Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from space DEV and version r085

...

RoleUsePermissions and roles
roles/dataprep.projects.user

Enables a user to run

D s product
productgdp
in a project See below.

Permissions:

  • dataprep.projects.use
  • resourcemanager.projects.get
  • serviceusage.quotas.get
  • serviceusage.services.get
  • serviceusage.services.list
roles/dataprep.serviceAgent

Enables the platform to access and modify datasets and storage and to run and manage

D s dataflow
jobs on behalf of the user within the project

Info

NOTE: When the product is enabled within a project, this role is granted by the project owner as part of the enablement process. For more information, see Enable or Disable Dataprep.

Permissions:

  • storage.buckets.get
  • storage.buckets.list

Roles:

  • roles/dataflow.developer
  • roles/bigquery.user
  • roles/bigquery.dataEditor
  • roles/storage.objectAdmin
  • roles/iam.serviceAccountUser

roles/dataprep.projects.user IAM Role

All users of any version of

D s product
productgdp
must be assigned the roles/dataprep.user IAM Role.

...

PermissionProduct Use
dataflow.jobs.cancel

Enables users to cancel their jobs in progress. It is not required for the product to work but may be helpful to add via IAM roles.

Info

NOTE: A user may be able cancel a job from the

D s webapp
, even though the user is not permitted to cancel the job in the running environment. The service account associated with the user's 
D s item
itemaccount
may have the appropriate permissions, but the user's personal account does not. For more information, see Google Service Account Management

BigQuery publishing options

...

Google Sheets access

D s ed
rtrue
editionsgdpstgdpent,gdppro,gdpsta,gdppr,gdpst

  • drive.readonly

For more information, see Import Google Sheets Data.

Additional Permissions for Cloud IAM

D s ed
rtrue
editionsgdpent,gdppr

Info

NOTE: Any change in a user's permissions in

D s platform
must be reflected in the service account assigned to the user.

...