Skip to main content

Frequently Asked Questions

Why would an organization use GCP Folders instead of just tagging Projects with labels?

Labels are metadata only — they don't propagate IAM permissions or Organization Policies. Folders are actual nodes in the resource hierarchy, so granting a role or applying a policy constraint at the Folder level automatically inherits down to every Project (and nested Folder) inside it, without re-applying anything per-Project. This is what makes Folders useful for enforcing department- or environment-wide governance in one place.

What's a common structuring mistake when designing a GCP Folder hierarchy?

Nesting Folders too deeply (GCP allows up to 10 levels) to mirror an org chart makes IAM auditing harder, since permissions can be inherited from several layers up and are non-obvious without tracing the whole chain. A flatter structure — typically by environment (prod/non-prod) at the top level and team or product below that — keeps policy inheritance traceable and is the more common practical pattern than deep org-chart mirroring.