GCP Permissions
Introduction
GCP Permissions are the least-privilege policies CoreStack requires to onboard and manage a Google Cloud project. CoreStack uses these permissions to ingest cost, inventory, configuration, and security data from your project, and — where read-write access is granted — to execute policy-based remediation. This page is relevant before onboarding any GCP project, or when adding a new product to an existing one. It applies to Account Admin and Provider Admin users who manage cloud account onboarding.
How It Works
Once GCP permissions are granted, cost and usage data syncs daily to twice daily via the Cloud Billing export to BigQuery. Inventory, configuration, policy evaluation, and access-posture data sync every 24 hours (configurable). Utilization metrics sync on a 4, 8, or 24-hour user-selectable interval via Cloud Monitoring. Activity and audit events ingest near real-time via a Cloud Logging sink routed to Pub/Sub. Threat findings ingest periodically. Each ingestion path runs as an independently observable process with its own run history and on-demand re-run, visible in Governance > Cloud Accounts > Account Status & Configurations.
Refer to the following user guides to get a summary of which least privilege policies are required to setup in your GCP cloud portal for different products and access levels
Updated 3 days ago