Policy Controller roles and permissions

This page lists the IAM roles and permissions for Policy Controller. To search through all roles and permissions, see the role and permission index.

Policy Controller roles

Policy Controller offers the following service agent roles. Service agent roles should only be granted to service agents.

Role Permissions

Anthos Policy Controller Service Agent

(roles/anthospolicycontroller.serviceAgent)

Gives the Anthos Policy Controller service agent access toCloud Platform resources.

gkehub.features.get

gkehub.gateway.delete

gkehub.gateway.generateCredentials

gkehub.gateway.get

gkehub.gateway.patch

gkehub.gateway.post

gkehub.gateway.put

gkehub.locations.*

  • gkehub.locations.get
  • gkehub.locations.list

gkehub.memberships.get

gkehub.memberships.list

Policy Controller permissions

There are no IAM permissions for this service.

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2026年08月28日 UTC.