Controlling who can do what.
WHAT THE MODEL IS
Permissions granted through roles, assigned to identities, at a scope.
WHAT IDENTITIES EXIST
User accounts Groups Service accounts, for applications Federated identities from other providers
WHAT ROLE TYPES EXIST
Basic roles, which are very broad Predefined roles, scoped to a service Custom roles, defined by you
WHAT TO AVOID
Basic roles, particularly owner and editor.
WHY
They grant far more than almost any task requires.
WHAT TO ASSIGN
The narrowest predefined role that permits the work.
WHAT SCOPE TO ASSIGN AT
The narrowest: a resource rather than a project, a project rather than a folder.
WHAT TO ASSIGN TO
Groups, not individuals.
WHY
Individual assignments accumulate and are never removed.
WHAT A SERVICE ACCOUNT IS
An identity for an application rather than a person.
WHAT TO NEVER DO
Create service account keys and distribute them.
WHY
They are long-lived credentials that leak.
WHAT TO USE INSTEAD
Attached identities, or workload identity federation.