If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: docs.cloud.google.com/iam/docs/create-service-agents - Create and grant roles to serv.

site address: docs.cloud.google.com/iam/docs/create-service-agents

site title: Create and grant roles to service agents     Identity and Access Management (IAM)     Google Cloud Documentation

Our opinion (on Tuesday 21 July 2026 20:35:13 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=How to create a service agent and grant it IAM roles.;

Headings (most frequently used words):

windows, linux, macos, or, cloud, shell, powershell, curl, service, and, roles, to, agents, gcloud, rest, cmd, exe, apis, explorer, browser, create, grant, required, console, terraform, stay, organized, with, collections, save, categorize, content, based, on, your, preferences, before, you, begin, identify, trigger, agent, creation, what, next, products, pricing, support, resources, engage, permissions,

Text of the page (most frequently used words):
the (335), #service (203), for (134), you (125), and (111), agents (90), roles (78), that (76), gcloud (72), #create (60), agent (60), access (59), cloud (56), role (49), grant (48), following (48), use (47), com (46), google (43), your (42), command (38), googleapis (37), account (37), policy (36), request (36), list (35), auth (35), identity (35), project (33), resource (33), with (31), iam (31), using (29), projects (29), can (28), each (28), services (28), response (27), 123456789012 (26), aiplatform (25), this (24), resource_type (24), endpoint (23), manage (22), policies (22), running (22), organization (22), terraform (21), allow (21), api (21), are (20), resource_id (20), example (20), resources (19), need (19), accounts (19), workload (19), cli (18), type (18), folder (18), granted (18), principal (18), all (17), user (17), active (17), want (17), execute (16), json (16), data (16), code (15), identities (15), method (15), headers (15), https (15), federation (15), page (14), note (14), token (14), automatically (14), organizations (14), folders (14), permissions (14), global (14), get (14), required (13), shell (13), created (13), workloadidentity (13), available (13), content (12), which (12), any (12), have (12), these (12), name (12), see (11), information (11), send (11), reference (11), application (11), expand (11), windows (11), like (11), before (11), custom (11), email (11), locations (11), body (10), apis (10), cred (10), print (10), authorization (10), bearer (10), assumes (10), logged (10), check (10), currently (10), login (10), init (10), curl (10), one (10), make (10), configuration (10), address (10), enable (10), workforce (10), samples (9), other (9), best (9), practices (9), version (9), contains (9), post (9), logs (9), ids (9), value (9), binding (9), serviceaccount (9), apply (9), console (9), will (9), where (9), resourcemanager (9), troubleshoot (9), configure (9), more (8), view (8), api_version (8), powershell (8), linux (8), macos (8), replacements (8), then (8), add (8), gcp (8), gserviceaccount (8), identify (8), creation (8), google_workload_identity_service_agent (8), operations (8), serviceproducers (8), state (8), level (8), usage (8), keys (8), pam (8), overview (8), about (7), thumb (7), managed (7), them (7), not (7), setiampolicy (7), select (7), granting (7), getiampolicy (7), trigger (7), run (7), permission (7), operation (7), also (7), serviceusage (7), limit (7), management (7), audit (7), 2026 (6), workloads (6), should (6), explorer (6), click (6), cloudresourcemanager (6), save (6), options (6), numeric (6), bigquery (6), default (6), condition (6), manager (6), job (6), container (6), serviceproducer (6), lists (6), from (6), number (6), endpoints (6), expression (6), their (6), admin (6), security (6), tools (6), oauth (6), logging (6), credentials (6), updated (5), learn (5), tool (5), invoke (5), webrequest (5), charset (5), utf (5), uri (5), object (5), named (5), into (5), http (5), url (5), alphanumeric (5), grants (5), primary (5), documentation (5), product (5), might (5), false (5), creating (5), record (5), generateserviceagents (5), filter (5), predefined (5), pipelines (5), temporary (5), boundary (5), functions (5), authenticate (5), português (4), español (4), understand (4), down (4), how (4), copy (4), right (4), requests (4), file (4), strings (4), rest (4), plan (4), after (4), target (4), member (4), associated (4), role_name (4), multiple (4), time (4), typically (4), don (4), specific (4), operation_name (4), resource_numeric_id (4), generate (4), ask (4), next_page_token (4), page_size (4), optional (4), storage (4), deny (4), short (4), lived (4), credential (4), elevated (4), delete (4), providers (4), users (4), microsoft (4), entra (4), sign (3), architecture (3), getting (3), system (3), products (3), under (3), details (3), control (3), returned (3), open (3), panel (3), opens (3), side (3), interact (3), complete (3), fields (3), browser (3), set (3), whose (3), write (3), members (3), vertex (3), bindings (3), owner (3), when (3), read (3), errors (3), section (3), google_project (3), remove (3), cmd (3), exe (3), below (3), needs (3), choose (3), function (3), based (3), those (3), some (3), because (3), aren (3), metadata (3), operationmetadata (3), createtime (3), 03t23 (3), verb (3), passthroughlro (3), requestedcancellation (3), apiversion (3), done (3), listed (3), field (3), identified (3), location (3), review (3), names (3), pagination (3), pagesize (3), pagetoken (3), results (3), quotes (3), contain (3), help (3), guides (3), networking (3), compute (3), monitor (3), scim (3), migrate (3), tags (3), related (3), key (3), gke (3), groups (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), terms (2), site (2), youtube (2), events (2), started (2), status (2), support (2), pricing (2), missing (2), last (2), utc (2), otherwise (2), licensed (2), license (2), feedback (2), explore (2), principals (2), next (2), store (2), paste (2), contenttype (2), infile (2), calling (2), already (2), project_number (2), customcodeserviceagent (2), policy_version (2), current (2), modify (2), pattern (2), update (2), execution (2), google_project_iam_member (2), added (2), service_agents (2), project_id (2), wanted (2), could (2), provider (2), basic (2), commands (2), search (2), must (2), they (2), properly (2), creates (2), necessary (2), 1775258415970 (2), 64e968f44b91a (2), 28fcf2f5 (2), 38367cfe (2), 982631253z (2), serviceagents (2), serviceagent (2), vtc (2), trainingclusterserviceagent (2), truncated (2), completed (2), return (2), were (2), was (2), 1775250941060 (2), 64e94d1baa76d (2), 1aa958f3 (2), 07b2ea9c (2), placeholder (2), skip (2), find (2), titles (2), greater (2), than (2), size (2), start (2), previous (2), include (2), maximum (2), quoting (2), filters (2), sandbox (2), but (2), library (2), through (2), repository (2), let (2), actual (2), resolve (2), revoke (2), prevent (2), revoked (2), sdk (2), languages (2), frameworks (2), infrastructure (2), costs (2), observability (2), monitoring (2), migration (2), industry (2), solutions (2), distributed (2), hybrid (2), multicloud (2), databases (2), analytics (2), hosting (2), development (2), error (2), messages (2), patterns (2), integration (2), controls (2), optimize (2), test (2), restrict (2), settings (2), entitlements (2), edit (2), conditions (2), conditional (2), types (2), legged (2), disable (2), integrate (2), pools (2), libraries (2), deployment (2), federate (2), load (2), applications (2), federated (2), oidc (2), saml (2), okta (2), cross (2), technology (2), areas (2), close (2), subscribe, newsletter, our, third, decade, climate, action, join, cookies, privacy, tech, twitter, blog, engage, training, certification, center, github, release, notes, community, forums, contact, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missingtheinformationsamplesineed, otherdown, tell, except, noted, java, registered, trademark, oracle, its, affiliates, developers, apache, creative, commons, attribution, act, ways, what, treat, sent, representation, format, has, platform, etag, bwwkmjvelug, requestedpolicyversion, specify, most, recent, specifying, shows, looks, good, ensures, without, known, would, targeted, for_each, try, prefaced, 0123456789012, instead, follow, principle, least, privilege, includes, only, perform, give, enter, person_add, asked, addresses, endtime, 315225515z, true, generateserviceagentsresponse, containing, ongoing, indicting, 03t21, 367155118z, parent, provisioned, once, during, step, manually, keep, track, programmatically, provide, know, unique, organization_number, folder_number, indicates, determine, triggering, earlier, specified, ended, 200, retrieve, uses, replace, single, double, nested, escape, inner, unlimited, expressions, topic, additional, methods, able, long, exact, organizationadmin, folderadmin, projectiamadmin, viewer, serviceusageviewer, administrator, likely, serviceusageadmin, begin, refer, stores, copies, appear, stored, inconsistency, incorrectly, proactively, drift, between, doesn, ensure, declarative, framework, option, useful, strategies, asking, lets, hasn, been, yet, sometimes, behalf, categorize, preferences, stay, organized, collections, home, withcond, insights, history, analyze, privileged, secure, vpc, intelligence, securely, exfiltration, interfaces, restore, downscoped, boundaries, approve, withdraw, remediate, excessive, entitlement, export, setup, lint, limits, conditionally, changes, auditing, billing, grantable, suggestions, gemini, assistance, change, propagation, inheritance, own, deploy, built, managing, upload, public, rotation, download, customers, 509, certificates, kubernetes, directory, aws, azure, external, balancers, balancing, gce, engine, attach, undelete, authentication, impersonation, obtain, power, pingone, aic, pingfederate, large, provisioning, client, discover, free, main,


Text of the page (random words):
ypes roles for service account authentication create and grant roles to service agents create service accounts manage service accounts list and edit service accounts disable and enable service accounts delete and undelete service accounts manage tags for service accounts attach service accounts to resources use custom organization policies for service accounts and keys service account best practices best practices for using service accounts best practices for using service accounts in deployment pipelines use managed workload identities about managed workload identities compute engine create managed workload identities for gce gke create managed workload identities for gke troubleshoot managed workload identities for gke cloud load balancing create managed workload identities for load balancers use custom organization policies federate identities for external workloads workload identity federation configure workload identity federation aws or azure active directory deployment pipelines kubernetes workloads with x 509 certificates other identity providers authenticate workloads using google auth libraries manage workload identity pools and providers best practices for using workload identity federation let customers access their google cloud resources from your product or service download credential configuration and grant access integrate cloud run and workload identity federation use custom organization policies create and manage service account keys migrate from service account keys service account key rotation create and delete service account keys list and get service account keys upload a public key disable and enable service account keys best practices for managing service account keys built in identities for resources configure identities for agents agent identity overview create and deploy an agent with agent cli and agent identity authenticate using an agent s own identity agent identity auth manager agent identity auth manager overview authenticate using 3 legged oauth authenticate using 2 legged oauth authenticate using an api key manage auth providers migrate to the agent identity api control access to resources about iam access controls roles and permissions principals policy types allow policies allow policy inheritance deny policies principal access boundary policies access change propagation iam conditions choose roles to grant choose which type of role to use find the right predefined roles get predefined role suggestions with gemini assistance view grantable roles roles for specific job functions predefined roles for job functions billing related job functions networking related job functions auditing related job functions create and manage custom roles create and manage custom roles manage tags for custom roles grant access manage access to projects folders and organizations manage access to service accounts manage access to other resources test allow policy changes grant access conditionally manage conditional role bindings configure temporary access configure resource based access tags and conditional access set limits on granting roles lint conditions in allow policies deny access restrict the resources that a principal can access create and apply principal access boundary policies view principal access boundary policies edit principal access boundary policies remove principal access boundary policies temporary elevated access temporary elevated access overview control temporary elevated access with pam pam overview permissions and setup create entitlements view update and delete entitlements configure pam settings view and export pam settings view grants revoke grants audit entitlement and grant events remediate excessive permissions with pam best practices for pam request temporary elevated access with pam withdraw grants approve or deny grants with pam create short lived credentials for a service account create short lived credentials for multiple service accounts restrict a credential s cloud storage permissions credential access boundaries for cloud storage create a downscoped short lived credential migrate to the service account credentials api restore a previous version of an allow policy test permissions for custom user interfaces use custom organization policies for allow policies use iam to help prevent exfiltration from data pipelines optimize your iam configuration use iam securely optimize iam policies by using policy intelligence tools help secure iam using vpc service controls monitor audit logging iam api audit logging iam scim audit logging service account credentials api audit logging privileged access manager audit logging security token service api audit logging example logs for service accounts example logs for workforce identity federation example logs for workforce oauth application integration example logs for workload identity federation analyze access to resources monitor service account usage tools to understand service account usage monitor usage patterns for service accounts and keys review allow policy history review security insights troubleshoot troubleshoot permission error messages permission error messages request missing permissions resolve permission errors troubleshoot allow and deny policies troubleshoot organization policy errors for service accounts troubleshoot withcond in policies and role bindings troubleshoot workforce identity federation troubleshoot workload identity federation troubleshoot agent identity auth manager samples all identity and access management code samples code samples for all products ai and ml application development application hosting compute data analytics and pipelines databases distributed hybrid and multicloud industry solutions migration networking observability and monitoring security storage access and resources management costs and usage management infrastructure as code sdk languages frameworks and tools home documentation security iam guides send feedback create and grant roles to service agents stay organized with collections save and categorize content based on your preferences in google cloud project level folder level and organization level service agents are created automatically as you enable and use google cloud services sometimes these service agents are also automatically granted roles that allow them to create and access resources on your behalf if necessary you can also ask google cloud to create project level folder level and organization level service agents for a service before you use the service asking google cloud to create service agents lets you grant roles to service agents before you use a service if a service agent hasn t been created yet then you can t grant roles to the service agent this option is useful if you use one of the following strategies to manage your allow policies a declarative framework like terraform if your terraform configuration doesn t include the service agents roles then those roles are revoked when you apply your configuration by creating service agents and granting them roles in your terraform configuration you ensure that these roles aren t revoked a policies as code system that stores copies of your current allow policies in a code repository if you let google cloud grant roles to service agents automatically those roles appear in your actual allow policy but not in your stored copy of the allow policy to resolve this inconsistency you might incorrectly revoke these roles by creating service agents and granting them roles proactively you can help prevent drift between your code repository and your actual allow policies after you trigger service agent creation you must grant the service agents the roles that they are typically granted automatically if you don t some services might not function properly this is because service agents that are created at a user s request aren t automatically granted roles note to create and grant roles to service agents for service specific resources refer to the service s documentation before you begin enable the resource manager and workload identity apis roles required to enable apis to enable apis you need the serviceusage services enable permission if you created the project then you likely already have this permission through the owner role roles owner otherwise you can get this permission through the service usage admin role roles serviceusage serviceusageadmin learn how to grant roles enable the apis understand service agents required roles to get the permissions that you need to create and grant access to service agents ask your administrator to grant you the following iam roles on the projects folders and organizations that you re creating service agents for and granting access to list available services and their endpoints service usage viewer roles serviceusage serviceusageviewer enable service agents workload identity api admin roles workloadidentity admin grant service agents access to a project project iam admin roles resourcemanager projectiamadmin grant service agents access to a folder folder admin roles resourcemanager folderadmin grant service agents access to projects folders and organizations organization admin roles resourcemanager organizationadmin for more information about granting roles see manage access to projects folders and organizations these predefined roles contain the permissions required to create and grant access to service agents to see the exact permissions that are required expand the required permissions section required permissions the following permissions are required to create and grant access to service agents list available services and their endpoints serviceusage services list enable service agents workloadidentity serviceagents create view long running operations workloadidentity operations get grant service agents access to a project resourcemanager projects getiampolicy resourcemanager projects setiampolicy grant service agents access to a folder resourcemanager folders getiampolicy resourcemanager folders setiampolicy grant service agents access to an organization resourcemanager organizations getiampolicy resourcemanager organizations setiampolicy you might also be able to get these permissions with custom roles or other predefined roles identify service agents to create to identify the service agents that you need to create and the resources that you need to create them for do the following make a list of the services that you use and their api endpoints to view all available services and their endpoints use one of the following methods console go to the api library page in the google cloud console go to api library the api endpoint is the service name listed in the additional details section gcloud the gcloud services list command lists all available services for a project before using any of the command data below make the following replacements expression optional an expression to filter the results for example the following expression filters for all services whose names contain googleapis com but don t contain sandbox name googleapis com and name sandbox for a list of filter expressions see gcloud topic filters limit optional the maximum number of results to list the default is unlimited execute the following command linux macos or cloud shell gcloud services list available filter expression limit limit windows powershell gcloud services list available filter expression limit limit windows cmd exe note if this command uses for quoting content replace these single quotes with double quotes if quoting is nested use to escape the inner quotes gcloud services list available filter expression limit limit the response contains the names and titles of all available services the api endpoint is the value in the name field rest the service usage api s services list method lists all available services for a project before using any of the request data make the following replacements resource_type the type of resource that you want to list available services for use projects folders or organizations resource_id the id of the google cloud project folder or organization that you want to list available services for project ids are alphanumeric strings like my project folder and organization ids are numeric like 123456789012 page_size optional the number of services to include in the response the default value is 50 and the maximum value is 200 if the number of services is greater than the page size the response contains a pagination token that you can use to retrieve the next page of results next_page_token optional the pagination token returned in an earlier response from this method if specified the list of services will start where the previous request ended http method and url get https serviceusage googleapis com v1 resource_type resource_id services pagesize page_size pagetoken next_page_token to send your request expand one of these options curl linux macos or cloud shell note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login or by using cloud shell which automatically logs you into the gcloud cli you can check the currently active account by running gcloud auth list execute the following command curl x get h authorization bearer gcloud auth print access token https serviceusage googleapis com v1 resource_type resource_id services pagesize page_size pagetoken next_page_token powershell windows note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login you can check the currently active account by running gcloud auth list execute the following command cred gcloud auth print access token headers authorization bearer cred invoke webrequest method get headers headers uri https serviceusage googleapis com v1 resource_type resource_id services pagesize page_size pagetoken next_page_token select object expand content the response contains the names and titles of all available services for the resource if the number of available services is greater than the page size the response also contains a pagination token the api endpoint is the value in the name field for each api endpoint that you will use make a list of the resources where you need to create that endpoint s service agents on the service agent reference page search for each api endpoint to find all service agents for that endpoint some endpoints might not have associated service agents you can skip triggering service agent creation for these endpoints for each of the endpoint s service agents use the service agent s email address to determine where you need to create the service agent the placeholder in a service agent s email address indicates where you need to create the service agent placeholder where to create the service agent project_number each project where you will use the service folder_number each folder where you will use the service organization_nu...
Images from subpage: "docs.cloud.google.com/iam/docs/overview" Verify
Images from subpage: "docs.cloud.google.com/iam/docs/apis" Verify
Images from subpage: "docs.cloud.google.com/iam/docs/samples" Verify
Images from subpage: "docs.cloud.google.com/iam/docs/resources" Verify
Images from subpage: "docs.cloud.google.com/iam/docs/grant-role-console" Verify

Verified site has: 210 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-205 206-210


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 200
last-modified Tue, 21 Jul 2026 04:34:04 GMT
content-type text/html; charset=utf-8
vary Cookie
vary Accept-Encoding
content-security-policy base-uri self ; object-src none ; script-src strict-dynamic unsafe-inline https: http: nonce-eV2FqAi21AnbEJkahTPXtzQV7/FC0W unsafe-eval ; frame-ancestors self htt????/developers.google.com/_d/analytics-iframe; report-uri htt????/csp.withgoogle.com/csp/devsite/v2
strict-transport-security max-age=63072000; includeSubdomains; preload
x-xss-protection 0
x-content-type-options nosniff
cache-control no-cache, must-revalidate
expires 0
pragma no-cache
content-encoding gzip
x-cloud-trace-context 37193b4e04121a8af34609afdd2ba89f
date Tue, 21 Jul 2026 20:35:12 GMT
server Google Frontend
content-length 38291
alt-svc h3= :443 ; ma=2592000,h3-29= :443 ; ma=2592000

Meta Tags

title="Create and grant roles to service agents  |  Identity and Access Management (IAM)  |  Google Cloud Documentation"
name="google-signin-client-id" content="721724668570-nbkv1cfusk7kk4eni4pjvepaus73b13t.apps.googleusercontent.com"
name="google-signin-scope" content="profile email htt????/www.googleapis.com/auth/developerprofiles htt????/www.googleapis.com/auth/developerprofiles.award htt????/www.googleapis.com/auth/devprofiles.full_control.firstparty"
property="og:site_name" content="Google Cloud Documentation"
property="og:type" content="website"
name="theme-color" content="#1a73e8"
charset="utf-8"
content="IE=Edge" http-equiv="X-UA-Compatible"
name="viewport" content="width=device-width, initial-scale=1"
property="og:title" content="Create and grant roles to service agents  |  Identity and Access Management (IAM)  |  Google Cloud Documentation"
name="description" content="How to create a service agent and grant it IAM roles."
property="og:description" content="How to create a service agent and grant it IAM roles."
property="og:url" content="htt????/docs.cloud.google.com/iam/docs/create-service-agents"
property="og:image" content="htt????/docs.cloud.google.com/_static/cloud/images/social-icon-google-cloud-1200-630.png"
property="og:image:width" content="1200"
property="og:image:height" content="630"
property="og:locale" content="en"
name="twitter:card" content="summary_large_image"

Load Info

page size38291
load time (s)0.692019
redirect count0
speed download55333
server IP 172.217.22.174
* all occurrences of the string "http://" have been changed to "htt???/"