Creating and Assigning Custom Roles

Follow the below steps to create custom roles on Google Workspace:

  1. In the Google Workspace configuration interface, go to Admin Console > Menu > Account > Admin roles.

  2. Select Create new role.

  3. Enter the Name and Description for the role and select Continue.

Follow the below steps to create custom roles on Google Cloud Provider (GCP):

  1. Go to GCP Console > Roles.

  2. Select Create Role.

  3. Enter the Title and Description for the role and select Continue.

Assigning Permissions to Custom Roles

The following permissions must be assigned to the custom role for the service account at the organization level:

  • cloudasset.assets.searchAllIamPolicies

  • cloudasset.assets.searchAllResources

  • iam.roles.list

  • iam.serviceAccounts.getIamPolicy

  • iam.serviceAccounts.list

  • logging.logEntries.list

  • resourcemanager.folders.getIamPolicy

  • resourcemanager.folders.list

  • resourcemanager.organizations.get

  • resourcemanager.organizations.getIamPolicy

  • resourcemanager.projects.get

  • resourcemanager.projects.getIamPolicy

  • resourcemanager.projects.list