
Govern GCP access without shared Owner roles
Connect a service account once, import projects and resources, then approve grants that Sync real IAM — projects, BigQuery, Storage, Pub/Sub, and Cloud SQL.
How it works
From service account to Sync’d IAM
Connect once, import what you govern, then Sync access when grants are approved.
01
Connect GCP
Create a service account, grant it Project IAM Admin (and resource Admin roles you need), enable APIs, then paste the JSON key in Approv.
02
Import resources
Import projects, then use the shared project picker to import BigQuery, Storage, Pub/Sub, or Cloud SQL into Approv resources.
03
Request → approve → Sync
Members request a permission level. Approvers grant access. Approv Syncs IAM to Google Cloud and keeps an audit trail.
Connect
One service account for the org
Upload a GCP service account JSON key. Approv encrypts it and validates Resource Manager access — then you import only the projects and resources you want to govern.
- Enable Cloud Resource Manager and the APIs you import against
- Grant Project IAM Admin plus Admin roles for BigQuery, Storage, Pub/Sub, or Cloud SQL as needed
- Paste the JSON key once — credentials stay encrypted

Resources
What you can govern in GCP
Import these resources into Approv, then approve access with mapped GCP IAM roles.
01
Projects
Import projects and Sync viewer, editor, or owner roles.
02
BigQuery
Import datasets and tables; Sync dataset IAM roles.
03
Cloud Storage
Import buckets and Sync object viewer, creator, or admin.
04
Pub/Sub
Import topics and subscriptions; Sync subscriber, publisher, or admin.
05
Cloud SQL
Import instances and databases; Sync client, instance user, or admin with an instance IAM condition.
Sync
Approved grants become real IAM
On approve, Approv binds the member’s Google email to the mapped role. On revoke or expire, the binding is removed — including Cloud SQL grants scoped with an instance IAM condition.
- Project, dataset, bucket, Pub/Sub, and Cloud SQL mappings
- Time-bound access that Syncs removal when it ends
- Full audit trail of who approved what, and when
Mapping
Permission mapping
Approv permission levels map to native GCP roles when Sync runs.
| In Approv | In GCP |
|---|---|
| Project · Viewer / Editor / Owner | roles/viewer · editor · owner |
| BigQuery · Viewer / Editor / Admin | bigquery.dataViewer · dataEditor · admin |
| Storage · Viewer / Creator / Admin | storage.objectViewer · objectCreator · admin |
| Pub/Sub · Subscriber / Publisher / Admin | pubsub.subscriber · publisher · admin |
| Cloud SQL · Client / Editor / Admin | cloudsql.client · instanceUser · admin |
Frequently Asked Questions
Connect, import, and Sync for Google Cloud.