Flow roles and permissions
Stay organized with collections
Save and categorize content based on your preferences.
This page lists the IAM roles and permissions for Flow. To
search through all roles and permissions, see the role and
permission index.
Flow roles
| Role |
Permissions |
Flow Admin
Beta
(roles/flow.admin)
Full access to all Flow resources. Intended for project administrators.
|
resourcemanager.projects.get
resourcemanager.projects.list
|
Flow Editor
Beta
(roles/flow.editor)
Create and manage Flow generated media. Intended for content creators.
|
resourcemanager.projects.get
resourcemanager.projects.list
|
Service agent roles
Service agent roles should only be granted to service agents.
| Role |
Permissions |
FlowService Service Agent
(roles/aisandbox.serviceAgent)
Grants FlowService Service Agent permissions to manage resources in the consumer project.
|
aiplatform.endpoints.predict
aiplatform.interactions.create
aiplatform.interactions.get
logging.logEntries.create
logging.logEntries.route
serviceusage.services.use
|
Flow Service Agent
(roles/flow.serviceAgent)
Grants Flow Service Agent permissions to manage resources in the consumer project.
|
aiplatform.endpoints.predict
aiplatform.interactions.create
aiplatform.interactions.get
logging.logEntries.create
logging.logEntries.route
serviceusage.services.use
|
Flow permissions
There are no IAM permissions for this service.
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-09-30 UTC.
[null,null,["Last updated 2026-09-30 UTC."],[],[]]