If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: docs.cloud.google.com/iam/docs/setting-limits-on-granting-roles - Set limits on granting roles  .

site address: docs.cloud.google.com/iam/docs/setting-limits-on-granting-roles redirected to: docs.cloud.google.com/iam/docs/setting-limits-on-granting-roles

site title: Set limits on granting roles     Identity and Access Management (IAM)     Google Cloud Documentation

Our opinion (on Wednesday 22 July 2026 16:31:36 UTC):

GREEN status (no comments) - no comments

Meta tags:

Headings (most frequently used words):

granting, role, limit, on, with, and, required, permissions, limited, iam, admins, to, curl, linux, macos, or, cloud, shell, powershell, windows, apis, explorer, browser, set, limits, roles, stay, organized, collections, save, categorize, content, based, your, preferences, before, you, begin, common, use, cases, what, next, create, allow, users, manage, write, condition, expression, conditional, bindings, console, gcloud, rest, products, pricing, support, resources, engage, logical, operators, for, hasonly, statements,

Text of the page (most frequently used words):
the (339), roles (171), for (142), and (131), role (115), iam (108), grant (81), you (73), project (61), revoke (59), policy (57), that (57), admin (56), allow (55), principal (53), service (44), resource (42), access (41), can (41), example (37), condition (36), with (35), following (35), limited (35), expression (32), create (32), request (31), com (31), identity (30), policies (29), use (29), organization (29), cloud (27), this (27), gcloud (26), your (26), api (26), granting (26), account (25), folder (25), google (24), other (24), permissions (24), manage (23), user (22), bindings (22), pubsub (22), modify (21), googleapis (20), using (20), custom (20), resourcemanager (20), compute (20), resources (19), list (19), type (19), set (18), admins (18), permission (18), editor (18), limits (18), accounts (18), auth (17), json (17), publisher (17), let (17), see (16), version (16), want (16), projects (16), don (16), only (16), engine (16), setiampolicy (15), owner (15), modifiedgrantsbyrole (15), app (15), federation (15), all (14), identities (14), description (13), members (13), organizations (13), folders (13), types (13), workload (13), are (12), select (12), command (12), these (12), limit (12), allowed (12), hasonly (12), binding (12), conditions (11), configure (11), not (11), note (11), title (11), manager (11), conditional (11), get (11), then (11), attribute (11), body (10), method (10), application (10), which (10), getattribute (10), pub (10), sub (10), lila (10), group (10), workforce (10), required (9), have (9), also (9), allows (9), certain (9), add (9), getiampolicy (9), noam (9), management (9), troubleshoot (9), agent (9), code (8), samples (8), more (8), page (8), any (8), click (8), resource_id (8), resource_type (8), api_version (8), cli (8), running (8), recognize (8), users (8), viewer (8), enable (8), keys (8), pam (8), best (8), practices (8), overview (8), thumb (7), information (7), content (7), them (7), execute (7), save (7), bwwkmjvelug (7), etag (7), value (7), data (7), give (7), include (7), edit (7), console (7), projectiamadmin (7), from (7), grants (7), function (7), security (7), audit (7), about (6), updated (6), send (6), temporary (6), apis (6), panel (6), headers (6), post (6), https (6), cloudresourcemanager (6), file (6), logs (6), make (6), write (6), writing (6), has (6), able (6), path (6), could (6), predefined (6), their (6), does (6), they (6), functions (6), than (6), usage (6), tools (6), oauth (6), logging (6), credentials (6), managed (6), requests (5), reference (5), token (5), expand (5), currently (5), active (5), one (5), replace (5), new (5), who (5), themselves (5), administrator (5), level (5), names (5), revoking (5), chose (5), will (5), values (5), within (5), storage (5), adding (5), services (5), ability (5), remove (5), her (5), pipelines (5), view (5), boundary (5), job (5), authenticate (5), workloads (5), português (4), español (4), understand (4), down (4), need (4), how (4), contains (4), explorer (4), tool (4), cred (4), print (4), authorization (4), bearer (4), charset (4), utf (4), named (4), assumes (4), logged (4), check (4), login (4), init (4), curl (4), shell (4), format (4), ids (4), like (4), roleadmin (4), end (4), warning (4), optional (4), must (4), read (4), principals (4), conditionally (4), however (4), choose (4), contain (4), returns (4), datasets (4), appengine (4), deny (4), short (4), lived (4), credential (4), elevated (4), delete (4), providers (4), product (4), microsoft (4), entra (4), sign (3), architecture (3), products (3), under (3), based (3), privilege (3), next (3), control (3), right (3), options (3), before (3), wrote (3), string (3), preceding (3), gets (3), selector (3), includes (3), included (3), where (3), but (3), true (3), consider (3), multiple (3), might (3), cannot (3), default (3), removing (3), existing (3), changes (3), help (3), own (3), guides (3), networking (3), monitor (3), scim (3), migrate (3), tags (3), related (3), key (3), gke (3), groups (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), join (2), terms (2), site (2), youtube (2), events (2), getting (2), started (2), system (2), support (2), pricing (2), missing (2), last (2), 2026 (2), utc (2), otherwise (2), licensed (2), details (2), license (2), feedback (2), learn (2), enforce (2), principle (2), least (2), what (2), store (2), should (2), returned (2), response (2), copy (2), open (2), opens (2), side (2), interact (2), paste (2), complete (2), fields (2), browser (2), invoke (2), webrequest (2), contenttype (2), infile (2), uri (2), object (2), powershell (2), windows (2), automatically (2), into (2), linux (2), macos (2), http (2), url (2), previous (2), alphanumeric (2), strings (2), numeric (2), 123456789012 (2), whose (2), replacements (2), finally (2), additional (2), briefly (2), describing (2), only_pubsub_roles (2), steps (2), formats (2), each (2), identifiers (2), lets (2), sure (2), change (2), policy_version (2), first (2), pattern (2), applied (2), download (2), after (2), update (2), apply (2), enter (2), name (2), selected (2), specific (2), organizationadmin (2), section (2), evaluates (2), both (2), false (2), operators (2), statements (2), customize (2), common (2), attributes (2), cases (2), bigquery (2), sections (2), herself (2), perform (2), actions (2), she (2), prevent (2), scenario (2), team (2), act (2), appadmin (2), appviewer (2), through (2), serviceusage (2), boundaries (2), large (2), documentation (2), sdk (2), languages (2), frameworks (2), infrastructure (2), costs (2), observability (2), monitoring (2), migration (2), industry (2), solutions (2), distributed (2), hybrid (2), multicloud (2), databases (2), analytics (2), hosting (2), development (2), errors (2), error (2), messages (2), review (2), patterns (2), integration (2), controls (2), optimize (2), configuration (2), test (2), restrict (2), settings (2), entitlements (2), legged (2), agents (2), disable (2), integrate (2), pools (2), libraries (2), deployment (2), federate (2), load (2), applications (2), federated (2), oidc (2), saml (2), okta (2), cross (2), technology (2), areas (2), close (2), subscribe, newsletter, our, third, decade, climate, action, cookies, privacy, tech, twitter, blog, engage, training, certification, center, github, status, release, notes, community, forums, contact, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missingtheinformationsamplesineed, otherdown, tell, except, noted, java, registered, trademark, oracle, its, affiliates, developers, apache, creative, commons, attribution, recommendations, treat, sent, shown, step, representation, sets, field, requestedpolicyversion, specify, most, recent, specifying, when, rest, containing, executing, highlighted, saved, current, closed, tab, previously, locate, button, appears, top, tells, working, chosen, buckets, objects, alternatively, folderiamadmin, follow, while, accept, represents, scope, override, bound, always, same, effect, either, single, fail, even, those, individually, logical, unconditionally, would, result, involving, empty, constants, because, input, uses, define, language, cel, modifies, defined, specifies, exception, behavior, still, specifically, regardless, placed, some, tries, fails, caution, explain, modifying, attached, member, only_compute_admin_role, escalation, instead, think, solution, others, words, only_appengine_admin_viewer_roles, describe, self, exact, folderadmin, ask, familiar, structure, created, likely, already, serviceusageadmin, begin, helpful, teams, independently, letting, greatly, increase, risk, categorize, preferences, stay, organized, collections, home, withcond, resolve, insights, history, analyze, privileged, secure, vpc, intelligence, securely, exfiltration, interfaces, restore, downscoped, approve, withdraw, remediate, excessive, entitlement, export, setup, lint, auditing, billing, grantable, suggestions, gemini, assistance, find, propagation, inheritance, deploy, built, managing, upload, public, rotation, run, customers, 509, certificates, kubernetes, directory, aws, azure, external, balancers, balancing, gce, attach, undelete, authentication, impersonation, obtain, power, pingone, aic, pingfederate, number, provisioning, client, discover, start, free, skip, main,


Text of the page (random words):
mples all identity and access management code samples code samples for all products ai and ml application development application hosting compute data analytics and pipelines databases distributed hybrid and multicloud industry solutions migration networking observability and monitoring security storage access and resources management costs and usage management infrastructure as code sdk languages frameworks and tools home documentation security iam guides send feedback set limits on granting roles stay organized with collections save and categorize content based on your preferences in large organizations it can be helpful to let teams independently manage the allow policies for their resources however letting a principal grant or revoke all iam roles can greatly increase your security risk you can set limits on the roles that a principal can grant and revoke with identity and access management iam conditions and the iam googleapis com modifiedgrantsbyrole api attribute these limits let you create limited iam admins who can manage their own team s allow policies but only within the boundaries that you have set before you begin enable the resource manager api roles required to enable apis to enable apis you need the serviceusage services enable permission if you created the project then you likely already have this permission through the owner role roles owner otherwise you can get this permission through the service usage admin role roles serviceusage serviceusageadmin learn how to grant roles enable the api be familiar with the structure of allow policies understand iam conditions required permissions to get the permissions that you need to create limited iam admins for a project folder or organization ask your administrator to grant you the following iam roles on the resource that you want to create a limited iam admin for project folder or organization to create a limited iam admin for a project project iam admin roles resourcemanager projectiamadmin to create a limited iam admin for a folder folder admin roles resourcemanager folderadmin to create a limited iam admin for a project folder or organization organization admin roles resourcemanager organizationadmin for more information about granting roles see manage access to projects folders and organizations these predefined roles contain the permissions required to create limited iam admins for a project folder or organization to see the exact permissions that are required expand the required permissions section required permissions the following permissions are required to create limited iam admins for a project folder or organization to create a limited iam admin for a project resourcemanager projects getiampolicy resourcemanager projects setiampolicy to create a limited iam admin for a folder resourcemanager folders getiampolicy resourcemanager folders setiampolicy to create a limited iam admin for an organization resourcemanager organizations getiampolicy resourcemanager organizations setiampolicy you might also be able to get these permissions with custom roles or other predefined roles common use cases the following sections describe how you can use limited role granting to enable self service management of allow policies create limited iam admins consider a scenario where you want to let a user noam act as a limited iam admin for your project you want noam to be able to grant and revoke only the app engine admin roles appengine appadmin and app engine viewer roles appengine appviewer roles for your project to grant this limited ability you conditionally grant noam the project iam admin role roles resourcemanager projectiamadmin the project iam admin role allows noam to grant and revoke iam roles and the condition limits which roles noam can grant and revoke version 3 etag bwwkmjvelug bindings members user owner example com role roles owner members user noam example com role roles resourcemanager projectiamadmin condition title only_appengine_admin_viewer_roles description only allows changes to role bindings with the app engine admin or viewer roles expression api getattribute iam googleapis com modifiedgrantsbyrole hasonly roles appengine appadmin roles appengine appviewer this conditional role binding lets noam do the following grant the app engine admin and app engine viewer roles for the project revoke the app engine admin and app engine viewer roles for the project add remove or modify conditions for project level role bindings that grant the app engine admin and app engine viewer roles perform other actions allowed by the project iam admin role that don t modify the project s allow policy for example noam could use the projects getiampolicy method to get the project s allow policy this conditional role binding does not let noam do any of the following modify allow policies for resources other than the project grant roles other than the app engine admin or app engine viewer roles revoke roles other than the app engine admin or app engine viewer roles add remove or modify conditions for role bindings that don t grant the app engine admin or app engine viewer roles allow users to manage limited iam admins consider a scenario where you want to make a user lila a limited iam admin for her team you want lila to be able to grant and revoke only the compute admin role roles compute admin for her project however you also want to let lila select other users to act as limited iam admins in other words you want to let lila allow other users to grant and revoke only the compute admin role you might think that the solution is to grant lila the project iam admin role roles resourcemanager projectiamadmin and then give her the ability to grant or revoke that role for others however if you grant lila the project iam admin role she could remove the condition from her own role and give herself the ability to grant or revoke any iam role to help prevent this privilege escalation you instead create a google group iam compute admins for the project s limited iam admins then you add lila to the group and make her a group manager after you create the group you conditionally grant the group the project iam admin role roles resourcemanager projectiamadmin the project iam admin role allows group members to grant and revoke iam roles and the condition limits which roles they can grant and revoke version 3 etag bwwkmjvelug bindings members user owner example com role roles owner members group iam compute admins example com role roles resourcemanager projectiamadmin condition title only_compute_admin_role description only allows changes to role bindings for the compute admin role expression api getattribute iam googleapis com modifiedgrantsbyrole hasonly roles compute admin as a member of the iam compute admins group lila can do the following grant the compute admin role for the project by adding a new binding for the role or by adding a principal to an existing binding for the role revoke the compute admin role by removing an existing binding for the role or by removing a principal from an existing binding for the role modify grants for the compute admin role by adding removing or modifying conditions attached to bindings for the role perform other actions allowed by the project iam admin role that don t modify the project s allow policy for example she could use the projects getiampolicy method to get the project s allow policy as a manager of the iam compute admins group lila can allow other users to grant or revoke the compute admin role by adding them to the iam compute admins group lila cannot do the following give herself the ability to grant or revoke other roles modify allow policies for resources other than the project grant roles other than the compute admin role revoke roles other than the compute admin role add remove or modify conditions for role bindings that don t grant the compute admin role limit role granting the following sections explain how to let principals grant or revoke only certain roles caution some google cloud services don t recognize limits on role granting if a limited iam admin tries to grant a role on a resource and the resource s service does not recognize limits on role granting then the request fails for a list of services that recognize limits on role granting see iam api attributes the exception to this behavior is bigquery datasets datasets don t recognize the modifiedgrantsbyrole attribute but limited iam admins can still grant or revoke roles on datasets specifically if a limited iam admin s role includes permissions to grant roles on datasets they can do so regardless of any limits placed on their role granting write a condition expression to limit role granting to limit a principal s ability to grant roles write a condition expression that specifies the roles a principal can grant or revoke use the following format for your condition expression api getattribute iam googleapis com modifiedgrantsbyrole hasonly roles this expression does the following gets the api attribute iam googleapis com modifiedgrantsbyrole using the api getattribute function for a request to set the allow policy of a resource this attribute contains the role names from the bindings that the request modifies for other types of requests the attribute is not defined in these cases the function returns the default value note not all services recognize the iam googleapis com modifiedgrantsbyrole attribute if a service does not recognize this attribute you cannot use this attribute to limit role granting for that service for a list of services that recognize this attribute see iam api attributes uses the hasonly common expression language cel function to define and enforce the roles that the principal is allowed to grant or revoke the input for the hasonly function is a list of the roles that the principal is allowed to grant or revoke if the roles in the iam googleapis com modifiedgrantsbyrole attribute are included in this list the function returns true if they are not the function returns false if the iam googleapis com modifiedgrantsbyrole attribute contains the default value the function returns true because does not contain any roles not included in the list to customize this expression replace roles with a list of the roles that the principal is allowed to grant or revoke for example to let the principal grant or revoke only the pub sub editor roles pubsub editor and pub sub publisher roles pubsub publisher roles use the value roles pubsub editor roles pubsub publisher you can include up to 10 values in the list of allowed roles all of these values must be string constants note you cannot customize the default value for api getattribute functions involving iam googleapis com modifiedgrantsbyrole it must be an empty list warning don t include the following types of roles in the list of allowed roles roles with permissions to grant and revoke iam roles that is roles with permission names that end in setiampolicy custom roles that the limited iam admin can modify for example if the limited iam admin also has the role administrator role roles iam roleadmin on a project don t allow them to grant or revoke project level custom roles both of these types of roles contain or could contain permission to modify allow policies as a result limited iam admins who can grant and revoke these types of roles can give themselves permission to grant and revoke all iam roles for example if a user is a limited iam admin for a project and you let them grant or revoke a custom role that they can modify they could add the resourcemanager projects setiampolicy permission to the custom role then grant themselves that role unconditionally they would then be able to grant and revoke all iam roles for the project logical operators for hasonly statements don t use the or operators to join multiple hasonly statements in a single condition if you do then requests that grant or revoke multiple roles might fail even if the principal can grant or revoke those roles individually for example consider the following condition api getattribute iam googleapis com modifiedgrantsbyrole hasonly roles pubsub editor api getattribute iam googleapis com modifiedgrantsbyrole hasonly roles pubsub publisher this condition evaluates to true if a request grants either the roles pubsub editor role or the roles pubsub publisher role but it evaluates to false if a request grants both the roles pubsub editor role and the roles pubsub publisher role limit role granting with conditional role bindings to allow a principal to grant or revoke only certain roles use the condition expression from the preceding section to create a conditional role binding then add the conditional role binding to a resource s allow policy note conditional role bindings do not override role bindings with no conditions if a principal is bound to a role and the role binding does not have a condition then the principal always has that role adding the principal to a conditional binding for the same role has no effect select a resource that represents the scope that you want to let a principal grant and revoke roles for if you want to let a principal grant and revoke certain roles for all resources within an organization select an organization if you want to let a principal grant and revoke certain roles for all resources within an folder select a folder if you want to let a principal grant and revoke certain roles for all resources within a project select a project note while other resource types recognize limits on role granting only projects folders and organizations accept conditions to limit role granting in their allow policies select a role that allows a principal to set the allow policy for the resource type you selected project folder or organization to follow the principle of least privilege choose one of the following predefined roles projects project iam admin roles resourcemanager projectiamadmin folders folder iam admin roles resourcemanager folderiamadmin organizations organization admin roles resourcemanager organizationadmin note this role also allows principals to set the allow policy for projects and folders alternatively choose a custom role that includes the resourcemanager resource type setiampolicy and resourcemanager resource type getiampolicy permissions where resource type is project folder or organization note you can also select a role that allows a principal to set the allow policy for specific resources within a project folder or organization for example you could select the storage admin role which includes permissions to set allow policies for buckets and objects however if you do so the principal will also be able to use the other permissions included in the role conditionally grant a principal your chosen role on the project folder or organization you selected the new allow policy is applied and your principal can modify bindings for only the roles you have allowed console in the google cloud console go to the iam...
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • Google Cloud Documentatio...

Verified site has: 204 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-204


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
location htt????/docs.cloud.google.com/iam/docs/setting-limits-on-granting-roles
x-cloud-trace-context d2788efef3164ac8857033906afef8a1
date Wed, 22 Jul 2026 16:31:34 GMT
content-type text/html
server Google Frontend
Content-Length 0
Connection close
HTTP/2 200
last-modified Tue, 21 Jul 2026 04:34:04 GMT
content-type text/html; charset=utf-8
vary Cookie
vary Accept-Encoding
content-security-policy base-uri self ; object-src none ; script-src strict-dynamic unsafe-inline https: http: nonce-H9oSrAlaufNQmBgb710g49SX1JkCGC unsafe-eval ; frame-ancestors self htt????/developers.google.com/_d/analytics-iframe; report-uri htt????/csp.withgoogle.com/csp/devsite/v2
strict-transport-security max-age=63072000; includeSubdomains; preload
x-xss-protection 0
x-content-type-options nosniff
cache-control no-cache, must-revalidate
expires 0
pragma no-cache
content-encoding gzip
x-cloud-trace-context 4b856131c7b9be268be310fb6d1a8c6a
date Wed, 22 Jul 2026 16:31:34 GMT
server Google Frontend
content-length 36302
alt-svc h3= :443 ; ma=2592000,h3-29= :443 ; ma=2592000

Meta Tags

title="Set limits on granting roles  |  Identity and Access Management (IAM)  |  Google Cloud Documentation"
name="google-signin-client-id" content="721724668570-nbkv1cfusk7kk4eni4pjvepaus73b13t.apps.googleusercontent.com"
name="google-signin-scope" content="profile email htt????/www.googleapis.com/auth/developerprofiles htt????/www.googleapis.com/auth/developerprofiles.award htt????/www.googleapis.com/auth/devprofiles.full_control.firstparty"
property="og:site_name" content="Google Cloud Documentation"
property="og:type" content="website"
name="theme-color" content="#1a73e8"
charset="utf-8"
content="IE=Edge" http-equiv="X-UA-Compatible"
name="viewport" content="width=device-width, initial-scale=1"
property="og:title" content="Set limits on granting roles  |  Identity and Access Management (IAM)  |  Google Cloud Documentation"
property="og:url" content="htt????/docs.cloud.google.com/iam/docs/setting-limits-on-granting-roles"
property="og:image" content="htt????/docs.cloud.google.com/_static/cloud/images/social-icon-google-cloud-1200-630.png"
property="og:image:width" content="1200"
property="og:image:height" content="630"
property="og:locale" content="en"
name="twitter:card" content="summary_large_image"

Load Info

page size36302
load time (s)0.498176
redirect count1
speed download72895
server IP 142.251.39.206
* all occurrences of the string "http://" have been changed to "htt???/"