🚀 Launch Week 10, September 22nd - 26th, 2025 🚀
Mods
GCP

Policy: GCP > IAM > Service Account > Role Bindings > Approved

Configure Service Account Role Bindings checking. This policy defines whether to verify the service account role bindings are approved, as well as the subsequent action to take on unapproved items.

If set to Enforce: Delete unapproved, any unapproved role bindings will be removed from the service account while preserving the service account and their approved roles.

Targets

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Controls

Setting this policy configures this control:

Policy Specification

Schema Type
string
Default
Skip
Valid Values [YAML]
  • Skip
    
  • Check: Approved
    
  • Enforce: Delete unapproved
    
Examples [YAML]
  • Skip
    

Category

In Your Workspace

Developers