Project-level policies
Below the organization, we have Google Cloud projects. Primitive roles granted at the project level apply to all resources within the project. As with organizations, it is generally a best practice to have more than one project owner. Project owners have full control over all project resources, including IAM and billing. Project Editors can control all resources in the project except for IAM and billing. Project viewers on the other hand cannot directly control any project resources, unless otherwise specified at the resource level. A common practice is to assign project viewer to all members.
Aside from primitive roles, curated roles can be created at the project level to define access for all resources of a given ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access