Google Associate Cloud EngineerSetting up a cloud solution environmentMedium
A financial services company requires strict control over who can create new Google Cloud projects. They want to delegate project creation rights to a specific team without granting them broader administrative privileges. Which IAM role is the LEAST permissive role that allows a user to create new projects within an organization?
- AProject Creator
- BBilling Account User
- CFolder Admin
- DOrganization Administrator
Show answer & explanationAnswer & explanation
Correct answer: A. Project Creator
The 'Project Creator' role is specifically designed to allow users to create new projects. It is less permissive than 'Organization Administrator' or 'Folder Admin' and does not grant unrelated billing permissions.
Why the other options are wrong
- B. Billing Account User manages billing accounts, not project creation itself.
- C. Folder Admin grants administrative access within a specific folder, but the 'Project Creator' role is more granular for just project creation.
- D. Organization Administrator grants very broad permissions across the entire organization, which is too permissive.
Project Creator Role
The 'Project Creator' IAM role grants permissions to create new Google Cloud projects within an organization or folder.
- Scoped to an organization or folder.
- Allows 'resourcemanager.projects.create' permission.
- Does not grant permissions to manage existing projects.
Memory trick: To create a project, you need the 'Creator' key, not the master key.