GCP IAM Role Types
Google Cloud IAM roles come in three types: Basic roles (Owner, Editor, Viewer) which are broad and legacy; Predefined roles curated by Google and scoped to a specific service's specific needs; and Custom roles built from individual permissions for access needs a predefined role doesn't precisely match.
Frequently Asked Questions
Why are Basic roles like Owner or Editor discouraged in production GCP environments?
Basic roles predate Google's fine-grained IAM system and grant sweeping access across nearly every service in a Project — Editor, for instance, can modify almost any resource, not just the ones a user's job actually requires. This violates least-privilege and makes audit trails less useful, since 'why does this account have Editor' doesn't tell you what it's actually supposed to do; Google's own guidance is to use Predefined roles for standard needs and reserve Basic roles for early prototyping only.
When does a team need Custom roles instead of just combining Predefined roles?
Custom roles make sense when the closest Predefined role grants meaningfully more permissions than needed — for example a role that needs to read Compute Engine metadata but never start or stop instances. The tradeoff is maintenance burden: Custom roles don't automatically pick up new permissions as GCP services evolve, so teams must manually update them over time, whereas Predefined roles are maintained by Google as services change.