GCP Permissions List
Detailed mapping of GCP IAM roles and permissions required by Wiv for cost optimization and resource analysis.
Written By Dotan Cohen
Last updated About 2 months ago
GCP Permissions List
1. Billing Data & BigQuery Analysis
Processing the billing export, and BigQuery-specific optimization.
2. Core Compute & Optimization Engine
These permissions are critical for primary Compute Engine recommendations (Rightsizing, Idle VMs, Snapshots, etc.).
3. GKE & Kubernetes Optimization
These roles specifically power the Container and Cluster analysis features.
4. Database & Storage Optimization
Permissions required for analyzing managed databases.
5. Resource Inventory & Network Visibility
These permissions allow us mapping "Ghost" costs—resources that appear on the bill but are hard to locate without specific viewer roles.
6. Serverless, PaaS & Security Posture
While your current primary list focuses on Compute/GKE, these permissions are required for comprehensive cost observability. If a client spends money on Cloud Run or Dataflow, Wiv needs these to visualize and attribute those costs correctly.
Summary
Wiv requests Viewer-only permissions. We do not request permissions to modify, delete, or deploy resources. The roles requested allow us to:
Read Metrics: To mathematically prove a resource is idle or oversized (Monitoring/Compute/Container roles).
Process Billing: To aggregate your spend data securely (BigQuery roles).
Map Inventory: To ensure every line item on your invoice corresponds to a visible resource (Cloud Asset/PaaS roles).