approvGCP

Govern GCP access without shared Owner roles

Connect a service account once, import projects and resources, then approve grants that Sync real IAM — projects, BigQuery, Storage, Pub/Sub, and Cloud SQL.

How it works

From service account to Sync’d IAM

Connect once, import what you govern, then Sync access when grants are approved.

  1. 01

    Connect GCP

    Create a service account, grant it Project IAM Admin (and resource Admin roles you need), enable APIs, then paste the JSON key in Approv.

  2. 02

    Import resources

    Import projects, then use the shared project picker to import BigQuery, Storage, Pub/Sub, or Cloud SQL into Approv resources.

  3. 03

    Request → approve → Sync

    Members request a permission level. Approvers grant access. Approv Syncs IAM to Google Cloud and keeps an audit trail.

Connect

One service account for the org

Upload a GCP service account JSON key. Approv encrypts it and validates Resource Manager access — then you import only the projects and resources you want to govern.

  • Enable Cloud Resource Manager and the APIs you import against
  • Grant Project IAM Admin plus Admin roles for BigQuery, Storage, Pub/Sub, or Cloud SQL as needed
  • Paste the JSON key once — credentials stay encrypted
Laptop on a desk ready for GCP setup

Resources

What you can govern in GCP

Import these resources into Approv, then approve access with mapped GCP IAM roles.

  • 01

    Projects

    Import projects and Sync viewer, editor, or owner roles.

  • 02

    BigQuery

    Import datasets and tables; Sync dataset IAM roles.

  • 03

    Cloud Storage

    Import buckets and Sync object viewer, creator, or admin.

  • 04

    Pub/Sub

    Import topics and subscriptions; Sync subscriber, publisher, or admin.

  • 05

    Cloud SQL

    Import instances and databases; Sync client, instance user, or admin with an instance IAM condition.

Team approving access with a thumbs up

Sync

Approved grants become real IAM

On approve, Approv binds the member’s Google email to the mapped role. On revoke or expire, the binding is removed — including Cloud SQL grants scoped with an instance IAM condition.

  • Project, dataset, bucket, Pub/Sub, and Cloud SQL mappings
  • Time-bound access that Syncs removal when it ends
  • Full audit trail of who approved what, and when

Mapping

Permission mapping

Approv permission levels map to native GCP roles when Sync runs.

In ApprovIn GCP
Project · Viewer / Editor / Ownerroles/viewer · editor · owner
BigQuery · Viewer / Editor / Adminbigquery.dataViewer · dataEditor · admin
Storage · Viewer / Creator / Adminstorage.objectViewer · objectCreator · admin
Pub/Sub · Subscriber / Publisher / Adminpubsub.subscriber · publisher · admin
Cloud SQL · Client / Editor / Admincloudsql.client · instanceUser · admin

Frequently Asked Questions

Connect, import, and Sync for Google Cloud.

At minimum Cloud Resource Manager. Enable BigQuery, Cloud Storage, Pub/Sub, and Cloud SQL Admin (sqladmin.googleapis.com) for the resource types you plan to import and Sync.