角色与权限

本页面列出了 Agent Registry 的 IAM 角色和权限。

向将在注册表中管理或查看代理的用户或群组授予适当的 Agent Registry IAM 角色。如需授予 角色,您可以使用控制台中的 Google Cloud IAM 页面或 Google Cloud CLI。如需查看详细说明,请参阅 管理对项目、文件夹和组织的访问权限

Agent Registry 角色

下表介绍了 Agent Registry IAM 角色及其典型职责:

角色

说明

用途

Agent Registry API Admin

执行所有操作,包括手动注册代理和 更新元数据。

  • 注册和管理代理和 MCP 服务器。
  • 更新工具定义和端点。

Agent Registry API Editor

拥有对 Agent Registry 资源的编辑权限。

  • 注册和管理代理和 MCP 服务器。
  • 更新工具定义和端点。

Agent Registry API Viewer

查看代理、工具及其属性。

  • 发现可用的代理和 MCP 服务器。
  • 查看用于集成的技能和端点。

Agent Registry 权限

下表列出了每个 Agent Registry IAM 角色拥有的权限:

(roles/agentregistry.admin)

拥有对 Agent Registry API 资源的完整访问权限。

agentregistry.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search
  • agentregistry.bindings.create
  • agentregistry.bindings.delete
  • agentregistry.bindings.fetchAvailable
  • agentregistry.bindings.get
  • agentregistry.bindings.list
  • agentregistry.bindings.update
  • agentregistry.endpoints.get
  • agentregistry.endpoints.list
  • agentregistry.locations.get
  • agentregistry.locations.list
  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search
  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list
  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

(roles/agentregistry.editor)

拥有对 Agent Registry API 资源的编辑权限。

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.*

  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list

agentregistry.services.*

  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

(roles/agentregistry.viewer)

拥有对 Agent Registry API 资源的只读权限。

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.services.get

agentregistry.services.list

如需详细了解 IAM 权限,请参阅 查找合适的预定义角色IAM 角色和权限索引