Google 会使用 AI 技术将内容翻译成您偏好的语言。AI 翻译可能包含错误。
角色与权限
使用集合让一切井井有条
根据您的偏好保存内容并对其进行分类。
本页面列出了 Agent Registry 的 IAM 角色和权限。
向将在注册表中管理或查看代理的用户或群组授予相应的代理注册表 IAM 角色。如需授予角色,您可以使用 Google Cloud 控制台中的“IAM”页面或 Google Cloud CLI。如需查看详细说明,请参阅管理对项目、文件夹和组织的访问权限。
Agent Registry 角色
下表介绍了 Agent Registry IAM 角色及其典型职责:
角色 |
说明 |
用途 |
Agent Registry API Admin |
执行所有操作,包括手动注册代理和更新元数据。
|
- 注册和管理代理和 MCP 服务器。
- 更新了工具定义和端点。
|
Agent Registry API 编辑器 |
拥有对 Agent Registry 资源的编辑权限。
|
- 注册和管理代理和 MCP 服务器。
- 更新了工具定义和端点。
|
Agent Registry API Viewer |
查看代理、工具及其属性。
|
- 发现可用的代理和 MCP 服务器。
- 查看 A2A 技能、独立技能和用于集成的端点。
|
Agent Registry User |
创建、更新和删除技能和技能修订版本。
|
- 管理 Agent Registry 中代理的独立技能。
- 保留技能修订版本的版本控制,并集中管理技能的有效状态。
|
Agent Registry 权限
下表列出了每个 Agent Registry IAM 角色拥有的权限:
Agent Registry API Admin
Beta 版
(roles/agentregistry.admin)
拥有对 Agent Registry API 资源的完整访问权限。
|
agentregistry.*
agentregistry.agents.get
agentregistry.agents.list
agentregistry.agents.search
agentregistry.bindings.create
agentregistry.bindings.delete
agentregistry.bindings.fetchAvailable
agentregistry.bindings.get
agentregistry.bindings.list
agentregistry.bindings.update
agentregistry.endpoints.get
agentregistry.endpoints.list
agentregistry.locations.get
agentregistry.locations.list
agentregistry.mcpServers.get
agentregistry.mcpServers.list
agentregistry.mcpServers.search
agentregistry.operations.cancel
agentregistry.operations.delete
agentregistry.operations.get
agentregistry.operations.list
agentregistry.publishers.get
agentregistry.publishers.list
agentregistry.services.create
agentregistry.services.delete
agentregistry.services.get
agentregistry.services.list
agentregistry.services.update
agentregistry.skillRevisions.create
agentregistry.skillRevisions.delete
agentregistry.skillRevisions.get
agentregistry.skillRevisions.list
agentregistry.skills.create
agentregistry.skills.delete
agentregistry.skills.get
agentregistry.skills.list
agentregistry.skills.search
agentregistry.skills.update
|
Agent Registry API Editor
Beta 版
(roles/agentregistry.editor)
拥有对 Agent Registry API 资源的编辑权限。
|
agentregistry.agents.*
agentregistry.agents.get
agentregistry.agents.list
agentregistry.agents.search
agentregistry.bindings.fetchAvailable
agentregistry.bindings.get
agentregistry.bindings.list
agentregistry.endpoints.*
agentregistry.endpoints.get
agentregistry.endpoints.list
agentregistry.locations.*
agentregistry.locations.get
agentregistry.locations.list
agentregistry.mcpServers.*
agentregistry.mcpServers.get
agentregistry.mcpServers.list
agentregistry.mcpServers.search
agentregistry.operations.*
agentregistry.operations.cancel
agentregistry.operations.delete
agentregistry.operations.get
agentregistry.operations.list
agentregistry.publishers.*
agentregistry.publishers.get
agentregistry.publishers.list
agentregistry.services.*
agentregistry.services.create
agentregistry.services.delete
agentregistry.services.get
agentregistry.services.list
agentregistry.services.update
agentregistry.skillRevisions.*
agentregistry.skillRevisions.create
agentregistry.skillRevisions.delete
agentregistry.skillRevisions.get
agentregistry.skillRevisions.list
agentregistry.skills.*
agentregistry.skills.create
agentregistry.skills.delete
agentregistry.skills.get
agentregistry.skills.list
agentregistry.skills.search
agentregistry.skills.update
|
Agent Registry API Viewer
Beta 版
(roles/agentregistry.viewer)
拥有对 Agent Registry API 资源的只读权限。
|
agentregistry.agents.*
agentregistry.agents.get
agentregistry.agents.list
agentregistry.agents.search
agentregistry.bindings.fetchAvailable
agentregistry.bindings.get
agentregistry.bindings.list
agentregistry.endpoints.*
agentregistry.endpoints.get
agentregistry.endpoints.list
agentregistry.locations.*
agentregistry.locations.get
agentregistry.locations.list
agentregistry.mcpServers.*
agentregistry.mcpServers.get
agentregistry.mcpServers.list
agentregistry.mcpServers.search
agentregistry.operations.get
agentregistry.operations.list
agentregistry.publishers.*
agentregistry.publishers.get
agentregistry.publishers.list
agentregistry.services.get
agentregistry.services.list
agentregistry.skillRevisions.get
agentregistry.skillRevisions.list
agentregistry.skills.get
agentregistry.skills.list
agentregistry.skills.search
|
Agent Registry User
Beta 版
(roles/agentregistry.user)
创建、更新和删除技能和技能修订版本。
|
agentregistry.agents.*
agentregistry.agents.get
agentregistry.agents.list
agentregistry.agents.search
agentregistry.bindings.fetchAvailable
agentregistry.bindings.get
agentregistry.bindings.list
agentregistry.endpoints.*
agentregistry.endpoints.get
agentregistry.endpoints.list
agentregistry.locations.*
agentregistry.locations.get
agentregistry.locations.list
agentregistry.mcpServers.*
agentregistry.mcpServers.get
agentregistry.mcpServers.list
agentregistry.mcpServers.search
agentregistry.operations.get
agentregistry.operations.list
agentregistry.publishers.*
agentregistry.publishers.get
agentregistry.publishers.list
agentregistry.services.get
agentregistry.services.list
agentregistry.skillRevisions.*
agentregistry.skillRevisions.create
agentregistry.skillRevisions.delete
agentregistry.skillRevisions.get
agentregistry.skillRevisions.list
agentregistry.skills.*
agentregistry.skills.create
agentregistry.skills.delete
agentregistry.skills.get
agentregistry.skills.list
agentregistry.skills.search
agentregistry.skills.update
|
如需详细了解 IAM 权限,请参阅找到合适的预定义角色和 IAM 角色和权限索引。
针对已注册资源的访问权限控制
Agent Registry 角色用于控制哪些人可以管理和发现注册表中的资源。如需控制哪些智能体可以通过Agent Gateway与已注册的服务、端点和 MCP 服务器通信,您可以使用 Identity-Aware Proxy 出站流量政策:
如需详细了解如何配置 IAP 出站政策,请参阅配置 IAM 代理政策。
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2026-09-10。
[null,null,["最后更新时间 (UTC):2026-09-10。"],[],[]]