Skip to main content
A role version contains an exact set of actions. Each action ID identifies one operation and is written service:Method. Action IDs are case-sensitive, and mthr iam roles create rejects an ID that is not in the tables below. Pass these IDs to mthr iam roles create --action. See Roles and bindings for the full workflow.

Account

Billing

Kubernetes access

Actions reserved to Owners

Member administration, service-account administration, and access administration stay with the built-in Owners role. A custom role that requests one of these is rejected. To use them, a person needs an Owners binding:
  • authorization:CreateRole, authorization:DisableRole, authorization:CreateBinding, authorization:DisableBinding
  • directory:InviteMember, directory:ResendInvitation, directory:CancelInvitation, directory:GetInvitation, directory:GetMember, directory:ListMembers, directory:DeactivateMember, directory:BeginOffboarding
  • directory:CreateServiceAccount, directory:ListServiceAccounts, directory:DeactivateServiceAccount
  • authentication:CreateServiceAccountCredential, authentication:ListServiceAccountCredentials, authentication:RotateServiceAccountCredential, authentication:RevokeServiceAccountCredential
Owners can still review and revoke any assignment, including one made by another owner. See Members and Service accounts for those workflows.

Inspect a role

The result lists the role’s exact actions, its version, and the action catalog that validated it. A role you create keeps that catalog for its lifetime.