IAM Helper for Policy Management
Orchestrates the lifecycle and management of IAM allow and deny policies across IAM v1 (allow policies) and IAM v2 (deny policies).
Core Concepts & Paradigms
IAM operates across two policy paradigms:
Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2). Manages access control across Resource Manager resources (Organization, Folder, Project) and individual resources. Use when creating, updating, listing, or deleting IAM allow policies or deny policies. Don't use for access denial troubleshooting (use iam-helper-for-troubleshooting), temporary privileged access (use iam-helper-for-privileged-access-management), configuring VPC Service Controls, or managing network firewall rules.
Permissions
Files
Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2). Manages access control across Resource Manager resources (Organization, Folder, Project) and individual resources. Use when creating, updating, listing, or deleting IAM allow policies or deny policies. Don't use for access denial troubleshooting (use iam-helper-for-troubleshooting), temporary privileged access (use iam-helper-for-privileged-access-management), configuring VPC Service Controls, or managing network firewall rules.
Orchestrates the lifecycle and management of IAM allow and deny policies across IAM v1 (allow policies) and IAM v2 (deny policies).
IAM operates across two policy paradigms:
Version history
When receiving a policy management request, determine whether the operation is Read-Only or Mutating, and whether it targets IAM v1 (Allow Policies) or IAM v2 (Deny Policies):
Read-only actions include the following:
get-iam-policy on project/folder/organization,
or gcloud iam list-testable-permissions //cloudresourcemanager.googleapis.com/projects/PROJECT_ID.gcloud iam policies list or gcloud iam policies get with --attachment-point and --kind=denypolicies.For read-only actions, execute the command autonomously to inspect state, and present the query results clearly to the user.
Mutating operations include the following:
add-iam-policy-binding,
remove-iam-policy-binding, or set-iam-policy across project, folder,
organization, or resource levels (see
references/v1-allow-policies.md).create, update, or delete deny policies on
attachment points
(cloudresourcemanager.googleapis.com/projects/PROJECT_ID,
cloudresourcemanager.googleapis.com/folders/FOLDER_ID, or
cloudresourcemanager.googleapis.com/organizations/ORG_ID) using YAML/JSON
policy files (see
references/v2-deny-policies.md).For mutating operations, follow the Plan & Confirm Protocol below. DO NOT execute mutating commands autonomously without prior user approval.
gcloud commands directly via tool calls without
explicit prior confirmation from the user. When asked to apply a mutating
change, do the following:
gcloud command (including all parameters such as --member, --role,
--attachment-point, --kind=denypolicies, and --policy-file).allUsers or allAuthenticatedUsers basic roles (roles/owner,
roles/editor, roles/viewer, roles/admin, roles/writer, and
roles/reader) or broad permissions. Explicitly refuse blanket public
access requests, explain the severe security risks of public project
ownership/access, and propose scoped, least-privileged role bindings for
specific authenticated identities instead.In these kits
More from @google
Works with
Claude, Codex, Cursor & more