Connect Google Cloud to Black Cat SSPM
Connect your Google Cloud project so Black Cat can review IAM bindings, service account keys, firewall rules, storage exposure, encryption keys and audit logging.
≈ 15 min · audit access · no write-capable permission
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
roles/iam.securityReviewer | Lets Black Cat review IAM bindings, service accounts and their keys across the project. | Required |
roles/compute.viewer | Lets Black Cat review firewall rules, networks and virtual machine configuration. | Required |
roles/storage.objectViewer | Lets Black Cat review Cloud Storage bucket settings such as public access and versioning. | Required |
roles/cloudsql.viewer | Lets Black Cat review Cloud SQL instances for public exposure, encryption and backups. | Required |
roles/cloudkms.viewer | Lets Black Cat review encryption keys and their rotation schedule. | Required |
roles/secretmanager.viewer | Lets Black Cat review secret metadata such as rotation and replication — never the secret values. | Required |
roles/container.viewer | Lets Black Cat review Kubernetes cluster settings and node configuration. | Required |
roles/logging.viewer | Lets Black Cat check that audit logging is switched on and covers data access. | Required |
roles/monitoring.viewer | Lets Black Cat see which alerting and notification channels are configured. | Required |
roles/dns.reader | Lets Black Cat review DNS zones and whether DNSSEC is enabled. | Required |
roles/bigquery.metadataViewer | Lets Black Cat review BigQuery dataset sharing and encryption settings — never the rows inside. | Required |
roles/cloudfunctions.viewer | Lets Black Cat review Cloud Functions, their triggers and the identities they run as. | Required |
roles/run.viewer | Lets Black Cat review Cloud Run services, their ingress settings and the identities they run as. | Required |
roles/orgpolicy.policyViewer | Lets Black Cat check organization policies such as restrictions on service account keys. | Optional |
roles/essentialcontacts.viewer | Lets Black Cat check that security contacts are registered for the project. | Optional |
roles/iam.denyReviewer | Lets Black Cat see the deny policies that restrict access. | Optional |
What you'll need
- Project identifier Required — Shown on the Google Cloud console dashboard for the project.
- Service account key (JSON) Required — The JSON key of the read-only service account you create for Black Cat.
- Organization identifier — Optional — add it to include organization-level policies and contacts in the review.
Where to create it
- Setup guide (Google Cloud) ↗ (opens in new tab)
- Developer documentation (Google Cloud) ↗ (opens in new tab)
What we check on Google Cloud →