[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-02 (世界標準時間)。"],[[["\u003cp\u003eEventarc uses Identity and Access Management (IAM) for access control, allowing you to manage permissions and roles.\u003c/p\u003e\n"],["\u003cp\u003eTo manage IAM roles for Eventarc, you must first enable the Eventarc API for your project through the Google Cloud console.\u003c/p\u003e\n"],["\u003cp\u003eEventarc offers predefined IAM roles like Admin, Developer, Viewer, Event Receiver, and Publisher, each with specific permissions, which can be viewed in the roles table.\u003c/p\u003e\n"],["\u003cp\u003eFor specific or less common scenarios not addressed by predefined roles, you can create custom IAM roles to tailor access controls.\u003c/p\u003e\n"],["\u003cp\u003eThe Eventarc Advanced feature is currently in a "Pre-GA" stage and is subject to specific terms and might have limited support.\u003c/p\u003e\n"]]],[],null,["# Access control with IAM\n\n[Advanced](/eventarc/advanced/docs/overview) [Standard](/eventarc/standard/docs/overview)\n\nThis page describes the access control options that are available to you in\nEventarc.\n\nOverview\n--------\n\nEventarc uses Identity and Access Management (IAM) for access control.\n\nFor an introduction to IAM and its features, see the\n[IAM overview](/iam/docs/overview). To learn how to grant and\nrevoke access, see\n[Manage access to projects, folders, and organizations](/iam/docs/granting-changing-revoking-access).\n\nFor lists of the permissions and roles that Eventarc\nsupports, see the following sections.\n\nEnable the Eventarc APIs\n------------------------\n\nTo view and assign IAM roles for Eventarc,\nyou must enable the Eventarc APIs for your project. You won't be able\nto see the Eventarc roles in the Google Cloud console\nuntil you enable the APIs. \n\n### Console\n\n\n[Enable the APIs](https://console.cloud.google.com/flows/enableapi?apiid=eventarc.googleapis.com,eventarcpublishing.googleapis.com&redirect=https://console.cloud.google.com)\n\n\u003cbr /\u003e\n\n### gcloud\n\n\n[Enable the APIs](https://console.cloud.google.com/flows/enableapi?apiid=eventarc.googleapis.com,eventarcpublishing.googleapis.com&redirect=https://console.cloud.google.com)\n\n\u003cbr /\u003e\n\nPredefined roles\n----------------\n\nThe following table lists the Eventarc predefined\nIAM roles with a corresponding list of all the permissions each\nrole includes.\n\nThe predefined roles address most typical use cases. If your use case isn't\ncovered by the predefined roles, you can\n[create an IAM custom role](/iam/docs/understanding-custom-roles).\n\n### Eventarc roles\n\nProject-level IAM management\n----------------------------\n\nAt the project level, you can grant, change, and revoke IAM roles\nusing the Google Cloud console, the IAM API, or the Google Cloud CLI.\nFor instructions, see\n[Manage access to projects, folders, and organizations](/iam/docs/granting-changing-revoking-access)."]]