Create a service account
Create a service account and list the service accounts in your tenant:Give the account access
Use Roles and bindings to create a custom role and assign it withmthr iam.
Sign in as an active tenant owner. Choose an enabled custom role belonging to
the same tenant as the active service account. Built-in roles, including Owners,
cannot be assigned to service accounts.
bindings ls. A new role version does not change existing assignments.
The existing mthr service-accounts grants commands remain available.
Manage credentials
Issue a credential for the automation:Disable a service account
Deactivate the service account when the automation is retired:Revoke access
Copy the binding ID from the direct-grants list returned bymthr iam bindings ls --service-account-id SERVICE_ACCOUNT_ID, then revoke
that assignment: