Built-in Roles for Impersonate User
-
Service Account Scopes and Custom Roles for Impersonate User
Additional Permissions for SailPoint Non-Human Identity (NHI) Discovery
The following GCP configuration is required when you enable SailPoint Non-Human Identity (NHI) Discovery on the Google Workspace SaaS connector. Grant only the roles and APIs that correspond to the features you plan to use. For supported features, refer to Supported Features.
Important
SailPoint NHI Discovery requires Service Account authentication grant type only.
SailPoint recommends assigning the Viewer and Organization Viewer roles to the SailPoint service account at the organization level. The following table lists additional GCP IAM roles you can assign for least-privilege access by features:
|
Features |
GCP IAM roles |
|---|---|
|
Continuous secret discovery |
Secret Manager Viewer, Secret Manager Secret Accessor, API Keys Viewer, Cloud Functions Viewer |
|
IAM monitoring |
Cloud Asset Viewer, View Service Accounts, IAM Recommender Viewer, Activity Analysis Viewer, Organization Role Viewer, Folder Viewer |
|
Compliance validation |
Logs Viewer, Logs View Accessor, Private Logs Viewer, Security Reviewer |