Skip to main content
compliance · gcp

GCP projects that grant the legacy Owner, Editor or Viewer basic roles

rule IDs covered
1
severity
high
resource types
all

What does ZopNight detect here?

Google Cloud's legacy basic roles `roles/owner`, `roles/editor` and `roles/viewer` each carry thousands of permissions across every service, and Google says not to grant them in production unless there is no alternative. ZopNight raises one high-severity finding per project for each of these roles that appears in the project's IAM policy.

Signal and threshold

How ZopNight evaluates GCP projects that grant the legacy Owner, Editor or Viewer basic roles.
Field Value
Rule IDsRC-1250
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdroles/owner, roles/editor or roles/viewer bound in the project policy
SourceZopNight
Permissions usedresourcemanager.projects.getIamPolicy

How broad the basic roles really are

Owner, Editor and Viewer predate IAM; Google’s docs now call them the legacy basic roles. The roles overview describes basic roles as highly permissive and warns that they include thousands of permissions across all Google Cloud services. Viewer grants read-only access across most services. Editor adds the ability to create and delete resources in most services. Owner adds managing roles and permissions for the project and setting up billing.

Two details make them worse than they look. Holders also get extra access some services give to basic-role members, such as Cloud Storage convenience values and BigQuery special groups. And unlike other roles, conditions cannot be added to bindings for the legacy basic roles, so you cannot limit them by time or resource.

Finding basic-role bindings

Terminal window
gcloud projects get-iam-policy PROJECT_ID \
--flatten=bindings \
--filter="bindings.role=roles/owner OR bindings.role=roles/editor OR bindings.role=roles/viewer" \
--format="value(bindings.role, bindings.members)"

Each row is a role and the principals holding it. Watch for service accounts in the list: default service accounts may have received Editor automatically when their API was enabled.

One finding per role, per project

ZopNight reads the project IAM policy and represents each distinct role in it as its own record, scoped to that project. Records for roles/owner, roles/editor and roles/viewer are marked as basic roles, and each of those raises one finding. A project that uses all three gets three findings; ten Editor members still produce a single Editor finding. No usage data or time window is involved.

What the rule leaves to other checks

Predefined and custom roles never trigger this rule, however broad they are. Predefined roles bound at the project level that could be scoped to a single resource are handled by GCP IAM Project-Level Role Binding, and service accounts holding admin-level roles by GCP Service Account Has Admin Role. Grants made on a folder or the organization are not read as part of the project.

Blast radius, not a saving

The saving is $0. The risk is what a single compromised member can do: with Editor, delete almost anything in the project; with Owner, also grant themselves or others more access.

Replacing basic roles with narrow ones

  1. For each member, work out what they actually do. Google’s role recommendations flag unused permissions and suggest smaller roles.
  2. Grant the matching predefined roles, for example roles/storage.objectCreator for a member that only uploads files, or a custom role.
  3. Remove the basic role with gcloud projects remove-iam-policy-binding PROJECT_ID --member=MEMBER --role=roles/editor.
  4. Test that applications and people can still do their jobs. The finding closes on the next inventory once no member holds the role.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·