service:Method. Action IDs are case-sensitive,
and mthr iam roles create rejects an ID that is not in the tables below.
Pass these IDs to mthr iam roles create --action. See
Roles and bindings for the full workflow.
Account
Billing
Kubernetes access
Actions reserved to Owners
Member administration, service-account administration, and access administration stay with the built-in Owners role. A custom role that requests one of these is rejected. To use them, a person needs an Owners binding:authorization:CreateRole,authorization:DisableRole,authorization:CreateBinding,authorization:DisableBindingdirectory:InviteMember,directory:ResendInvitation,directory:CancelInvitation,directory:GetInvitation,directory:GetMember,directory:ListMembers,directory:DeactivateMember,directory:BeginOffboardingdirectory:CreateServiceAccount,directory:ListServiceAccounts,directory:DeactivateServiceAccountauthentication:CreateServiceAccountCredential,authentication:ListServiceAccountCredentials,authentication:RotateServiceAccountCredential,authentication:RevokeServiceAccountCredential