GCP: Inventory Permissions
This page outlines the permissions required for the Google Cloud Platform (GCP) inventory connector. Enable these permissions to view the resource listing in the inventory tab.
As cloud environments evolve and providers introduce API changes, required permissions may change as well. These permissions are reviewed and updated with each product release to reflect the latest requirements. Stale API entries are periodically removed, and updates are included in subsequent releases.
| Resource | Permissions |
|---|---|
| Address Groups | networksecurity.addressGroups.list networksecurity.locations.list |
| Agent Registry | agentregistry.agents.list |
| Cloud Functions | cloudfunctions.functions.list compute.regions.list compute.zones.list |
| Cloud Run Services | run.locations.list run.services.list |
| Firewall | compute.firewalls.list compute.regions.list compute.zones.list |
| Firewall Policy | compute.forwardingRules.list |
| Kubernetes clusters | container.clusters.list |
| Load Balancing | compute.forwardingRules.list |
| Model Registry | aiplatform.models.list |
| Network | compute.networks.list compute.regions.list compute.zones.list |
| Subnetwork | compute.subnetworks.list compute.regions.list compute.zones.list |
| Virtual Machines | compute.instances.list compute.regions.list compute.zones.list resourcemanager.projects.list (mandatory permission) |