Skip to main content

Frequently Asked Questions

Why are Basic roles like Owner or Editor discouraged in production GCP environments?

Basic roles predate Google's fine-grained IAM system and grant sweeping access across nearly every service in a Project — Editor, for instance, can modify almost any resource, not just the ones a user's job actually requires. This violates least-privilege and makes audit trails less useful, since 'why does this account have Editor' doesn't tell you what it's actually supposed to do; Google's own guidance is to use Predefined roles for standard needs and reserve Basic roles for early prototyping only.

When does a team need Custom roles instead of just combining Predefined roles?

Custom roles make sense when the closest Predefined role grants meaningfully more permissions than needed — for example a role that needs to read Compute Engine metadata but never start or stop instances. The tradeoff is maintenance burden: Custom roles don't automatically pick up new permissions as GCP services evolve, so teams must manually update them over time, whereas Predefined roles are maintained by Google as services change.