Policy: Defines an Identity and Access Management (IAM) policy. It is used to specify access control policies for Cloud Platform resources.

A `Policy` consists of a list of `bindings`. A `Binding` binds a list of `members` to a `role`, where the members can be user accounts, Google groups, Google domains, and service accounts. A `role` is a named list of permissions defined by IAM.


{ "bindings": [ { "role": "roles/owner", "members": [ "user:[email protected]", "group:[email protected]", "", "serviceAccount:[email protected]", ] }, { "role": "roles/viewer", "members": ["user:[email protected]"] } ] }

For a description of IAM and its features, see the [IAM developer's guide](

