In IAM, you grant a role to a principal on a resource. A principal can be a Google account, a Google group, a service account, a Cloud Identity or Workspace domain, or special identifiers such as allUsers. A role is a collection of permissions, such as compute.instances.start. The combination of principals and a role is a binding, and all bindings on a resource form its allow policy.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.