This document describes roles and permissions for Cloud Hub.
To control access to data displayed in Cloud Hub, use Identity and Access Management (IAM) to assign roles and permissions to users or groups.
Required roles
This section lists roles for viewing data in Cloud Hub.
To get the permissions that you need to view data in Cloud Hub, ask your administrator to grant you the following IAM roles on the project (project view) or management project for a folder (application view):
-
View most application and project data:
Cloud Hub Operator (
roles/cloudhub.operator) -
Use Gemini Cloud Assist:
Gemini Cloud Assist User (
roles/geminicloudassist.user) -
Create and view investigations:
Investigations Creator (
roles/geminicloudassist.investigationCreator)
For more information about granting roles, see Manage access to projects, folders, and organizations.
You might also be able to get the required permissions through custom roles or other predefined roles.
The Cloud Hub Operator role is intended for users such as operators and developers who perform their work in specific projects.
For information about support for project data and application data in Cloud Hub, see Application views and project views.
Roles for taking action on data
The Cloud Hub Operator role and the other roles listed in this document only provides permissions to view data. If you want to make a change based on the data, such as opening a support case, creating an alert policy, or updating an App Hub application in App Design Center, you must have the permissions to make those changes. The specific roles or permissions you need depend on the Google Cloud resources that you are responsible for managing.
The documentation for each Cloud Hub page include links to documentation about roles and permissions for some common actions you might take to respond to data you see in Cloud Hub
Permissions in the Cloud Hub Operator role
| Role | Permissions |
|---|---|
Cloud Hub Operator Beta( Allows users to view and interact with Cloud Hub. |
|