PermissionsThe Enforce GCP IAM Users Belong To Approved Domains policy pack requires 1 permission:resourcemanager.projects.setIamPolicy