This page describes changes to the public Identity and Access Management (IAM) permissions for all Generally Available (GA) and Preview services on Google Cloud. This change log can help you maintain and troubleshoot your custom roles.
When a permission is added, IAM does not automatically add the permission to your custom roles.
For changes that occurred before 2022, see Archived permissions change log.You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
IAM changes for the week of 2026-08-11
| Service | Description |
|---|---|
| App Hub |
The following permissions have been added to the App Management Viewer role (
|
| Batch |
The following permissions have been added to the Google Batch Service Agent role (
|
| Cloud TPU |
The following permissions have been added to the Cloud TPU V2 API Service Agent role (
|
| Managed Service for Apache Airflow |
The following permissions have been added to the Cloud Composer API Service Agent role (
|
| Compute Engine |
The following permissions have been added to the Compute Instance Admin (beta) role (
|
| Compute Engine |
The following permissions have been added to the Compute Instance Admin (v1) role (
|
| Google Kubernetes Engine |
The following permissions have been added to the Kubernetes Engine Service Agent role (
|
| Dataflow |
The following permissions have been added to the Cloud Dataflow Service Agent role (
|
| Knowledge Catalog |
The following permissions have been added to the Dataplex Catalog Admin role (
|
| Managed Service for Apache Spark |
The following permissions have been added to the Dataproc Service Agent role (
|
| Application Design Center |
The following permissions have been added to the Application Design Center Admin role (
|
| Application Design Center |
The following permissions have been added to the Application Admin role (
|
| Application Design Center |
The following permissions have been added to the Application Editor role (
|
| Application Design Center |
The following permissions have been added to the Application Viewer role (
|
| Application Design Center |
The following permissions have been added to the Designcenter Editor role (
|
| Application Design Center |
The following permissions have been added to the Application Design Center User role (
|
| Application Design Center |
The following permissions have been added to the Application Design Center Viewer role (
|
| Developer Connect |
The Developer Connect Admin role ( |
| Developer Connect |
The Developer Connect Git Proxy Reader role ( |
| Developer Connect |
The Developer Connect Git Proxy User role ( |
| Developer Connect |
The Developer Connect User role ( |
| Developer Connect |
The Developer Connect Viewer role ( |
| Discovery Engine |
The following permissions have been added to the Discovery Engine Service Agent role (
|
| Flow |
The Flow Service Agent role ( |
| Cloud Life Sciences |
The following permissions have been added to the Genomics Service Agent role (
|
| Identity and Access Management |
The following permissions have been added to the Site Reliability Engineer role (
|
| Cloud Life Sciences |
The following permissions have been added to the Cloud Life Sciences Service Agent role (
|
| Notebooks |
The following permissions have been added to the AI Platform Notebooks Service Agent role (
|
| Developer Connect |
The following permissions have reached General Availability (GA):
|
| Firebase Data Connect |
The following permissions have been added:
|
| Firebase Data Connect |
The following permissions are supported in custom roles:
|
| Production Actuation Service |
The following permissions have been added:
|
| Production Actuation Service |
The following permissions are supported in custom roles:
|
IAM changes for the week of 2026-08-04
| Service | Description |
|---|---|
| Agent Identity API |
The Agent Identity Admin role ( |
| Agent Identity API |
The Agent Identity Editor role ( |
| Agent Identity API |
The Agent Identity User role ( |
| Agent Identity API |
The Agent Identity Viewer role ( |
| Gemini Enterprise Agent Platform |
The following permissions have been added to the Vertex AI Service Agent role (
|
| Backup and Disaster Recovery |
The following permissions have been added to the Backup and DR Service Agent role (
|
| BigQuery |
The following permissions have been added to the BigQuery Studio Admin role (
|
| BigQuery |
The following permissions have been added to the BigQuery Studio User role (
|
| Data Lineage API |
The following permissions have been added to the Data Lineage Editor role (
|
| Database Migration Service |
The following permissions have been added to the Database Migration Admin role (
|
| Database Migration Service |
The following permissions have been added to the Datamigration Editor role (
|
| Datastream |
The following permissions have been added to the Datastream Admin role (
|
| Distributed Cloud Edge Container |
The following permissions have been added to the Edge Container Service Agent role (
|
| Cluster Director |
The following permissions have been added to the Cluster Director Service Agent role (
|
| Identity and Access Management |
The following permissions have been added to the Data Scientist role (
|
| Agent Identity API |
The following permissions have reached General Availability (GA):
|
| Agent Registry |
The following permissions have been added:
|
| Agent Registry |
The following permissions are supported in custom roles:
|
| Cloud Key Management Service |
The following permissions have been added:
|
| Cloud Key Management Service |
The following permissions are supported in custom roles:
|
| Cloud Key Management Service |
The following permissions have reached General Availability (GA):
|
| Discovery Engine |
The following permissions have been added:
|
| Discovery Engine |
The following permissions are supported in custom roles:
|
| Firebase App Check |
The following permissions have been added:
|
| Firebase App Check |
The following permissions are supported in custom roles:
|
| Firebase App Check |
The following permissions have reached General Availability (GA):
|
| Firebase Data Connect |
The following permissions have been added:
|
| Firebase Data Connect |
The following permissions are supported in custom roles:
|
IAM changes for the week of 2026-07-28
| Service | Description |
|---|---|
| Google Kubernetes Engine |
The following permissions have been added to the Kubernetes Engine Admin role (
|
| Google Kubernetes Engine |
The following permissions have been added to the Kubernetes Engine Cluster Admin role (
|
| Cloud Data Fusion |
The following permissions have been removed from the Cloud Data Fusion API Service Agent role (
|
| Identity and Access Management |
The following permissions have been removed from the Data Scientist role (
|
| AI Platform |
The AI Platform Editor role ( |
| Spanner |
The following permissions have been removed from the Cloud Spanner Database Reader role (
|
| Spanner |
The following permissions have been removed from the Cloud Spanner Database Reader with DataBoost role (
|
| Spanner |
The following permissions have been removed from the Cloud Spanner Database User role (
|
| Spanner |
The following permissions have been removed from the Cloud Spanner Database Graph Intelligence features user role (
|
| Cloud TPU |
The TPU Editor role ( |
| VM Migration |
The following permissions have been added to the VM Migration Administrator role (
|
| Cloud Billing |
The following permissions have been added:
|
| Cloud Billing |
The following permissions are supported in custom roles:
|
| Cloud Billing |
The following permissions have reached General Availability (GA):
|
| Google Security Operations |
The following permissions have been added:
|
| Google Security Operations |
The following permissions are supported in custom roles:
|
| Cloud SQL |
The following permissions have been added:
|
| Cloud SQL |
The following permissions are supported in custom roles:
|
| Cloud SQL |
The following permissions have reached General Availability (GA):
|
| Compute Engine |
The following permissions have been added:
|
| Compute Engine |
The following permissions are supported in custom roles:
|
IAM changes for the week of 2026-07-21
| Service | Description |
|---|---|
| Flow |
The FlowService Service Agent role ( |
| AlloyDB for PostgreSQL |
The following permissions have been removed from the AlloyDB Admin role (
|
| AlloyDB for PostgreSQL |
The following permissions have been removed from the AlloyDB Database User role (
|
| Backup and Disaster Recovery |
The following permissions have been added to the Backup and DR Admin role (
|
| Business AI Code |
The Business AI Code Service Agent role ( |
| Business AI Code |
The User role for Business AI Code API role ( |
| Google Security Operations |
The following permissions have been added to the Chronicle API Editor role (
|
| Google Security Operations |
The following permissions have been added to the Chronicle API Viewer role (
|
| Cloud Tasks |
The following permissions have been added to the Cloud Tasks Admin role (
|
| Cloud Tasks |
The following permissions have been added to the Cloud Tasks Editor role (
|
| Cloud Tasks |
The following permissions have been added to the Cloud Tasks Enqueuer role (
|
| Cloud Tasks |
The following permissions have been added to the Cloud Tasks Viewer role (
|
| Customer Experience Insights |
The following permissions have been added to the Contact Center AI Insights Service Agent role (
|
| Sensitive Data Protection |
The following permissions have been removed from the DLP Organization Data Profiles Driver role (
|
| Sensitive Data Protection |
The following permissions have been removed from the DLP Project Data Profiles Driver role (
|
| Basic Role |
The following permissions have been added to the Editor role (
|
| Identity and Access Management |
The following permissions have been removed from the Databases Admin role (
|
| Identity and Access Management |
The following permissions have been removed from the Data Scientist role (
|
| Identity and Access Management |
The following permissions have been added to the Support User role (
|
| Basic Role |
The following permissions have been added to the Owner role (
|
| Basic Role |
The following permissions have been added to the Viewer role (
|
| Cloud Workstations |
The following permissions have been added to the Cloud Workstations Admin role (
|
| BigLake |
The following permissions have reached General Availability (GA):
|
| BigQuery |
The following permissions have been added:
|
| BigQuery |
The following permissions are supported in custom roles:
|
| BigQuery |
The following permissions have reached General Availability (GA):
|
| BigQuery Reservation API |
The following permissions have been added:
|
| BigQuery Reservation API |
The following permissions are supported in custom roles:
|
| BigQuery Reservation API |
The following permissions have reached General Availability (GA):
|
| Bigtable |
The following permissions are supported in custom roles:
|
| Business AI Code |
The following permissions have been added:
|
| Business AI Code |
The following permissions are supported in custom roles:
|
| Business AI Code |
The following permissions have reached General Availability (GA):
|
| Cloud Tasks |
The following permissions have been added:
|
| Developer Connect |
The following permissions have been added:
|
| Developer Connect |
The following permissions are supported in custom roles:
|
| Looker |
The following permissions have been added:
|
| Looker |
The following permissions have reached General Availability (GA):
|
| Google Cloud MCP servers |
The following permissions are supported in custom roles:
|
| Model Armor |
The following permissions have been added:
|
| Model Armor |
The following permissions are supported in custom roles:
|
| Model Armor |
The following permissions have reached General Availability (GA):
|
| Google Cloud NetApp Volumes |
The following permissions have been added:
|
| Google Cloud NetApp Volumes |
The following permissions are supported in custom roles:
|
| Network Security |
The following permissions have been added:
|
| Secret Manager |
The following permissions have been added:
|
| Secret Manager |
The following permissions have reached General Availability (GA):
|
| VM Migration |
The following permissions have been added:
|
| VM Migration |
The following permissions have reached General Availability (GA):
|
IAM changes for the week of 2026-07-14
| Service | Description |
|---|---|
| Database Migration Service |
The following permissions have been added to the Database Migration Service Agent role (
|
| Managed Service for Apache Spark |
The following permissions have been added to the Dataproc Service Agent role (
|
| Datastream |
The following permissions have been added to the Datastream Admin role (
|
| Discovery Engine |
The following permissions have been added to the Discovery Engine Service Agent role (
|
| Cluster Director |