In Google Cloud you never grant permissions directly; you grant roles, which are collections of permissions. A permission has the form service.resource.verb, such as compute.instances.start or storage.objects.get. Picking the right role is the core of least privilege: give each principal only the access its job requires, at the narrowest scope that works.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.