Anthos roles and permissions
Stay organized with collections
Save and categorize content based on your preferences.
This page lists the IAM roles and permissions for Anthos. To
search through all roles and permissions, see the role and
permission index.
Anthos roles
Anthos offers the following service agent roles.
Service agent roles should only be granted to service agents.
| Role |
Permissions |
Anthos Service Agent
(roles/anthos.serviceAgent)
Gives the Anthos service agent access to Google Cloud resources.
|
gkehub.features.get
gkehub.locations.*
gkehub.locations.get
gkehub.locations.list
gkehub.memberships.get
gkehub.memberships.list
serviceusage.consumerpolicy.analyze
serviceusage.consumerpolicy.get
serviceusage.effectivepolicy.get
serviceusage.groups.*
serviceusage.groups.list
serviceusage.groups.listExpandedMembers
serviceusage.groups.listMembers
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
|
Anthos permissions
There are no IAM permissions for this service.
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-07-29 UTC.
[null,null,["Last updated 2026-07-29 UTC."],[],[]]